Live data from Hacker News

At Facebook, zero-day exploits, backdoor code bring war games drill to life

arstechnica.com

31–40 of 52 posts

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#31
post #27
post #14

I'd be moderately pissed off if I got stuck in a drill for 24h+ without knowing it was a drill, unless it was a known thing that drills would be run routinely. There is stuff I'd do for "real" (missing one-off personal events, etc.) which I wouldn't do for training. I'd skip out on a wedding (well, I always do anyway), funeral, etc. for a real security issue, but would quit the next day if I had done so for training…

I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole th…

> I had no idea we'd go so far as buying a 0-day

Where did they get the 0-day?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#33
post #31
post #27

Earlier quoted context omitted.

I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole th…

> I had no idea we'd go so far as buying a 0-day Where did they get the 0-day?

The phrase "if you have to ask the price, you can't afford it" comes to mind....

If you don't know where to aquire (buy) 0-days, then you probably shouldn't know.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#34
post #22
post #13

Earlier quoted context omitted.

Because it was all staged?

But then what about this : "The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. (Facebook promptly reported it to the developer.) It allowed a "red team" composed of current and former Facebook employees to access the company's code production environment. (The affected software developer was notified before the drill was disclosed to the rest of the Faceb…

They could have planned out a drill and then waited for the first vulnerability they could exploit.

Edit: mkjones says they bought the 0-day: https://news.ycombinator.com/item?id=5199757

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#35

A drill? This is so cheesy. Makes working at Facebook sound like Office Space. Only thing missing is TPS reports.

Without drills, how would you suggest Facebook tests the response times and standards of their security teams? If you want to know how the team will react under pressure, you essentially have two options:

- make up a fake security alert

- wait until a real attack is underway

Perhaps I'm missing something, but I do not see a connection to Office Space.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#36

> If it were any other industry and it was any other critical function of a product not doing this you'd have people screaming that [the companies] were negligent and wanting to sue them left and right. Are Facebook and Google critical functions?

Well, google possibly, but, yeah, FB being deemed "critical" is a bit of a mystery to me. I can more accept twitter being "critical".

I would have thought infrastructure is properly "critical", various websites not so.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#37
post #6

The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

I'm trying really hard not to read your post in Ned Flanders' voice.

But in terms of 0-day exploits, I believe there is a ready market for them if you know where to look, and are willing to pay.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#38
post #34
post #22

Earlier quoted context omitted.

But then what about this : "The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. (Facebook promptly reported it to the developer.) It allowed a "red team" composed of current and former Facebook employees to access the company's code production environment. (The affected software developer was notified before the drill was disclosed to the rest of the Faceb…

They could have planned out a drill and then waited for the first vulnerability they could exploit. Edit: mkjones says they bought the 0-day: https://news.ycombinator.com/item?id=5199757

All very nice, but the article clearly says that they disclosed the backdoor to the developer after the drill.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#39
post #24
post #14

I'd be moderately pissed off if I got stuck in a drill for 24h+ without knowing it was a drill, unless it was a known thing that drills would be run routinely. There is stuff I'd do for "real" (missing one-off personal events, etc.) which I wouldn't do for training. I'd skip out on a wedding (well, I always do anyway), funeral, etc. for a real security issue, but would quit the next day if I had done so for training…

The article says that in an earlier test, "the organizers made an exception, however, when early in the drill, an employee said the magnitude of the intrusion he was investigating would require him to cancel a vacation that was scheduled to begin the following week. McGeehan pulled the employee aside and explained it was only a drill and then instructed him to keep that information private." I'd hazard a guess that t…

I'd seriously consider giving that employee a small raise. Skipping a vacation for work is actually a pretty loyal thing to do.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#40

Meh. Rest of world (including many governments) "we are not allowing use of Facebook for the intelligence threat it poses against our entire societies". Techy people: "Facebook isn't good for your privacy, internet users!" Facebook PR puff piece: "Look, we take security very seriously, we even dumped some serious money on it!" Bottom line: you can have great people but when you are such a high profile target holding…

Your imagination seems a little lacking if you think that the only outcome of such an attack on Facebook was the disclosure of personal information.
Post reply on HN