Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

21–30 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#21

Just curious if "ties to China" means "an IP address that may or may not be allocated to Chinese geography, and may or may not simply be a Tor exit node or a VPN service." People are far too trusting of these claims of where these attacks originated. Very few people in the world, including journalists, know how IP networks work.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#22
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks.

Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise.

If I had a static environment with no new software or business processes, then NO PROBLEM. I can lock it down in every kinda way and it stays locked down to a known baseline.

Add to that new biz processes and now I have interconnection internally and externally which make detection and prevention difficult. Things are much more difficult now.

Add to that new software, ever changing dev env, OS updates, firmware updates, software version updates, dev env dependency updates, now you're talking near impossible to keep up.

And that's the state we're in today. There are some generic mostly effective controls that if implemented correctly can stop most advanced attackers (the so called "20 security controls") https://www.yumpu.com/en/document/read/6582321/20-critical-s...

But even in spite of that, any major nation state had an arsenal of "capabilities" that allow them to dominate most cyber warfare area of operations in the civilian sector. US can do it, UK, Israel, China, Russia, probably even India and others!

Against nation states, there is no stopping nation states in the civ sector, despite what every F500 company's CSO wants you to believe.....sad but true.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#23
post #9
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

The primary thing to help randsomemware would be to have tested backups, where you can reimage the computers and restore from backups reasonably quickly.

And offline backups

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#24
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

No. The reality is that nobody cares about security unless it's their job to, so you have a handful of security people trying to get things fixed, meanwhile the rest of the organization just sees you as a speedbump in the way of implementing new features or buying some new SaaS product. Devs where I work even went to my manager and asked if I could only be allowed to report security findings during specific timeframes because they get behind schedule when they have to fix things. We even have a document that lists a bunch of security controls to cover almost every situation imaginable, and most of the time the devs just say it's impossible to fix the vulnerability without breaking the feature, so they go to management and get a waiver for the security issue.

Realistically, the only way for an organization to actually be secure is if it's part of the culture from the start.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#25

Cyberattack day! This one happened over a month ago, its obvious this is a trending headline likely not organically, so make sure to separate the dates before thinking we are under a coordinated attack all at once right now

The media needs something to scream about after corona is over. It looks like Russian and Chinese hackers are on the menu.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#26

Cyberattack day! This one happened over a month ago, its obvious this is a trending headline likely not organically, so make sure to separate the dates before thinking we are under a coordinated attack all at once right now

I think on HN this has always been a trend. a headline sparks more headlines of similar stories regardless of date. I've seen it happen quite frequently.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#27
post #5
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

> Perhaps a pentester or security person can help answer this Not one of those but since they are [apparently] inadequate anyway... I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works. Minimum safety standards: laws and ability to enforce them. This is a short-term win for the bad actors. Just w…

A better analogy would be an armored truck full of cash parking overnight in a bad neighborhood with the doors unlocked, then crying to the media about how they were robbed by criminals. There has to be some level of personal responsibility; it's foolish to expect people to not do bad things just because the law says they shouldn't.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#28

Cyberattack day! This one happened over a month ago, its obvious this is a trending headline likely not organically, so make sure to separate the dates before thinking we are under a coordinated attack all at once right now

I think on HN this has always been a trend. a headline sparks more headlines of similar stories regardless of date. I've seen it happen quite frequently.

I've also noticed. I think once interest is sparked in a topic, any topic, people are thirsty for more. I don't think it's the most useful way to orderly accumulate knowledge of a subject but there it is, i'm as guilty as the next guy.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#29
post #9
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

The primary thing to help randsomemware would be to have tested backups, where you can reimage the computers and restore from backups reasonably quickly.

I think the perpetrators are now taking data "hostage", and threatening to release it publically unless the ransom is paid - in this case backups don't help, though it depends on how sensitive your data is.
Post reply on HN