Earlier quoted context omitted.
If we, the west, let Russia take Crimea and China take Hong Kong with minimal fuss, I don't see why a few cyber attacks would get more attention.
Take over? I thought Hong Kong was given back?
US companies hit by 'colossal' cyber-attack
411–420 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#412These kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the poi…
Re: US companies hit by 'colossal' cyber-attack
#413After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
Re: US companies hit by 'colossal' cyber-attack
#414Earlier quoted context omitted.
Yes. In case you're asking what OPM is and not just the acronym intended, OPM is an agency that manages and maintains stewardship of a stupid amount of information about all employees that work for or closely with the federal government. Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employ…
Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…
Re: US companies hit by 'colossal' cyber-attack
#415Really good thread here: https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.
It is a sad say when Reddit has higher quality details than HN.
Re: US companies hit by 'colossal' cyber-attack
#416Earlier quoted context omitted.
If we outlaw money no one will rob people don’t you know?
What would you rob from someone on the street, who isn't carrying any expensive item, especially no fungible ones? In the past, there were often abductions for ransom. This has mostly stopped, as the police always got the abductors when they tried to collect the money.
Re: US companies hit by 'colossal' cyber-attack
#417https://www.zerohedge.com/geopolitical/cyber-polygon-will-ne...
Re: US companies hit by 'colossal' cyber-attack
#418After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
Re: US companies hit by 'colossal' cyber-attack
#419Earlier quoted context omitted.
The interesting part about last year's incidents of solarwinds, fireeye and fortinet is that there's a switch away from actually targeting the hosts after the first line of defense. Redteams / hackers now target the infastructure, because it's way easier and they're more outdated in regards of code, stability and used libraries. Most enterprise-grade VPN solutions still use OpenSSL from decades ago, and most of their…
WireGuard is a simple and secure new protocol that most VPN companies are moving to. It doesn't do the key rotation or TOTP authentication part however.
Using a token generator with embedded analytics was just wrong in the first place, but...yeah.
Personally I'd love to see better Wireguard support and adoption outside the Linux world.