Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

101–109 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#101
post #38

F5 claims that the threat actors' access to the BIG-IP environment did not compromise its software supply chain or result in any suspicious code modifications. Why would anyone have confidence in F5’s analysis?

I think it is more valuable for the attackers to have exfiltrated their code and analyze it for vulnerabilities.

Adding some malicious code to the BIG-IP software would require a long time for the attackers to persist in f5's systems undetected until they understood the current code. Not a zero percent chance, but pretty unlikely.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#102
post #68

Earlier quoted context omitted.

Yeah, I was trying to make sense of what was described here. Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products? If so, lol.

A simple search across a codebase for "TODO" will find all sorts of things left undone, but having access to source control and commit messages, who knows what you might find. "Here be dragons" is also a good search if you're responsible for security hardening legacy code.

Yeah, it's unclear if this is something like TODO or an internal Jira tracking bugs.

Either way though, this is not a small company. DoD/Navy utilizes this all over their systems. TODO shouldn't be getting pushed to main, nor should there be security issues swept under the rug for later.

Maybe they disclosed this to some vendors previously, but I doubt.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#106

Earlier quoted context omitted.

Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.

You will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.

Tell that to my customers.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#107

Earlier quoted context omitted.

You will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.

Tell that to my customers.

Your lawyers and your PR department will do that, emphasizing very strongly that you did nothing wrong and their security is your utmost priority.
Post reply on HN