Earlier quoted context omitted.
What would be a less gimmicky setup?
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…
CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
31–40 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#32Earlier quoted context omitted.
What's the story re: backtrack2, for the uninformed?
I'm trying to find a citation here, but it's difficult because "Backtrack 2 ssh exploit defcon" is going to produce a lot of content which is unrelated. Anyway I can give you the skinny of the situation: 1) Backtrack 2 did not have an installer, it was a live-CD. But that doesn't stop you installing it by just copying the live environment to a disk (with some mount-binding and grub install, you're all good!) There we…
https://www.csoonline.com/article/2462478/hacker-hunts-and-p...
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#33This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#34This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#35To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205
Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online.
Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe.
And when will these state actors with unlimited funding figure out that NOBODY can keep secrets forever, not even them?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#36Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#37Guarding information and guarding physical assets have one thing in common. It is largely a passive exercise in waiting for something to happen. For this reason it is very boring and unreliable. The only way to improve the situation is to have active and random drills when someone attempts to steal the assets. This would make the work of the Blue team a lot more rewarding rather than just be relegated to mindless blo…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#38This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
This also contributes to perverted incentives (like the red/blue teams) where the CIO frequently gets their way and is more likely to get budget while CISOs take all the blame when their budget increase requests get declined and IT is tasked with keeping unpatched systems up and stable rather than patching systems quickly. Obviously, the best orgs find a way to get both done, but resources are always scarce for the rest of us.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#39Earlier quoted context omitted.
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…
That's good. Perhaps something like if they can attribute the attack to a particular machine the red team gets "arrested".
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#40How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
Put another way: perhaps it's not an accident? And perhaps some of what was leaked was a decoy?
Yes, keeping secrets is difficult. All the more reason to take advantage of that.