Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

481–490 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#481

“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.” I don’t understand how Putin can stop these attacks unless he is personally responsible for them. Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them? The naivety of US government is just a…

It may be worth considering if you are naive in thinking that Putin doesn’t explicitly fund and direct the execution of cyber attacks against the west as a lever in improving Russia’s own relative standing. Why do you think he wouldn’t do so? American sponsors the same cyberattacks on Iranian and North Korean entities.

Define “fund”. I don’t think he directly funds most of those operations simply because there’s no need.

Imagine if Merrick Garland announced that he was using prosecutorial discretion to effectively decriminalize cyber attacks on foreign countries as long as they didn’t affect US interests and the best of its allies. The federal government wouldn’t need to fund the entrepreneurial ambitions of the US talent pool. They’d self-fund and make a mint in the process.

It’s privateering of the modern age. So Putin only “funds” them in the sense that he allows them to operate, providing them implied letters of marque.

Re: US companies hit by 'colossal' cyber-attack

#482
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

I've always said: "There's surprisingly little money in correct software."

Re: US companies hit by 'colossal' cyber-attack

#483

In some not-so-distant future dystopia, ransomware hackers will morph into a file encryption service w/ optional data exfiltration as a backup. Just don't stop paying the bill. Or at least that's where we're headed if companies keep giving in to the ransom demands.

Blaming companies for paying a ransom is like blaming a ship captain for surrendering to a pirate on the high seas. It’s ransom or death. The captain’s nation wasn’t providing adequate security against piracy, another nation was condoning privateers. What do you expect them to do?

Or better yet, what happened with privateering amongst the nations in history? First each nation unleashed its own privateers, then they built up and deployed their own navies, and the countries that couldn’t keep up fell under a new Pax Romana aside from fits and struggles. Where are we in this process today?

Re: US companies hit by 'colossal' cyber-attack

#484

I got an abnormally high number of robocalls today - could this be related?

I awoke in the middle of the night and heard a crow caw. Not a normal caw but more like “caw, caw”. And then I stepped on a Lego. Ow! It went right in the heel. Could this be related?

Re: US companies hit by 'colossal' cyber-attack

#485
post #113

Earlier quoted context omitted.

Why not? What's to prevent e.g. the U.S. Government from outlawing the use of exchanges, and/or outlawing the payment of cryptocurrency ransoms, just as it forbids globally the payment of bribes?

Nothing. Also nothing prevents the US government from outlawing drugs. Likely with the same effectiveness. BTW are most of these hackers transferring to fiat through U.S. exchanges? I can't imagine that's the case but maybe it is.

I tend to believe that any laws requiring that corporations not transact using cryptocurrencies, period, would have extremely broad effect, much more so than attempts to stamp out the (surprisingly inelastic) demand by individuals for substances. Just imagine all of the perpetual accounting fraud and ongoing OpSec that would be necessary to cover up its use at the corporate level!

Drugs (and yes, earlier, alcohol) present kind of an unique situation with respect to noncompliance with the law; not sure I can see the case for suggesting the government is destined to fail in enforcing the prohibition of anything whatsoever.

Re: US companies hit by 'colossal' cyber-attack

#486

Earlier quoted context omitted.

Statistically EVERYONE has extremely poor security culture. It's been wallpapered over as just cutting unnecessary expense for too long.

It is almost proof we can't collectively think statistically. I get it at a pretty deep level individually but even knowing this I make enormous mistakes.

What does "statistically EVERYONE..." mean to you?

It sounds to me like if it means anything, it's denying that any probability depends on the exact dimensions of your ignorance.

There is no statistic that applies to everyone, unless that person is a completely generic person with no known qualities.

Re: US companies hit by 'colossal' cyber-attack

#487
post #71
post #26

Earlier quoted context omitted.

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

>That's what ended state-sponsored terrorism.

Wait, what? Have you notified the Department of State?

https://www.state.gov/state-sponsors-of-terrorism/

Iran is still on there. I'm pretty sure some people have been "annoyed enough to do something drastic" for quite a while.

https://en.wikipedia.org/wiki/Assassination_of_Iranian_nucle...

Re: US companies hit by 'colossal' cyber-attack

#488

Earlier quoted context omitted.

[flagged]

I mean you're not even putting any efforts into your delusions. These are things that have been long debunked with very simple logic. My favorite part is how you believe that the big bad conspirators removed Trump and are pushing the vaccine, but back here in reality, Trump was the biggest champion of the vaccines. He created the program that got them into production so quickly. I don't know why I'm wasting the keyst…

The presumption I support trump is inaccurate - I do not, I think he’s incompetent.

You also assume what conspiracy theories I believe possible vs which are provable conspiracies. I made minimal claims, but pointed out all feel something is wrong. I then provided some clear issues in my life.

Regarding vaccines, nothing I said was a delusion. I stated a few facts and pointed out the prior post _may_ indeed be correct, given current facts (could also not). Whether you believe it or not, the fact we are having a discussion is proof something has gone terribly wrong and that is what I’m commenting on. I made no claim what was explicitly the cause.

Do you not see the irony in “you are very far down the rabbit hole” and “things you have no understanding of” in the same comment.

First, I debunk stuff for a living — my job is literally assessing others research for commercial ability. Regarding my blog, I consult experts, I have an education in CS & Math and bioengineering, and i read papers / government documents. In some cases recently I’ve even been talking to the authors of these papers and funders of research. I comment on them and make public predictions. I also take the feedback and incorporate it. If you read my blog you can probably see corrections.

I don’t understand the hostility, frankly. I’m happy to alter my opinions, especially if evidence or debate is brought.

Why am I responding?

I hope in the future you’ll be open minded, but more importantly — if you feel someone is wrong, try to (on a human level) convince them they are wrong. Clearly you care enough to type some keystrokes, perhaps use that effort to help the delusional see the err of their ways.

Re: US companies hit by 'colossal' cyber-attack

#489
post #456

Earlier quoted context omitted.

> Holy hell... no wonder they snuffed it out in the media. The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up. The fact that some people have forgotten about it is a completely different issue.

I had recently just moved back from NYC at the time. I was kinda still plugged 24/7 to the US media sphere. But it's true that I don't remember it at all, even though I worked in a field parallel to CompuSec and usually notice those events.

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#490

Earlier quoted context omitted.

I always thought that when thinking security a compromised system HAS to be rebuilt. I have never seen that happen in an enterprise though. They never ever rebuild compromised systems they just try to improve perimeter protection.

Rebuilding the entire IT deployment is prohibitively expensive. Imagine if the solution to Covid was "the virus can spread to anyone, we need to replace all humans"

When a machine/server/laptop/PC is hacked, it's considered compromised. No amount of pruning that system can restore trust in it. It needs to be reset.

It's only prohibitively expensive because most of these enterprise tools and servers are actually very much focused on manual setup.

Post reply on HN