Live data from Hacker News

Microsoft confirms Russian spies stole source code, accessed internal systems

theregister.com

11–20 of 38 posts

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#11
post #9

Earlier quoted context omitted.

Take this wildly simplified example. You are the attacker. You already have access to internal systems at Microsoft. Now you need to send the large amounts of data back to yourself, preferably without giving away your own location in the process. That’s the exfiltration phase of the cyber kill chain. In order to do that, you’ve already established a set of listening posts and command/control sites across the internet…

What happens after the first node is hit? You more or less need to control the network stack around it to know were it in turn sends data. If the NSA or whatever do control virtually every network stack they can access politically, every lead will end in countries which does not comply, right? If there is any world-wide N-to-N statistical analysis of eavesdropped nodes for reentry of the data, it should trivially be…

You’re overstating the technical capabilities at scale and understating just basic investigation techniques.

“Buffering” absolutely happens for a variety of reasons.

Tracking down the money or owning the operations infrastructure of the hosting companies along the way can help. Try to expand past bits on the wire- people set this stuff up at the end of the day.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#12
post #8

Earlier quoted context omitted.

No that's why we all can naively say it isn't happening even though many of us here could do it ourselves as a fun side project.

So you just are wildly speculating and assume this one technique you know about completely defeats teams of specialists with the budget of the richest country in the world It's one thing to point out issues with attribution. It's another to just say since we can't say with 100% certainty let's just make up attributions. Especially with no knowledge of the attributions certainty, they could be 99.9% sure

What OP is doing also happens to look like a disinformation technique.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#13
post #11

Earlier quoted context omitted.

What happens after the first node is hit? You more or less need to control the network stack around it to know were it in turn sends data. If the NSA or whatever do control virtually every network stack they can access politically, every lead will end in countries which does not comply, right? If there is any world-wide N-to-N statistical analysis of eavesdropped nodes for reentry of the data, it should trivially be…

You’re overstating the technical capabilities at scale and understating just basic investigation techniques. “Buffering” absolutely happens for a variety of reasons. Tracking down the money or owning the operations infrastructure of the hosting companies along the way can help. Try to expand past bits on the wire- people set this stuff up at the end of the day.

What does scale have to do with it. That is like saying I don't understand, because it is Big Data in the Cloud with Edge Computing. As I see it I just need one computer in Venezuela and the trail is gone.

There is a lot of hand waiving from "security" folks. They are probably about as fraudulent as bullet forensics etc.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#15
post #6

Earlier quoted context omitted.

No that's why we all can naively say it isn't happening even though many of us here could do it ourselves as a fun side project.

Nobody in this thread is saying that but you, atm. I was just wondering if you were speculating or had any evidence. Id even be interested to hear more about your logic because "its possible and has been done before by other actors" isnt enough to convince me

Are you implying that people are not, in fact, IPs?

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#16
post #11

Earlier quoted context omitted.

You’re overstating the technical capabilities at scale and understating just basic investigation techniques. “Buffering” absolutely happens for a variety of reasons. Tracking down the money or owning the operations infrastructure of the hosting companies along the way can help. Try to expand past bits on the wire- people set this stuff up at the end of the day.

What does scale have to do with it. That is like saying I don't understand, because it is Big Data in the Cloud with Edge Computing. As I see it I just need one computer in Venezuela and the trail is gone. There is a lot of hand waiving from "security" folks. They are probably about as fraudulent as bullet forensics etc.

You’re doing your own hand waving. Why does a computer in Venezuela make the trail go cold? I could have an agent working for me passing me customer lists from Venezuelian colo facilities. Combine that with knowledge of known shell entities who also operate from other points of presence and I can make inferences. If I want I could then use offensive techniques to own the middle box and enhance my confidence level by observing traffic/stored data on that machine.

Look I can’t summarize how threat actor attribution works in a hacker news comment. Does that mean the people who do it are quacks? Nope. I know people who do it, who build tools to help, and they are exceptionally sharp technical minds.

And I see you have casually dismissed an entire industry because you may not understand how someone could draw conclusions from imperfect data?

Hate to say it but this happens all day every day as human existence is filled with imperfect data. Not everything can be summarized in a neat mathematical form.

Does that mean you don’t try? I choose to try my best and continually improve methods. Otherwise what’s the point? Just give up because we can’t model human behavior and geopolitics as a pure functional state machine?

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#17
post #16

Earlier quoted context omitted.

What does scale have to do with it. That is like saying I don't understand, because it is Big Data in the Cloud with Edge Computing. As I see it I just need one computer in Venezuela and the trail is gone. There is a lot of hand waiving from "security" folks. They are probably about as fraudulent as bullet forensics etc.

You’re doing your own hand waving. Why does a computer in Venezuela make the trail go cold? I could have an agent working for me passing me customer lists from Venezuelian colo facilities. Combine that with knowledge of known shell entities who also operate from other points of presence and I can make inferences. If I want I could then use offensive techniques to own the middle box and enhance my confidence level by…

Sure I am not claiming that you can't figure out who or where the hackers are. I am claiming that you more or less have to arrest them and get their computers to be even remotely sure, and that it is trivial to frame hackers or "frame" the plot of dirt where they are located, for a hack. Especially so, when the victim can shift blame to CYA.

If the methodology is secret because secret, I as a observer just assumes everything is made up. It is way to convenient for Microsoft to shift blame. There is this smell of the Clinton email leak again.

I mean, you I presume, and I, are programmers. How ludacris would it be to claim it is not a miracle the computer it even boots? It is black box upon black box and the "pink elephant behind my back", in the world of computing, is real.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#18
post #16

Earlier quoted context omitted.

You’re doing your own hand waving. Why does a computer in Venezuela make the trail go cold? I could have an agent working for me passing me customer lists from Venezuelian colo facilities. Combine that with knowledge of known shell entities who also operate from other points of presence and I can make inferences. If I want I could then use offensive techniques to own the middle box and enhance my confidence level by…

Sure I am not claiming that you can't figure out who or where the hackers are. I am claiming that you more or less have to arrest them and get their computers to be even remotely sure, and that it is trivial to frame hackers or "frame" the plot of dirt where they are located, for a hack. Especially so, when the victim can shift blame to CYA. If the methodology is secret because secret, I as a observer just assumes ev…

I’m not sure how this shifts blame? In my opinion the blame sits squarely on the shoulders of the entity whose systems were exploited. Microsoft is responsible for the security of their systems, full stop. Doesn’t matter if the GRU did it or some random guy in Venezuela.

How do you know Microsoft was even “hacked”? I mean if you want to get super pedantic about this, I haven’t personally seen any proof.

So yes while a computer provides a convenient mathematical abstraction upon which we can reason, we aren’t talking about how a computer boots. We are talking about figuring out - within a certain confidence level - the group of individuals that likely carried out an attack. We are now firmly outside the scope of the neat little mathematical abstraction of the machine. Even within a machine, there’s more nondeterminism than you or I would like to admit. But that’s a topic for another day.

The methodology is not secret, you can google for threat actor attribution. Private companies do this work as well as governments. You are welcome to go join one of those companies or organizations to learn how it works and work to improve the process if you are so passionate about it!

You are the one putting some political agenda on this. China, Russia, as well as North Korea, Israel, Iran, and many other countries have robust offensive cyber capabilities. Attribution is not an exact science, and if you actually read any raw intelligence report it is clearly marked with a confidence level for that exact reason.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#19
post #8

Earlier quoted context omitted.

No that's why we all can naively say it isn't happening even though many of us here could do it ourselves as a fun side project.

So you just are wildly speculating and assume this one technique you know about completely defeats teams of specialists with the budget of the richest country in the world It's one thing to point out issues with attribution. It's another to just say since we can't say with 100% certainty let's just make up attributions. Especially with no knowledge of the attributions certainty, they could be 99.9% sure

> we can't say with 100% certainty

This admission is unknown to the general public, they "trust the experts" that it is 100 proven.

> let's just make up attributions.

If you aren't 100% it is Russia and scream Russia, that's what you are doing

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#20

Remember when we all learned from the vault 7 leaks that the US government has the ability to create cyberattacks that appear to investigators to have come from another nation? We were doing that prior to 2017. Thank God someone like China can't ever do that, even nearly a decade after we did and we can trust these sort of accusations at face value and not at all think critically about them.

The cyberattacks which used the Marble framework were limited to those where a payload was delivered. Marble is comparable to mailing a bomb and putting a fake return address on the package.

For data exfiltration, which is like robbing a bank vault, you'll need more than a fake address. It's orders of magnitude more difficult to cover your tracks, and you only need to leave one clue behind to undo all that work.

Post reply on HN