Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

41–50 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#41

This demonstrates two major points that many people not familiar with security may not understand: The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach w…

You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level security executive) of a multi-billion dollar company ever answer the question: "How much would it cost to critically compromise your systems and do an unrecoverable amount of damage?" with a number higher than $1,000,000. $1,000,000 is a rounding error to these companies. $1,000,000 is a rounding error in a rounding error to a sizable nation-state. These systems are not just insecure against nation-state attackers, they are insecure against organizations with the staggering weight of 3-10 people. Or, to use a quote from the recent Project Zero blogpost on the iOS exploit said: "one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with." That is a far cry from being secure against credible threats to a multi-billion dollar business by any stretch of the imagination.

Are systems more secure now than they were in the past? Maybe. A targeted attack against an arbitrary target would generally take a few 10 to 100s of thousands of dollars. This is probably orders of magnitude more than the past of teenagers hacking for giggles. But, there are like 6-8 orders of magnitude between teenagers hacking for giggles and a "nation-state actor" and about 3 orders of magnitude between a random company/organization and a nation-state. The best systems deployed systems are about as close to adequate as a house is to a skyscraper.

Re: FireEye Shares Details of Recent Cyber Attack

#42
post #11
post #10

The problem with these articles is the cloak and dagger nature of these stories and the lack of healthy skepticism. While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor. In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School. You never r…

Maybe you should try to gain a basic understanding of what you're talking about before posting this /pol/ conspiracy theory stuff? There exists very little doubt that NK was behind the Sony hack, there's even a federal indictment. >It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath. This is a complete fabrication by you, utterly unsupported by the link you shared which…

Here is the congressional sworn testimony of Shawn Henry, the CEO of Crowdstrike, specifically saying that there is no concrete evidence of Russian hacking of the DNC.

https://intelligence.house.gov/uploadedfiles/sh21.pdf

You can peruse the whole pdf or jump straight to the money quote on page 32.

As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking Sony. In fact, there was a smoking gun to a disgruntled ex employee. On a side note Sony and Sony entities were publicly hacked over 18 times prior to this as “revenge” for the PS lawsuit against the hacker who exposed encryption keys of the Playstation.

https://www.wired.com/2014/12/evidence-of-north-korea-hack-i...

https://en.wikipedia.org/wiki/Sony_Pictures_hack#Doubts_abou...

https://www.wired.com/2014/12/evidence-of-north-korea-hack-i...

Re: FireEye Shares Details of Recent Cyber Attack

#43

I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…

>I'm not sure anything can protect against a targeted attack from a nation-state.

hardware airgap can go a long way

Re: FireEye Shares Details of Recent Cyber Attack

#44

I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

Didn't help Iran: https://en.wikipedia.org/wiki/Stuxnet

Re: FireEye Shares Details of Recent Cyber Attack

#45
post #38
post #36

Earlier quoted context omitted.

They are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?

It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.

I mean, it's only over the top of it isn't true. Those are all words people have used to describe intrusions in the past, like Stuxnet or Sandworm.

Re: FireEye Shares Details of Recent Cyber Attack

#46
"They used a novel combination of techniques not witnessed by us or our partners in the past."

This is the scary part. FireEye and the others have been studying and watching APTXX nation-state teams for many years. They should have some idea by now. It is entirely possible that a new team is out there.

Re: FireEye Shares Details of Recent Cyber Attack

#47
post #31
post #29

Huge target on their back no matter what. Like those movies where the tough guy is tested when he gets to prison. This is where it does not pay to be a public company. If they weren't a public company they wouldn't have to disclose this or acknowledge it and there most likely would not be a credibility damaging story which is easy to find. Sure the story could have gotten out but it would not be easy findable and wou…

> Why say that? Why not just say you were attacked and going to try and determine why and make any changes Because they would be out of business tomorrow if they say they think it was a 13 year old from Ohio just fooling around on a Sunday. This is FireEye marketing itself for the F500 by selling fear of an invisible adversary with unlimited resources that already deliver innovative black hat capabilities.

> if they say they think it was a 13 year old from Ohio

How could you read my comment and think that is what I thought they should say?? I said not to say anything. And why use hyperbole ie 'they would be out of business tomorrow'.

And no it's not marketing anymore than if a Karate expert airs that he was beat up in an alley and then says 'but the person was 9 feet tall that's why!'. (But sure to your point if they said 'by a 13 year old' that would not be better but once again I didn't say that.)

Re: FireEye Shares Details of Recent Cyber Attack

#48

"They used a novel combination of techniques not witnessed by us or our partners in the past." This is the scary part. FireEye and the others have been studying and watching APTXX nation-state teams for many years. They should have some idea by now. It is entirely possible that a new team is out there.

They are probably trying to make it look like they got hit by a clever attack, rather than SQLi or a XSS.

Re: FireEye Shares Details of Recent Cyber Attack

#49
> During our investigation to date, we have found that the attacker targeted and accessed

did their best to bury the lede. they say they were targeted multiple times, but dont say they were breached until the fourth paragraph, something like 40% of the way through - even then the admission is intentionally mentioned vice announced. i understand fireeye is a security company, but pussyfooting is pussyfooting and weasel words are weasel words.

idk, politics is part of the game at the highest level. maybe im not destined for the c-suite.

Re: FireEye Shares Details of Recent Cyber Attack

#50

I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

Airgaps protect against low to medium level attackers. Nation state tools for bypassing airgaps are a dime a dozen.

One of the most common is interdiction of computers in shipping and installation of hardware implants.

Post reply on HN