It says they had to find out from the FBI. At least theoretically, how does the FBI find out? (unless someone knows the actuality and is willing to share? Didn't see anything in the article)
Not so sure about that. I use ShareFile for secure document delivery and they forced a password reset with stricter requirements in January, the month after the first breach, and two months before the FBI notification. No notice of breached documents to its customers yet.
Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
151–160 of 216 posts
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#152Earlier quoted context omitted.
Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.
This argument is not much different than what the grandparent is referring to. weev was convicted of conspiracy to access a computer without authorization because he advised a guy who discovered a publicly available HTTP API hosted by AT&T that returned email addresses based on guessable ids. The conviction was overturned, but on procedural grounds, not legal ones.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#153Earlier quoted context omitted.
I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…
There's another way to use computers to help with voting. Have Ballots with a unique identifier. People come to a polling station, get a ballot, fill in their vote. The ballot goes through a scanner to tally the vote, and then goes into a standard vote bin. At the end of voting, you cross-check a random sample (both ways) and check the total number of votes matches between the scanner and bin. If all goes well, scann…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#154Earlier quoted context omitted.
I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.
Yes, it makes you wonder, how does a small company pop into existence straight into class-A office space in downtown LA, and within the span of what? two years? claims to have done business with a dozen or so heavyweight companies. And what is their web presence? Vague, inscrutable C-suite-speak about security, and one blockbuster claim in the Citrix break. At some point, Occam's razor will favor that this company is…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#155Ah, The Register lifting another story from another news outlet. The original report came from NBC: https://www.nbcnews.com/politics/national-security/iranian-b... Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. Every site online credited NBC except these "journalism experts" (to be red clickbait-loving, content thieving d-bags)
>> Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. That seems uncalled for. Are Indian blogs (as opposed to non-Indian blogs) known for this kind of thing?
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#156Earlier quoted context omitted.
It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…
I think it is best to take a wholesale view that the news as we know it is a religion. That sounds a bit odd given that a lot that is in the news is fact oriented and a lot of current affairs is discussed. But in a formal church there is mention and prayers for those caught up in actual events. Fundamentally though the news requires belief. It is there for the 'capitalist flock' who have a world where the government,…
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#157Earlier quoted context omitted.
It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…
> We were never given any proof, so it’s impossible to verify... Bullshit. https://www.nytimes.com/2015/01/19/world/asia/nsa-tapped-int... https://www.recode.net/2015/4/21/11561700/sony-hack-was-not-... https://www.symantec.com/connect/blogs/collaborative-operati... https://www.nytimes.com/2018/09/06/us/politics/north-korea-s...
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#158Compromise feels almost inevitable. Perhaps the idea that we can keep data protected and accessible at the same time using complex software is folly? Systems get more and more complex, security measures layer on top, patching over holes as they are found. But we are never in front of the cat and mouse game by necessity, only ever behind. So it must be that compromise is inevitable. I wouldn't put personal data I am n…
> I wouldn't put personal data I am not willing to lose online or on an intranet at all anymore Anymore? Not trusting the internet used to be the default.
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#159Earlier quoted context omitted.
Are you the CEO of a company that works in computer security, where fame is probably more important than in other fields?
Fame does not equal trust. While there may not be any security through obsecurity it is a barrier. As for being a trusted CEO at a certain point its about who you know and who knows you. Do you think the NSA employees all have social media profiles?
Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets
#160Earlier quoted context omitted.
[flagged]
You're downvoted, because you seem to be whitewashing a few things - from Assad, to Soviets in Afghanistan, in your quest to paint USA blacker. You tell us to take intelligence community with a grain of salt, and then speculate about Kashoggi - where most information comes from Turkey's intelligence aparatus. Also socialists are also funded and armed by USA (see SDF in Syria). Also this guy (armed by USA) - https://e…
Socialists and Shiites were obviously occasionally funded and armed by the USA, and I even alluded to this - Saddam was a socialist, and the new government of Iraq was a Shiite government. However, that doesn’t negate what I said - read it carefully. Far more mainstream sources than me have pointed this out:
http://www.cc.com/video-clips/yt7an7/the-daily-show-with-jon...