Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

31–40 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#31

Earlier quoted context omitted.

What would be a less gimmicky setup?

Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…

I kind of like the dual approach. First team to get in to the box has to try and hold onto it while still maintaining specified services it's supposed to be providing in the simulation. Winner is whoever holds it the longest.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#32
post #20

Earlier quoted context omitted.

What's the story re: backtrack2, for the uninformed?

I'm trying to find a citation here, but it's difficult because "Backtrack 2 ssh exploit defcon" is going to produce a lot of content which is unrelated. Anyway I can give you the skinny of the situation: 1) Backtrack 2 did not have an installer, it was a live-CD. But that doesn't stop you installing it by just copying the live environment to a disk (with some mount-binding and grub install, you're all good!) There we…

I don't remember that one but it's similar to the wifi pineapple vulnerability that was being exploited a few years ago.

https://www.csoonline.com/article/2462478/hacker-hunts-and-p...

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#33

This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…

Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.

I disagree completely. Red team tools and techniques are different and gimmicky for a reason, their goal is to demonstrate lack of or effectiveness of security controls and processes. While bad guys have more time and more precise target. For example, 0days and disruptive actions are mostly prohibited for red teamers

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#34

This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…

That's why "purple team" is the way (not sarcasm for people not aware of purple team methodology)

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#35
How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed?

To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205

Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online.

Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe.

And when will these state actors with unlimited funding figure out that NOBODY can keep secrets forever, not even them?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#36
A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feasible, persisting,lateral movement and exfiltration without getting caught is very difficult but even commercial tools like cobaltstrike are built to allow different teams to focus on different stages of a hack.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#37

Guarding information and guarding physical assets have one thing in common. It is largely a passive exercise in waiting for something to happen. For this reason it is very boring and unreliable. The only way to improve the situation is to have active and random drills when someone attempts to steal the assets. This would make the work of the Blue team a lot more rewarding rather than just be relegated to mindless blo…

I mean you have more or less described a modern Cyber security Red Team.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#38

This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…

Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company.

This also contributes to perverted incentives (like the red/blue teams) where the CIO frequently gets their way and is more likely to get budget while CISOs take all the blame when their budget increase requests get declined and IT is tasked with keeping unpatched systems up and stable rather than patching systems quickly. Obviously, the best orgs find a way to get both done, but resources are always scarce for the rest of us.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#39

Earlier quoted context omitted.

Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…

That's good. Perhaps something like if they can attribute the attack to a particular machine the red team gets "arrested".

Easier said than done, the red team can’t break real laws (routing through compromised hosts) where real hackers will.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#40

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

Absolutely. So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use.

Put another way: perhaps it's not an accident? And perhaps some of what was leaked was a decoy?

Yes, keeping secrets is difficult. All the more reason to take advantage of that.

Post reply on HN