US companies hit by 'colossal' cyber-attack
191–200 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#192Earlier quoted context omitted.
Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a…
I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.
Yes much can be automated but there is usually a human element to these deals and that costs the hackers money.
They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company directly or indirectly linked to your state/handler/patron.
Re: US companies hit by 'colossal' cyber-attack
#193Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
> this should be the death knell of these "remote monitoring and management" tools Yeah, sure. We should have a person on each of hundreds of sites whose only job is to check manually every router, switch, and vending machine. Maybe in the best HN traditions you will train the necessary workforce in a weekend?
> tools that have extreme low-level access to networks and systems
The emphasis being on the low level access. The solution is not having hundreds of people checking things by hand (though I'm sure that could contribute to security). The solution is more privilege separation; so that when the "remote monitoring tool" is compromised, not every part of your infrastructure is also compromised by default.
Re: US companies hit by 'colossal' cyber-attack
#194Earlier quoted context omitted.
Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…
Would you mind briefly explaining the concept of "tech debt" to a layperson?
You can cook a bunch of times ignoring these secondary results but over time cooking will be slower and of worse quality due to the mess and at some point it will be impossible (too dirty, no usable pots and pans, etc).
Re: US companies hit by 'colossal' cyber-attack
#195Re: US companies hit by 'colossal' cyber-attack
#196Earlier quoted context omitted.
I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.
That stuff is automated. What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.
Re: US companies hit by 'colossal' cyber-attack
#197Earlier quoted context omitted.
Two more things to consider: - Can you articulate specific reasons to buy anything beyond the default windows defender? - If anyone went to an actual war with the US, would the source of your antivirus software get even close to top 5000 things you care about at that point...
As for default Windows Defender, there isn't really good reporting tools related to it. There are reporting tools for Defender, but those are paid license add-ons. And yeah there's a decent chance if the US went to war with another country it might not impact the majority of US businesses very directly especially in the short term IRT their IT plans. McDonald's kept selling burgers when we invaded Iraq (multiple time…
Re: US companies hit by 'colossal' cyber-attack
#198[1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
Re: US companies hit by 'colossal' cyber-attack
#199One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
Patients in Region Skåne were also unable to access their journals on Friday afternoon (possibly unrelated) and Coop's competitor ICA's apothecary company Apoteket Hjärtat seems to be affected by Kaseya/REvil attack also.
Re: US companies hit by 'colossal' cyber-attack
#200thats bad because kaseya protects other companies