Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

51–60 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#51

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

What are the tools to help orgs notice exfiltration?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#52
post #20

Earlier quoted context omitted.

What's the story re: backtrack2, for the uninformed?

I'm trying to find a citation here, but it's difficult because "Backtrack 2 ssh exploit defcon" is going to produce a lot of content which is unrelated. Anyway I can give you the skinny of the situation: 1) Backtrack 2 did not have an installer, it was a live-CD. But that doesn't stop you installing it by just copying the live environment to a disk (with some mount-binding and grub install, you're all good!) There we…

>4) someone at defcon unveilled an sshd exploit, a pretty nasty one, they had disclosed responsibly and everyone had been patched for at least 6 months, except the people who went against recommendations and installed backtrack2. They all got rooted.

Yeah, I don't think this happened. Nobody has publicly exploited an opensshd rce for ages.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#53
I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things...

So does anything in this vault possibly call certain recent allegations of Russian interference into question?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#54
post #44

Earlier quoted context omitted.

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

Strange. I can imagine the average corp board member underestimating the risk accumulated by consistently ignoring CISO request for more cybersecurity investments, but the insurance industry is used to dealing with the low-frequency, high-impact payouts. Do you think it was mis-communication, ignorance, greed, hubris, or something else?

All of the above.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#55

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#56
post #44

Earlier quoted context omitted.

Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company. T…

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue losses by adding sometimes insane amounts of friction to the product delivery process.

That's not to say there aren't cowboy CxOs recklessly ignoring reality, but accepting risks is part of the job. The real answer generally lies somewhere in the middle of the two extremes.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#57

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

No, Russian interference allegations were confirmed through other means, mainly human intelligence and other types of intercepts. The dutch even filmed the meddling operations through GRU hacked security camera.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#58
post #55

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.

You're either misleading or ill-informed. Since 2016 it is well documented Russia intervened through hacking and disinfo operations.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#59
post #44

Earlier quoted context omitted.

Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company. T…

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I'd actually expect this to be the opposite. Insurance is heavily risk analysis based. It sounds like they were choosing to take the risks because either you didn't show them properly, or you don't realize how cheap the actuated cost of non compliance is.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#60

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

No, Russian interference allegations were confirmed through other means, mainly human intelligence and other types of intercepts. The dutch even filmed the meddling operations through GRU hacked security camera.

I don't see how the Dutch story is relevant, if it's the one I looked up, and it sounds therefore like there is at best circumstantial evidence. Even motive isn't very reliable because all kinds of people are out to do things like influence the elections.
Post reply on HN