A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…
CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
41–50 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#42I find it ironic that the CIA didn't bother to have it's systems secured/verified by the NSA. I'm sure the CIA thought that they were good enough, coming from an organization that was infiltrated from its inception, their hubris isn't surprising.
My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.
Half of the NSA's mission is to build/design secure communication systems for the US government and military.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#43How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
This is why I've been so concerned about cybersecurity and cyberwarfare. I do not see gross competence here and most of the people I respect that write about this type of thing are sounding the alarm. Click Here to Kill Everybody or Matt Tait (@pwnallthethings on Twitter) ending an Infiltrate conference talk with a nuclear bomb as the final image.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#44This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company. T…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#45A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…
Also, I'm sure those members of "the hacking team" weren't allowed to discuss their work with their family/friends, so it's not terribly unrealistic to expect them to use even just basic security hygiene (eg. don't share admin passwords).
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#46Earlier quoted context omitted.
Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company. T…
I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.
I can imagine the average corp board member underestimating the risk accumulated by consistently ignoring CISO request for more cybersecurity investments, but the insurance industry is used to dealing with the low-frequency, high-impact payouts.
Do you think it was mis-communication, ignorance, greed, hubris, or something else?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#47I find it ironic that the CIA didn't bother to have it's systems secured/verified by the NSA. I'm sure the CIA thought that they were good enough, coming from an organization that was infiltrated from its inception, their hubris isn't surprising.
My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.
Even if it was a "hey, could you look at this and tell us what you think" with no obligation to address issues, it is undesirable to establish a precedence.
They do use standards and recommendations from NSA/OMB for enterprise systems. But even the US Courts went that route, just with a lot of renaming of things so it can't be seen as being subservient to the Executive branch. There are some good frameworks and standards that you shouldn't waste time re-implementing.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#48Earlier quoted context omitted.
What would be a less gimmicky setup?
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#49>34 terabytes of information, or about 2.2 billion pages. That's insane that they could leave so much data available to be stolen.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#50How well protected do you think cyber-weapons designed to surveil countries, disable infrastructure, and destabilize governments should be? How capable and well-funded should the attacker need to be before gaining access to cyber-weapons designed to kill economies and people? $1B, $10B? A team of 1,000, 10,000?
Does anyone know of any system or organization in existence that would even be willing to claim they can stop a team of 1000 dedicated hackers working full-time for 10 years funded with $1B let alone put it in writing? What is the highest you have heard? Is it even in the general ballpark?
It is absurd to assume that the failure to solve the problem is just a lack of prioritization if no one even claims to be able to solve it and it is meaningless to propose that they should adopt policies that do not even claim to be able to protect against the actual threat model let alone have evidence of such protection. They either need to find someone who will make the extraordinary claim that they can provide an actual defense and have the extraordinary evidence to back up that extraordinary claim or they MUST NOT deploy such systems since they can not be protected.