Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

21–30 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#22
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Because "We got hacked by the concerted efforts of China/Russia" sounds much better than "We literally never update php or linux, and John Script Kiddy Jones pwnd us".

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#23
post #12

Earlier quoted context omitted.

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Lowers the percieved incompetence on hacked side, and its hard to argue against (how do you prove it wasnt?). Stock price fall distaster mitigation via simple PR. But I agree experts should know better when of any solid proof is lacking. Or any proof at all.

[deleted]

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#24

Source: https://my.f5.com/manage/s/article/K000154696

The NCC attestation letter is wild:

F5, Inc. (“F5”) engaged NCC Group to perform (i) a security assessment of critical F5 software source code, including critical software components of the BIG-IP product, as provided by F5, and (ii) a review of portions of the software development build pipeline related to the same, and designated as critical by F5 (collectively, the “In-Scope Items”). NCC Group’s assessment included a source code security review by 76 consultants over a total of 551 person-days of effort.

Wonder what the bill was?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#25
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

BRB, changing handle to 'nation-state'. Need the resume fodder.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#27
post #12

Earlier quoted context omitted.

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Lowers the percieved incompetence on hacked side, and its hard to argue against (how do you prove it wasnt?). Stock price fall distaster mitigation via simple PR. But I agree experts should know better when of any solid proof is lacking. Or any proof at all.

What I'm saying is they often actually mean "country", but that is less fancy sounding. A nation-state is just one specific type of polity, certainly not the only type which organize attacks.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#28
post #8

Earlier quoted context omitted.

BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...

This is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.

It seems like its a place were there are some serious tradeoffs. You can choose to have visibility into your network traffic or can choose not to. If you choose yes, you create a single point of failure but have the ability to detect breaches elsewhere; if you choose no, you avoid the single point of failure but make it easier for an attacker to exfiltrate data undetected.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#29

[flagged]

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this.

If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone military network, is basically infinite free IP.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#30

Earlier quoted context omitted.

They say the attacker exfiltrated data, including source code. They claim the vulnerabilities discovered through the exfiltration were not used though.

Not sure why I'm downvoted. Literally quoted from their incident page. > We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. > We have no knowledge of undisclosed critical or remote cod…

No, they claimed: "We have no knowledge" and "we are not aware" which does not mean "the vulnerabilities discovered through exfiltration were not used".

That admits nearly every possible class of outcome as long they did not actively already know about it and chose to say they did not. The specific words that their lawyers intentionally drafted explicitly even allow them to intentionally spend effort to destroy any evidence that would lead them to learn if the vulnerabilities were used and still successfully claim that they were telling the truth in a court of law. You should not assume their highly paid lawyers meant anything other than the most tortured possible technically correct statement.

PR statements drafted by legal are a monkey's paw. Treat them like it.

Post reply on HN