Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

251–260 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#251

Earlier quoted context omitted.

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

That's not what I've said. I'm not a financial expert by any means but I think the stock market has proved again and again that it is not reliable and can be manipulated easily. People short-squeezing stocks, shooting their "value" by 30x in 2 hours making them millionaires. Hedge funds manipulating stocks to meet their portfolios IPO's in billions of dollars for new, non-profitable startups just because of hype. whe…

It will crash, predicting when is something else. I was correct in 2001 and 2008 but I was wrong in the past years as the market has been overheated for quite a while (I thought we would've crashed already) and both in stocks and recently in crypto, I have been hearing 'this is the new normal, all is different this time around'. Which is what people always say just before the carpet gets pulled.

Re: US companies hit by 'colossal' cyber-attack

#252

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

Gee, cashless is such a great idea. In related news, I saved money by replacing all my house's circuit breakers with old pennies.

I dont think this is necessarily due to 'cashless' as much as general computerization. Stuff like prices, article numbers and inventory are likely all digitized nowadays, so even if people could pay with cash I imagine they'd still be keeping closed.

Re: US companies hit by 'colossal' cyber-attack

#253

Earlier quoted context omitted.

This is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.

Perhaps, but of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder thanks to Citizens United and armies of lobbyists. Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries. I think it’s safe to say that corruption and greed are at the ro…

> of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder

I would contend with that. The US government is just very visible. I know HN likes to glorify European nations but we're really really good at wasting taxpayer money, too. It's just less lobbying and more knowing the right people here.

Re: US companies hit by 'colossal' cyber-attack

#254

Earlier quoted context omitted.

A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.

In my country (Switzerland), while they have massively invested in cashless solutions, a lot of places are still accepting cash, and I think it is a good thing. One of the big retailer (Coop) has self-checkout machines that accept and give back cash (you can insert 200CHF~216USD at a time if you want).

Jordan (head of SNB) is not going to let cash go and even kept the CHF 1000 bill under EU pressure. Thank God.

What urks me is the obvious "never let a crisis go to waste" where we have visa etc marketing that cash might spread Corona.

Yes, I've put CHF 200 in coop register before. Funny, they don't care but if I scan a tiny bottle of alcohol I need to wait for someone to approve it...

Re: US companies hit by 'colossal' cyber-attack

#255
post #193

Earlier quoted context omitted.

Your quote cuts off before the salient part, and you seem to be attacking an imaginary argument. > tools that have extreme low-level access to networks and systems The emphasis being on the low level access. The solution is not having hundreds of people checking things by hand (though I'm sure that could contribute to security). The solution is more privilege separation; so that when the "remote monitoring tool" is c…

I'd agree partially with you. However, once a remote agent is compromised, it will be chained with some privilege escalation vulnerability and this same argument will be repeated with the twist that now every foreign executable with remote connection is an attack surface. Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your reso…

IMO, a big issue is conflating monitoring with management.

Management is always going to have access, so maybe you should not enable remote management access of everything to a centralized system? Make it lean and secure, possibly segmented, dual-factor, use HSM etc.

Monitoring - there is no good reason why it should have access to anything. Make it ingest only (use firewalls and reasonable protocols), and you've cut out most of the "monitoring and management" vulnerabilities.

Re: US companies hit by 'colossal' cyber-attack

#256

These digital networks and devices have become so complex we can’t reason about them, or in any case can’t easily reason about them given the resources available to most of the organizations running them. However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).

Mostly, they're neglecting training their employees to keep the business running when the software is down.

Re: US companies hit by 'colossal' cyber-attack

#257
post #218
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

Where does "being bad at your job" stop and "negligence" begin?

Some jobs come with certain responsibilities. Of course we need to have some leeway for e.g. doctors making honest mistakes – they're only human after all – but at some point that stops.

Re: US companies hit by 'colossal' cyber-attack

#258

Earlier quoted context omitted.

Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…

If the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.

> that's probably a sign that the stock market is massively overvaluing everything

No it's not. The performance of stocks was always only weakly linked to actual company performance.

There are countless examples of companies that are hardly profitable and not even a tenth the size of their competition, but are valued at twice the price of some of their competitors. It's mostly made-up prices created entirely on hype that often make less sense than the soccer trading card market.

Re: US companies hit by 'colossal' cyber-attack

#259

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

At some point you cross the threshold of "this is too much, drone them". Or send an assassin. Yes, even the United States does this occasionally. I suspect the attackers know this. Or else they aren't in it for the money. One or the other.

The catchy rhyme being "warheads on foreheads".

Re: US companies hit by 'colossal' cyber-attack

#260
post #209
post #167

Earlier quoted context omitted.

I keep reading over and over again indignant comments about "cost centers" on Hacker News and I think it's not a good term to use because I looked up the definitions and the only logical consensus I could find is that everything which isn't shareholder profit is a cost center. It's just rhetoric.

I don't think it is - I think it's cultural and organisational. The CFO and Finance in general see businesses as capital flows, they don't see value being added - just opportunities for leverage and cash management. The description of a cost center is a labelling denoting a target for removal and reduction - the destruction of value that occurs (typically 12 -24 months after the exercise) is seen as disconnected and…

Eye of the beholder topics don't generalize. If your CFO and Finance team is doing things like laying off all the information security people since they thought Axa would pay the ransom gangs, then state the name of the company. Otherwise it's just venting handwavy frustration about people whose job requires taking risk mitigation seriously.
Post reply on HN