Just block all traffic from russia :)
takes step over the border and opens laptop
Microsoft actions following attack by nation state actor Midnight Blizzard
141–150 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#142Earlier quoted context omitted.
Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.
A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment.
From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#143Earlier quoted context omitted.
>> It is not known whether this hacking group is private, government sponsored, or government run. Coming from Russia, that's a distinction without a difference. Sure, private groups can 'freelance', but not without at least tacit permission from the FSB, GRU, and/or SVR (more accurately, cant freelance for long). Especially so for sch a high visibility target such as Microsoft. And when the RU govt isdues a denial,…
The distinction probably matters to a lot of people at the scale that Microsoft is operating at. They likely worked with some sort of MS US government liaison on the wording. Operating with tacit approval is not the same as being a government entity. Even you admit there is a small chance that this group is not tacitly approved ("for long"). I mean yeah, we all know the score, but a it's really bad idea to levy heavy…
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#144Earlier quoted context omitted.
Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
They mean root access on the production email servers, not access to individual email accounts.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#145Earlier quoted context omitted.
No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.
That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#146Earlier quoted context omitted.
No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.
That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#147There are developers out there with excellent track records who have built bug-free solo projects which prove their excellence and yet can't find a job in this economy. Some of these developers have also proven themselves to work well in a team so there is no excuse to ignore them. They are excellent both as lone wolf and team player. Companies should desperately look for them and recruit them. Only such developers can save companies from technical decay.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#148Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#149Earlier quoted context omitted.
That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
If the blog post was written by their internal IT team, you’d be totally justified in reading “production” to include their internal systems.
Microsoft produces software and services. The communications of their CEO as well as their cybersecurity and legal teams is part of that overall production process.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#150Why do they say "nation state actor", isn't "state actor" the correct term? I thought Russia, like the UK and many other states, is a multinational state, including numerous languages and cultures.
I've always wondered why infosec people love this expression so much. Maybe "nation state" just sounds more impressive. Who cares what the state is composed of? Or is it "nation/state", one or the other?