Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

31–40 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#32
post #12

Earlier quoted context omitted.

Lowers the percieved incompetence on hacked side, and its hard to argue against (how do you prove it wasnt?). Stock price fall distaster mitigation via simple PR. But I agree experts should know better when of any solid proof is lacking. Or any proof at all.

What I'm saying is they often actually mean "country", but that is less fancy sounding. A nation-state is just one specific type of polity, certainly not the only type which organize attacks.

You’re overthinking it. “Country” is simply more ambiguous when used as an adjective. “F5 announces attack from country hackers” sounds silly and confusing.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#33

[flagged]

Nation-states sponsored hackers make up a huge amount of known targeted intrusion groups. This is not some random company tilting at windmills, these are real threats that hit American and American-aligned companies daily.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#35

[flagged]

> I keep seeing it pop up again and again and it only makes sense in that context.

Not saying that these companies would turn down corporate welfare given the chance, but I’ll offer an alternative explanation: it shifts accountability away from the company by positing a highly resourced attacker the company could not reasonably be expected to protect against.

If you have a physical security program that you’ve spent millions of dollars on, and a random drug addict breaks in and steals your deepest corporate secrets people are going to ask questions.

If a foreign spy does the same, you have a bit more room to claim there’s nothing you could have done to prevent the theft.

I’ve seen a bunch of incident response reports over the years. It is extremely common for IR vendors to claim that an attack has some hallmark or another of a nation-state actor. While these reports get used to fund the security program, I always read those statements as a “get out of jail free” card for the CISOs who got popped.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#36
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Nation-state actors do this kind of stuff all the time, and they're difficult to defend against because they tend to be well-funded and therefore able to hire talent, have resources, and spend money on intelligence and 0days. And they're immune from prosecution unless they're stupid enough to travel to a hostile state.

North Korea really does spend a lot of money on this, and so does Russia and China. And US and Israel, for that matter.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#37

Earlier quoted context omitted.

They say the attacker exfiltrated data, including source code. They claim the vulnerabilities discovered through the exfiltration were not used though.

Not sure why I'm downvoted. Literally quoted from their incident page. > We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. > We have no knowledge of undisclosed critical or remote cod…

> Not sure why I'm downvoted.

I downvoted you for complaining about downvotes, so at least you know the reason for one of them now.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#39

[flagged]

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone militar…

You can get a lot of fat kids on a computer in a bedroom for the cost of building and maintaining a 6th Gen fighter.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#40
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

No, it's a real thing with a real meaning. Nation-state actors are, in general, very well-funded and sophisticated, and therefore much more difficult (and expensive) to defend against and clean up after. They tend to have different motivations than the normal crime groups, and therefore go after different things.
Post reply on HN