Live data from Hacker News

At Facebook, zero-day exploits, backdoor code bring war games drill to life

arstechnica.com

11–20 of 52 posts

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#11
post #6

The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

(I work at Facebook but don't know anything about the event in question or if this post is accurate) I suspect it wasn't actually a "0-day" in that sense, but rather a disclosed but unpatched vulnerability, and described as "a real 0-day exploit" in the article because of the typical reduced fidelity of press articles.

Ah! See, that makes much more sense, but I hope this isn't spin. ;)

So then next question, how come the vulnerability was unpatched?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#13
post #11

Earlier quoted context omitted.

(I work at Facebook but don't know anything about the event in question or if this post is accurate) I suspect it wasn't actually a "0-day" in that sense, but rather a disclosed but unpatched vulnerability, and described as "a real 0-day exploit" in the article because of the typical reduced fidelity of press articles.

Ah! See, that makes much more sense, but I hope this isn't spin. ;) So then next question, how come the vulnerability was unpatched?

Because it was all staged?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#14
I'd be moderately pissed off if I got stuck in a drill for 24h+ without knowing it was a drill, unless it was a known thing that drills would be run routinely. There is stuff I'd do for "real" (missing one-off personal events, etc.) which I wouldn't do for training. I'd skip out on a wedding (well, I always do anyway), funeral, etc. for a real security issue, but would quit the next day if I had done so for training without my knowledge.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#15
> If it were any other industry and it was any other critical function of a product not doing this you'd have people screaming that [the companies] were negligent and wanting to sue them left and right.

Are Facebook and Google critical functions?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#16
post #14

I'd be moderately pissed off if I got stuck in a drill for 24h+ without knowing it was a drill, unless it was a known thing that drills would be run routinely. There is stuff I'd do for "real" (missing one-off personal events, etc.) which I wouldn't do for training. I'd skip out on a wedding (well, I always do anyway), funeral, etc. for a real security issue, but would quit the next day if I had done so for training…

These teams usually work in rotations, so if you have prior knowledge of a personal event then you'd take yourself out of the rotation for that time period.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#17
post #7

A more interesting response test would have been to drop the less-realistic FBI alert email and find out how long it would have taken them to find the backdoor without it

Very good idea, but that'd test threat detection, not threat response. Different teams handle those areas.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#19
>> The engineer's computer was compromised using a real zero-day exploit targeting...

Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits.

I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of their pa.. laptops.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#20

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

Client side zero-day is not even remotely unrealistic for an organization like Facebook. This stuff happens much more than you think it does.
Post reply on HN