Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

181–190 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#181

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

If i recall correctly solarwinds was more of an espionage operation by russia government actors. Their targets were mainly government agencies in US. The ransomware attack are from private profit-seeking groups, although I remember the head of REvil tweeted once he was neighbours with KGB's number two guy so you could argue the distinction is vague

Re: US companies hit by 'colossal' cyber-attack

#182

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

Can you explain more about the ‘root ash’ issue please?

Re: US companies hit by 'colossal' cyber-attack

#183
post #44

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…

> If it was me (it was not)

Sure…

Re: US companies hit by 'colossal' cyber-attack

#185
post #71
post #26

Earlier quoted context omitted.

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

You make it sound like the Teamsters Union could do something bad to the attackers, so attackers gave up, but in reality Teamsters just rebuilt from archives, which was perhaps an economical decision:

“Ultimately, the union decided not to pay the ransom based on advice from its insurance company, and instead rebuilt its systems based on archived materials, NBC reported.”

Re: US companies hit by 'colossal' cyber-attack

#186
post #71
post #26

Earlier quoted context omitted.

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

Maybe a nation state is already behind it? https://cryptome.org/2021/06/Peck-Barb-1974.pdf

Was Edward Snowdon "https://www.youtube.com/watch?v=1GtVt6quoD8&t=78s" or a psychologically manipulated patsy for the good/bad guys & girls?

https://en.wikipedia.org/wiki/Full-spectrum_dominance isnt just about hacking a few computers, its about getting inside the brain of each and every one of us/you like a https://www.youtube.com/watch?v=lG7DGMgfOb8.

Or is this line of thought just a https://www.youtube.com/watch?v=wmin5WkOuPw&t=48s ?

Re: US companies hit by 'colossal' cyber-attack

#187
post #84

Earlier quoted context omitted.

Without crypto, would it be impossible to extract cash from a company? What is the current mechanism used to get funds that the FBI can’t track down? Wire the money to a jurisdiction mostly out of our sphere of influence.

More difficult, but feasible. One way is to demand that a smaller amount of money be wired to 1,000 accounts throughout the world. You — the bad guy - own merely one of them. Difficult to trace them all before you empty your particular account.

But then the amount would be 1/1000 and it wouldn’t be financially lucrative enough

Re: US companies hit by 'colossal' cyber-attack

#189

Earlier quoted context omitted.

This is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.

Perhaps, but of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder thanks to Citizens United and armies of lobbyists. Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries. I think it’s safe to say that corruption and greed are at the ro…

Yes yes I know the scriptures, and yes I'm possessed by the secular-devil (who is that today? Putin? Hitler? Trump?) for not unthinkingly reciting them verbatim.

Re: US companies hit by 'colossal' cyber-attack

#190

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

> this should be the death knell of these "remote monitoring and management" tools

Yeah, sure. We should have a person on each of hundreds of sites whose only job is to check manually every router, switch, and vending machine. Maybe in the best HN traditions you will train the necessary workforce in a weekend?

Post reply on HN