Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

351–360 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#351

Really good thread here: https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.

It is a sad say when Reddit has higher quality details than HN.

Re: US companies hit by 'colossal' cyber-attack

#352

Earlier quoted context omitted.

>You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down. I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what…

Equifax’s stock is up 50% from a year ago. I’d say this hack did nothing bad for their stock.

Seems long covid fogs the market analysts brains too.

Re: US companies hit by 'colossal' cyber-attack

#353

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

The interesting part about last year's incidents of solarwinds, fireeye and fortinet is that there's a switch away from actually targeting the hosts after the first line of defense. Redteams / hackers now target the infastructure, because it's way easier and they're more outdated in regards of code, stability and used libraries. Most enterprise-grade VPN solutions still use OpenSSL from decades ago, and most of their…

WireGuard is a simple and secure new protocol that most VPN companies are moving to. It doesn't do the key rotation or TOTP authentication part however.

Re: US companies hit by 'colossal' cyber-attack

#354

Earlier quoted context omitted.

It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.

Long term shareholder returns are directly correlated to the long term company success. It's always such an odd criticism to think of "shareholder returns" as a pejorative.

They key is long-term

Re: US companies hit by 'colossal' cyber-attack

#355

Earlier quoted context omitted.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair c…

Then why is the SEC public, it could arbitrarily issue fines and fuck with the share price of any company that didnt donate to your party, maybe it should be private too?

Different role, different scope, different situation. The SEC has limited power to target individuals compared to a credit rating agency. It would be a scandal to politicize the SEC, but it would not be the sort of nightmare that a politicized credit rating agency could become.

It is also worth pointing out that both the credit ratings and audits of publicly traded corporations are conducted by private-sector companies, not government agencies. The SEC's primary role is to ensure that the rules are being followed, which is a straightforward law-enforcement/regulatory role that makes sense for a government agency.

Re: US companies hit by 'colossal' cyber-attack

#356
post #52

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

The argument by people who understand how banking systems work is that cryptocurrencies facilitate anonymous transfers of large amounts of money with zero risk to the criminals.

https://www.stephendiehl.com/blog/ransomware.html

Re: US companies hit by 'colossal' cyber-attack

#357
post #218
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

> like fines and people going to jail for negligence Being bad at your job is not negligence, nor is underestimating the threat. It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups. Don’t some of these companies have… shareholders?

In case of Equifax, for example, they're in a quasi-cartel with only two competitors.

It's quasi-monopolistic. It has the same problems : nobody gives a flying furry about actual performance.

Re: US companies hit by 'colossal' cyber-attack

#358

Earlier quoted context omitted.

It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.

Long term shareholder returns are directly correlated to the long term company success. It's always such an odd criticism to think of "shareholder returns" as a pejorative.

TheOtherHobbes said "only", as in "to the exclusion of all other concerns". Where's the pejorative?

Re: US companies hit by 'colossal' cyber-attack

#359

These kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the poi…

> I'm pretty much at the point of thinking people need to learn how to write on paper and whiteboards again. Health IT here: won't happen. You need your CT NOW. The patient is about to be opened. There is no time to wait for the printer and it's Sunday night. The radiologist is at home examining the data while the scanner runs. And man...security is so bad and it's so hard to convince management to invest into proper…

Well, that's the scariest thing I've read all week. Just reading your level of stress between the lines here gives me the chills. Why is it so hard to convince them to take security seriously? Especially with hospitals, this should be a national security issue. The consequences are right in everyone's face now. In my case, an attack might be expensive, even dire, but no one would die. I know why I have a hard time pushing security reviews, they're costly and intensive and not sexy for management or investors. But things like this need to make it clear to the c-suite how quickly the wheels can come off.

Re: US companies hit by 'colossal' cyber-attack

#360
post #312

These kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the poi…

> We set up software on a lot of machines Windows, right?

In the case I had in mind, the company runs a mix of windows and os x. And some android. Luckily it's mostly mac in the shops now, but personal laptops and tablets that connect to the LANs are also involved, and definitely the most dangerous point of failure.
Post reply on HN