Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

41–50 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#41
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks. Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise. If I had a static environment with no new software or business processes, then NO PROBLEM. I can lock it down in every kinda way and it stays locked down to a known baseline. Add to that new…

Those are all reasons why a network/company cannot be 100% invulnerable to hacks, but it doesn't answer the question of if a company can be be significantly more resistant to ransomware. My answer to that question is "absolutely".

These ransomware attacks are so devastating in no small part due to decisions Microsoft made many years ago. Combining authentication, remote administration, file sharing, printing, event monitoring, security policy updates, and the kitchen sink into Windows Networking. An attacker compromises a single Windows machine and has leeway to attack critical servers across the network. If real segmentation of services were reasonably possible in a Windows environment a single credential couldn't be used to hop between systems and encrypt file services everywhere. Not to say some segmentation isn't possible in these environments but the skills and hours needed to accomplish it are far beyond what most companies have available.

And that doesn't even begin to cover the Exchange/Outlook dominance and poor security choices that lead to the higher rate of success for phishing attacks.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#42
post #11
post #4

Earlier quoted context omitted.

there are standards and operating procedures that can be used. it’s not that hard. it comes down to training and cost cutting. If the penalty for failing miserably is 0 you won’t see any change. I would hold the companies responsible for things like this liable to the point they would be put out of business after an event like this. If the cost of being sloppy is that you no longer have a business people will start p…

> there are standards and operating procedures that can be used 99% of these standards are completely useless and exist only to reduce legal liability. The other 1% are only incidentally slightly useful. You will never ever create a secure company by following some stupid checklist, unless the checklist is so extreme as to be useless to most orgs. “Step 1: only run OpenBSD…”

a checklist is not where it begins, but it is where it starts. if you don’t have it you probably don’t know what you’re doing

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#43
post #9
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

The primary thing to help randsomemware would be to have tested backups, where you can reimage the computers and restore from backups reasonably quickly.

Backups are absolutely essential but I think you understate the amount of hours needed to restore an entire corporate network if it's compromised and encrypted at once. (As Colonial apparently found out)

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#44
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

Although password routine expiry is not a recommended strategy now, it'a really good indication of how this can look.

For a long time, people like insurance companies had an "enforceable standard" for 60/90 day password rotation. And in every single business I looked at, they "had a password rotation policy", but then three key executives didn't like it so "do not expire password" got ticked on their accounts as some "accepted exemption". This sort of thing always passed audits, and marketing always wrote information about how the business had a strict password expiry policy. And those executives were the most likely to be compromised.

I think if you go too far down a "minimum standard" path, that's the sort of thing you're going to see.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#45

Just curious if "ties to China" means "an IP address that may or may not be allocated to Chinese geography, and may or may not simply be a Tor exit node or a VPN service." People are far too trusting of these claims of where these attacks originated. Very few people in the world, including journalists, know how IP networks work.

I don’t think regular person/organisation can host Tor node or VPN server in China.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#46

Just curious if "ties to China" means "an IP address that may or may not be allocated to Chinese geography, and may or may not simply be a Tor exit node or a VPN service." People are far too trusting of these claims of where these attacks originated. Very few people in the world, including journalists, know how IP networks work.

Crowdstrike attributed the 2015/2016 DNC "Hacks" to Russia based solely on a file creation timestamp in the same timezone as Moscow and the presence of Cyrillic in a Word document's metadata, and the western world ran with it for years. Don't expect much.

The "Russian" Twitter propagandists were identified based on a similarly specious methodology, and I only ever encountered one article (Wired) they even bothered to mention it. And in many, many internet conversations I've had, I've not once met a believer who had the ability to consider whether authenticity was important, even while they mocked their outgroup for believing whatever story pleases them.

People are funny.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#47

Earlier quoted context omitted.

The media needs something to scream about after corona is over. It looks like Russian and Chinese hackers are on the menu.

Corona isn't over and we should still be screaming at the top of our lungs at the Chinese for answers. Instead of going out to the shops and buying brooms to sweep the topic under the carpet (which are also recent buys).

> Instead of going out to the shops and buying Chinese made brooms to sweep the topic under the carpet (which are also recent buys).

FTFY

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#48

Just curious if "ties to China" means "an IP address that may or may not be allocated to Chinese geography, and may or may not simply be a Tor exit node or a VPN service." People are far too trusting of these claims of where these attacks originated. Very few people in the world, including journalists, know how IP networks work.

Crowdstrike attributed the 2015/2016 DNC "Hacks" to Russia based solely on a file creation timestamp in the same timezone as Moscow and the presence of Cyrillic in a Word document's metadata, and the western world ran with it for years. Don't expect much.

Why would you think this? They found shared infrastructure and TTPS related to other attacks for the actors.

edit: And what's with the "hacks" scare quotes? We know exactly how the attack happened, step by step... in what way was it not a very straightforward hack?

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#49
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

Most people will say no, but I think if you add some constraints it gets a lot easier. Things like MFA and a zero trust approach are extremely effective against attackers. If you have the ability to start early and get that sort of approach in place you're going to be one of the harder targets out there.

There's obviously way more to it than that, but a huge problem today is that once an attacker gets into a network they can hop around as they please due to implicit trust. Removing that implicit trust and checkpointing access via u2f are huge barriers.

It's also not super hard imo to gradually move to.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#50
post #21

Just curious if "ties to China" means "an IP address that may or may not be allocated to Chinese geography, and may or may not simply be a Tor exit node or a VPN service." People are far too trusting of these claims of where these attacks originated. Very few people in the world, including journalists, know how IP networks work.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.
Post reply on HN