Live data from Hacker News

Microsoft confirms Russian spies stole source code, accessed internal systems

theregister.com

21–30 of 38 posts

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#22
post #18

Earlier quoted context omitted.

Sure I am not claiming that you can't figure out who or where the hackers are. I am claiming that you more or less have to arrest them and get their computers to be even remotely sure, and that it is trivial to frame hackers or "frame" the plot of dirt where they are located, for a hack. Especially so, when the victim can shift blame to CYA. If the methodology is secret because secret, I as a observer just assumes ev…

I’m not sure how this shifts blame? In my opinion the blame sits squarely on the shoulders of the entity whose systems were exploited. Microsoft is responsible for the security of their systems, full stop. Doesn’t matter if the GRU did it or some random guy in Venezuela. How do you know Microsoft was even “hacked”? I mean if you want to get super pedantic about this, I haven’t personally seen any proof. So yes while…

> you can google for threat actor attribution.

I've had a interesting life. I'm a expert in not getting "attributed" if you will. No need.

> Private companies do this work as well as governments.

It's mostly private snake oil vendors.

Famously the FBI used a conclusion a private company, hired by a presidential campaign made, as a pretext to engage in surveillance on their primary opponents campaign a few elections ago. They did no forensics themselves. They didn't even get the full report and what they got was heavily redacted![0]

[0]https://consortiumnews.com/2019/06/17/fbi-never-saw-crowdstr...

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#24

Remember when we all learned from the vault 7 leaks that the US government has the ability to create cyberattacks that appear to investigators to have come from another nation? We were doing that prior to 2017. Thank God someone like China can't ever do that, even nearly a decade after we did and we can trust these sort of accusations at face value and not at all think critically about them.

The cyberattacks which used the Marble framework were limited to those where a payload was delivered. Marble is comparable to mailing a bomb and putting a fake return address on the package. For data exfiltration, which is like robbing a bank vault, you'll need more than a fake address. It's orders of magnitude more difficult to cover your tracks, and you only need to leave one clue behind to undo all that work.

You don't think you can smuggle a few terabytes of traffic over the internet undetected?

For the US to have the capability to be aware of that they would have to be engaged in unconstitutional spying on US citizens. A thing they have claimed to have stopped doing.

"Trust us, we are lying"

P.S. this also means the feds have the ability to stop child sexual exploitation that takes place over the internet in its tracks but decided not to.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#25
post #18

Earlier quoted context omitted.

I’m not sure how this shifts blame? In my opinion the blame sits squarely on the shoulders of the entity whose systems were exploited. Microsoft is responsible for the security of their systems, full stop. Doesn’t matter if the GRU did it or some random guy in Venezuela. How do you know Microsoft was even “hacked”? I mean if you want to get super pedantic about this, I haven’t personally seen any proof. So yes while…

> you can google for threat actor attribution. I've had a interesting life. I'm a expert in not getting "attributed" if you will. No need. > Private companies do this work as well as governments. It's mostly private snake oil vendors. Famously the FBI used a conclusion a private company, hired by a presidential campaign made, as a pretext to engage in surveillance on their primary opponents campaign a few elections a…

So once again you turn this back into a Hillary Clinton conspiracy theory. I guess theres no moving on from something that happened seven years ago now. Last I checked, the guy who was running against her won and Obama peacefully transferred power to him.

Glad you’ve had an interesting life! Best of luck in your future endeavours.

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#26

Earlier quoted context omitted.

The cyberattacks which used the Marble framework were limited to those where a payload was delivered. Marble is comparable to mailing a bomb and putting a fake return address on the package. For data exfiltration, which is like robbing a bank vault, you'll need more than a fake address. It's orders of magnitude more difficult to cover your tracks, and you only need to leave one clue behind to undo all that work.

You don't think you can smuggle a few terabytes of traffic over the internet undetected? For the US to have the capability to be aware of that they would have to be engaged in unconstitutional spying on US citizens. A thing they have claimed to have stopped doing. "Trust us, we are lying" P.S. this also means the feds have the ability to stop child sexual exploitation that takes place over the internet in its tracks…

I think we're discussing different topics. The article headline says, "Microsoft confirms Russian spies stole source code, accessed internal systems." I interpreted your comment about vault 7 to imply that investigators (ie, MS & anyone that they asked to be involved) couldn't be certain this was Russia. I disagree with that; snuggling data leaves too many breadcrumbs. Your reply seems more focused on other parts of vault 7, and although I don't necessarily disagree with it, I'm not sure what you're trying to say here.

However, it's important to remember that FBI!=CIA!=NSA

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#28

Earlier quoted context omitted.

You don't think you can smuggle a few terabytes of traffic over the internet undetected? For the US to have the capability to be aware of that they would have to be engaged in unconstitutional spying on US citizens. A thing they have claimed to have stopped doing. "Trust us, we are lying" P.S. this also means the feds have the ability to stop child sexual exploitation that takes place over the internet in its tracks…

I think we're discussing different topics. The article headline says, "Microsoft confirms Russian spies stole source code, accessed internal systems." I interpreted your comment about vault 7 to imply that investigators (ie, MS & anyone that they asked to be involved) couldn't be certain this was Russia. I disagree with that; snuggling data leaves too many breadcrumbs. Your reply seems more focused on other parts of…

> snuggling data leaves too many breadcrumbs

I can understand these breadcrumbs in detail. From easy stuff like TCP and DNS to the design patterns of the radiation hardened firmware running on the communication satellites.

I propose a blinded trial, give me a API with a few terabytes of data I'll have it accessed and the data moved to a third party. Then Microsoft can tell me who that person is right?

Re: Microsoft confirms Russian spies stole source code, accessed internal systems

#29
post #8

Earlier quoted context omitted.

So you just are wildly speculating and assume this one technique you know about completely defeats teams of specialists with the budget of the richest country in the world It's one thing to point out issues with attribution. It's another to just say since we can't say with 100% certainty let's just make up attributions. Especially with no knowledge of the attributions certainty, they could be 99.9% sure

> we can't say with 100% certainty This admission is unknown to the general public, they "trust the experts" that it is 100 proven. > let's just make up attributions. If you aren't 100% it is Russia and scream Russia, that's what you are doing

>If you aren't 100% it is Russia and scream Russia, that's what you are doing

So anything attributing attacks to Russia is made up?

I think you've lost the benefit of the doubt I was giving you. The other reply to my post is probably right, you seem to be purposefully spreading disinformation.

Post reply on HN