Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

101–110 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#102
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

I don't believe you. Give me an example of a company spending 100's of millions as a result of a breach. Companies understand it costs them nothing and if there is a cost it's trivial. When there is no penalty or the fine is a pittance, no company is going to spend 10's to 100's of millions. It makes no business sense first of all and secondly they can blame a foreign actor to mask their own incompetence.

Re: US companies hit by 'colossal' cyber-attack

#103
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

Please point out some 10Q/10K filings that go into detail about these enormous expenditures related to security breaches.

The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck!

[0] https://www.sec.gov/edgar/searchedgar/companysearch.html

Re: US companies hit by 'colossal' cyber-attack

#104
post #96

In some not-so-distant future dystopia, ransomware hackers will morph into a file encryption service w/ optional data exfiltration as a backup. Just don't stop paying the bill. Or at least that's where we're headed if companies keep giving in to the ransom demands.

Subscription based Ransom ware.

RWaaS. It should come with indemnity against other ransomware hackers where your RWaaS provider will either provide you with backups &/or go after (negotiate, hack, or physically assault) the other hackers.

Re: US companies hit by 'colossal' cyber-attack

#105
post #61

Earlier quoted context omitted.

I used to work for an MSP and we had used Kaseya. There was an AV integration, and then Kaseya changed to Kaspersky. I don’t remember what the prior AV software was. I always thought it bizarre we were actively installing AV software from Russia on banking and medical office PCs.

That has been a consideration in the AV software I recommend to friends, family, and professionally as an informal part of my threat assessment model. I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and…

Two more things to consider:

- Can you articulate specific reasons to buy anything beyond the default windows defender?

- If anyone went to an actual war with the US, would the source of your antivirus software get even close to top 5000 things you care about at that point...

Re: US companies hit by 'colossal' cyber-attack

#106

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though).

I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with massive risk reviews, but for some reason those security zones then share subnets with the entire LAN.

They also have a default configuration which makes everything access the standard intranet directory once its deemed secure. Enterprise security tools like Cyberark are deemed more secure than say yubikey HSMs, which may result in root ssh being enabled in a lot of settings. They have system configurations that are done with massive Excel sheets. Their cloud VPCs basically only have one risk profile and once its deemed secure it gets access to things in the intranet. They also vehemently refuse to do threat modelling when designing anything.

These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems.

And the offenders are always the same, advised by Accenture, Infosys etc.

Re: US companies hit by 'colossal' cyber-attack

#107

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

RMM is absolutely vital to securing systems. This is as ridiculous as suggesting we should just get rid of firewalls because there are vulnerabilities found in them. RMMs are how enterprise scale networks close off every other security hole on a network.

That being said, RMM tools have plenty of examples that they need to beef up their security practices or get replaced.

Re: US companies hit by 'colossal' cyber-attack

#108
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.”

It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after the public became aware of the breach, with a $90m severance package.

https://fortune.com/2017/09/26/equifax-ceo-richard-smith-net...

Re: US companies hit by 'colossal' cyber-attack

#109

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

One could hope but I doubt it. CFO's gonna CFO and it's "cheaper" to outsource IT. I had one of these vendors really pushing me to "take a call" or "let them show me how they could cut costs". It was ALL about the costs. And I eventually called the CEO and said we would consider it if the company would take out a $100M bond that we could call on to repair any damage that occurred as a result of their managing our IT systems. He thought that was ridiculous of course and thought poorly of me. Since that time at least two of his customers have been the victims of breaches that IT either directly facilitated or indirectly made possible by providing additional attack surface that was required for their business to work.

But not every person who has executive oversight of operations thinks like I do, and all of them are represented in the company's finances as a 'cost center' that is second only to Payroll in terms of how juicy a 'cost reduction' target it presents.

So when the going gets tough, the company cuts back its IT budget.

Re: US companies hit by 'colossal' cyber-attack

#110

Earlier quoted context omitted.

These attacks didn't exist before crypto.

No, they typically sold stolen information on private/underground/invite forums or IRC. Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SS…

> it would be Apple or Google Play codes

I don't think Apple or Google credits would be effective for large-scale ransomware. Not anonymous, could be stopped by a slightly-motivated central authority. It works for preying on individuals, however, because they don't have enough clout to force the issue.

Post reply on HN