Live data from Hacker News

British Parliament Hit by Cyberattack, Affecting Email Access

nytimes.com

21–27 of 27 posts

Re: British Parliament Hit by Cyberattack, Affecting Email Access

#21
post #19

Based on the names mentioned I searched for their email addresses in password dumps and they all match the large 500M+ lists (anti public and exploit.in - covered here[0]) that have been available on some of the credential-stuffing and hacking forums since late last year. They are aggregate lists composed of MySpace, LinkedIn and other breaches. It appears someone has grepped out parliament.uk emails from those leaks…

Yup, completely agree with this. I know I've mentioned it on HN before, but credential stuffing is unfortunately common practice and is a huge reason not to reuse passwords - especially if they've been leaked.

We see credential stuffing attacks regularly - some from folks just trying their luck (using known tools and scripts such as Sentry-MBA). Others are a little more advanced and persistent, looking to gather information from successful logins which they can then re-sell on the various shifty marketplaces.

Sites that have monetary value are particularly high value targets. If you have a site which reveals key personal information such as addresses and credit card info (last 4 etc.), these will likely be scraped. If you have a site that can order goods, successful accounts will be scraped to see if they have a valid and active card associated with them, allowing them to be sold for a higher price. If you have a site which collects points (think airlines or hotels), these too will be scraped and sorted, allowing them to market those with higher points for more cash.

Where possible, use 2FA, and always use a different password for each website. Password managers sometimes get a bad name, but they're much better than using the same password everywhere.

Re: British Parliament Hit by Cyberattack, Affecting Email Access

#22
post #4

Earlier quoted context omitted.

I wouldn't get too grandiose about saying the institutions are broken. It's just email, why not consider it like postal mail? Definitely not good, definitely needs to be fixed, but also definitely does not mean the legislature entirely is not secured or that institutions are all broken.

It's just email How is that not critical infrastructure given legislators' need for secure and accessible communications?

It demonstrably doesn't fulfil that need; GP's point, I think, is that postal mail has (perhaps more obvious, especially outside HN) vulnerabilities that were coped with for millennia.

Re: British Parliament Hit by Cyberattack, Affecting Email Access

#23
post #5

In what way have they been 'hacked'? Constituents can email their MPs and I'd imagine they all share the same few email servers. It's not hard to imagine that someone thought they'd 'have a go' (as was the case during the election period), and the reaction by Parliament has so far been a precautionary one.

FTA: > stolen data revealed the private login details of 1,000 British members of Parliament and parliamentary staff, 7,000 police employees and more than 1,000 Foreign Office officials. Not sure how that wouldn’t be treated as a cyberattack. Note, the word used was not ‘hack’ - not all cyberattacks are hacks.

Seems the NYT changed the title to remove the 'hack' insinuation.

> stolen data revealed the private login details of 1,000 British members of Parliament and parliamentary staff, 7,000 police employees and more than 1,000 Foreign Office officials.

That was reported last week. The attacks happened months ago. (Why do I even bother?)

Re: British Parliament Hit by Cyberattack, Affecting Email Access

#24
National institutions have indeed begun their long slide into irrelevance. Ray Kurzweil, a big shot at Google, already wrote about that. Anything that existed before the widespread commercialization of the internet cannot remain the same, after. I am waiting for news of the inevitable to break loose. A group of disgruntled people setting up internet infrastructure to literally organize the decimation of state officials. They will end up dying like flies. As soon as the first guys do that, there will be no stopping it. The national state uses force to enforce its views, while they no longer have a credible monopoly on the use of force.

Re: British Parliament Hit by Cyberattack, Affecting Email Access

#25
post #4

Earlier quoted context omitted.

I wouldn't get too grandiose about saying the institutions are broken. It's just email, why not consider it like postal mail? Definitely not good, definitely needs to be fixed, but also definitely does not mean the legislature entirely is not secured or that institutions are all broken.

It's just email How is that not critical infrastructure given legislators' need for secure and accessible communications?

It is critical infrastructure. There are two parts: a.) mimic the thing our predecessors created: postal mail was so important that they had a person on a steed ride across barren land for days to deliver a message; b.) how do we adapte the modern equivalent. It's not so hideous for someone to make a copy of the payload on the horse, is it? It's not good to copy it. But it's much worse if the original is compromised: faked message or faked originator or destroyed.
Post reply on HN