Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

51–60 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#51
post #21

Earlier quoted context omitted.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

The new york times target audience is not likely to understand a reference to metasploit, let alone digital forensic techniques. They wouldn't go into chemistry when writing a mass market article on batteries either, they'd just say "new breakthrough in battery technology".

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#52
post #21

Earlier quoted context omitted.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

So they would know which techniques to change? The reason not to share is obvious.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#53
post #11

Earlier quoted context omitted.

> there are standards and operating procedures that can be used 99% of these standards are completely useless and exist only to reduce legal liability. The other 1% are only incidentally slightly useful. You will never ever create a secure company by following some stupid checklist, unless the checklist is so extreme as to be useless to most orgs. “Step 1: only run OpenBSD…”

a checklist is not where it begins, but it is where it starts. if you don’t have it you probably don’t know what you’re doing

This is almost the exact opposite of the truth. People who know what they’re doing don’t blindly follow some checklist. Doing this properly requires deliberation, or an implausibly large decision tree.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#54
post #21

Earlier quoted context omitted.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

As a person who works in cyber security, no, no we probably wouldn't share those details. It gives an edge to attackers about how we track them. Those details are only made public when the malicious activity is aggressive or widespread enough, at which point it's for the greater good to go public and bare it all. There is so much that goes into that blurb that you cannot even comprehend unless you work at a security agency/company, and many times on the specific incident in question.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#55
post #53

Earlier quoted context omitted.

a checklist is not where it begins, but it is where it starts. if you don’t have it you probably don’t know what you’re doing

This is almost the exact opposite of the truth. People who know what they’re doing don’t blindly follow some checklist. Doing this properly requires deliberation, or an implausibly large decision tree.

i disagree. having a set of rules and a domain expert that defines those rules is key. automation around enforcement and designing the system to make it as less painful as possible are also key.

you cannot just say: oh this is so complicated that we cannot possibly have a system for it and we have to rely on the people to do the “right thing”

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#56
Bring your own equipment. It works for rock stars and counter terror teams because there's no excuses. It increases demand and education. There's a breach, or a hack, next man up. You messed up? Liability is yours. Best to hit the road. Worst though, you're not it. You're just not good.

Smart contracts on existing exploits would make a great state backed cryptocurrency. Stopped pipelines make great labs for chemical electricity generation. Attack on the food supplies can be used as tallow. Go ahead world. Wake the sleeping giant.

Stand up for yourself. The USA, you're better. Stop the relativism. The law applies to everyone, or there is no law. Limit the violence, don't add to it. Lessen enemies, don't create them. Don't tell everyone what to do when you're not willing to do it yourself. Walk away. Doing the minimum is a lot easier than ruling the world.

The dead fight with weapons, they dying, tricks and traps and deceipt. Soon they fall into a trap of their own making. Or what they are fighting against wises up and defeats it. We're strong enough to live among bad people, where other people have to outright kill them. They only know barbarism.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#57

Earlier quoted context omitted.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

As a person who works in cyber security, no, no we probably wouldn't share those details. It gives an edge to attackers about how we track them. Those details are only made public when the malicious activity is aggressive or widespread enough, at which point it's for the greater good to go public and bare it all. There is so much that goes into that blurb that you cannot even comprehend unless you work at a security…

>There is so much that goes into that blurb that you cannot even comprehend unless you work at a security agency/company, and many times on the specific incident in question.

Sure, but as a result that statement could also be full or complete bullshit and anyone not related would be unable to distinguish the difference. The times you've made that statement may have had substantial evidence behind them, but (presumably) you know just as much as me about what's being used to make this statement.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#58
post #21

Earlier quoted context omitted.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

Well, it's also fair to say your comment is designed to cast doubt on the article's claim, despite the fact that you have no proof whatsoever to the contrary.

> One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

Did they say it was the only evidence they had to tie the incident to China linked hackers, or was that one thing they were willing to share?

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#59
post #21

Earlier quoted context omitted.

To give them the benefit of the doubt, they said "a hacking group believed to have links to the Chinese government", which makes me think they probably used tools and techniques associated with a known group.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

>That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons.

Well, no, because obviously the Chinese government's teams don't want to get tracked and attributed, and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity.

Of course, their saying "just take my word for it" doesn't mean you should trust them or their findings, but it doesn't mean you should necessarily distrust them just because they don't reveal their methods.

>One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

What's the source on this one? Sounds like an interesting story.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#60

Cyberattack day! This one happened over a month ago, its obvious this is a trending headline likely not organically, so make sure to separate the dates before thinking we are under a coordinated attack all at once right now

We can only talk about breaches on the day they happened otherwise it's propaganda?
Post reply on HN