Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

141–150 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#142

Earlier quoted context omitted.

Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.

No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.

That may be how Microsoft would like to portray it but I disagree.

A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment.

From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#143
post #17

Earlier quoted context omitted.

>> It is not known whether this hacking group is private, government sponsored, or government run. Coming from Russia, that's a distinction without a difference. Sure, private groups can 'freelance', but not without at least tacit permission from the FSB, GRU, and/or SVR (more accurately, cant freelance for long). Especially so for sch a high visibility target such as Microsoft. And when the RU govt isdues a denial,…

The distinction probably matters to a lot of people at the scale that Microsoft is operating at. They likely worked with some sort of MS US government liaison on the wording. Operating with tacit approval is not the same as being a government entity. Even you admit there is a small chance that this group is not tacitly approved ("for long"). I mean yeah, we all know the score, but a it's really bad idea to levy heavy…

This group is also known as CozyBear, if that rings a bell. The US government named them years ago in an announcement kicking out several Russian diplomats. I don’t think anyone is worried about being wrong on this.

https://attack.mitre.org/groups/G0016/

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#144

Earlier quoted context omitted.

Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.

They mean root access on the production email servers, not access to individual email accounts.

"any access to customer environments, production systems, source code, or AI systems" does not mean root access. It can also mean access to data.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#145

Earlier quoted context omitted.

No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

That is how it has been defined at every SAAS company I have worked for. When someone says there is an outage in production, it means your product.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#146

Earlier quoted context omitted.

No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

If the blog post was written by their internal IT team, you’d be totally justified in reading “production” to include their internal systems.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#147
I'm wondering how many hacks like this must occur before companies start caring about hiring good developers with a proven individual record instead of those who can solve the most gimmicky puzzles in 30 minutes.

There are developers out there with excellent track records who have built bug-free solo projects which prove their excellence and yet can't find a job in this economy. Some of these developers have also proven themselves to work well in a team so there is no excuse to ignore them. They are excellent both as lone wolf and team player. Companies should desperately look for them and recruit them. Only such developers can save companies from technical decay.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#149

Earlier quoted context omitted.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

If the blog post was written by their internal IT team, you’d be totally justified in reading “production” to include their internal systems.

No. Whether or not a system runs in production as opposed to a testing/development environment is not a question of who is writing a blog post.

Microsoft produces software and services. The communications of their CEO as well as their cybersecurity and legal teams is part of that overall production process.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#150
post #134

Why do they say "nation state actor", isn't "state actor" the correct term? I thought Russia, like the UK and many other states, is a multinational state, including numerous languages and cultures.

I've always wondered why infosec people love this expression so much. Maybe "nation state" just sounds more impressive. Who cares what the state is composed of? Or is it "nation/state", one or the other?

Clearly only a nation-state threat actor could have pulled off this highly sophisticated cyber attack of ... Spraying passwords
Post reply on HN