Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

51–60 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#51
post #35

[flagged]

> I keep seeing it pop up again and again and it only makes sense in that context. Not saying that these companies would turn down corporate welfare given the chance, but I’ll offer an alternative explanation: it shifts accountability away from the company by positing a highly resourced attacker the company could not reasonably be expected to protect against. If you have a physical security program that you’ve spent…

>it shifts accountability away

I agree. I think what we are split on is purpose/intent.

>could not reasonably be expected to protect against.

Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation.

> “get out of jail free”

This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire sec industry seems shady AF. Which is why I think they are a huge future rent seek lobby. Once the insurance industry catches on.

> these reports get used to fund the security program

So we agree?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#52

[flagged]

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone militar…

> I have no idea why you're incredulous about this.

I understand human nature.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#53
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

It's a bit like copspeak's fondness for mentioning "individuals" (otherwise known as "people.") It's just a kind of shibboleth. "State actors" is just as clear and means the same thing.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#55
post #35

Earlier quoted context omitted.

> I keep seeing it pop up again and again and it only makes sense in that context. Not saying that these companies would turn down corporate welfare given the chance, but I’ll offer an alternative explanation: it shifts accountability away from the company by positing a highly resourced attacker the company could not reasonably be expected to protect against. If you have a physical security program that you’ve spent…

>it shifts accountability away I agree. I think what we are split on is purpose/intent. >could not reasonably be expected to protect against. Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation. > “get out of jail free” This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire…

> I agree. I think what we are split on is purpose/intent.

I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack.

> Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who?

If you think you as a private entity can defend against a tier 1 nation state group like the NSA or Unit 8200, you are gravely mistaken. For one thing, these groups have zero day procurement budgets bigger than most company market caps.

That’s why companies reflexively blame nation state actors. It isn’t to get government funding. It is to avoid blame for an attack by framing it as something they could not have prevented.

> So we agree?

No, I don’t believe we do.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#56
post #50
post #8

Earlier quoted context omitted.

BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...

Perhaps more importantly to a non-U.S. nations is that there are a lot of military networks that touch the public Internet whose security from outside attack is more or less premised on F5's implementation of mutual TLS to CACs. Finding a way to subvert that authentication or, better yet, bypass it entirely, could put U.S. military networks that can be reached over the public Internet at risk of remote exploitation.…

The same F5 responsible for the existence of the padding extension in TLS? And that still has predictable TCP sequence numbers by default.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#57
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Personally, I think its worse. The whole point of employing a company like F5 is precisely to protect against those kind of "nation-state" actors.

If F5 can't do that, what is their actual value proposition?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#58
post #43

Looks like they rotated all signings keys a day earlier: https://my.f5.com/manage/s/article/K000157005 In October 2025, F5 rotated its signing certificates and keys used to cryptographically sign F5-produced digital objects. As a result: BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later are signed with new certificates and keys BIG-IP and BIG-IQ TMOS product versions released in October 2025…

I wonder if there's a bet to be made on future 8K disclosures following quietly updated signing keys. A bet against F5 placed this morning would've only made 3.6%.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#59

[flagged]

This is a mean-spirited interpretation of what happens when you claim nation state.

Generally the government (as of now) is not paying private (but maybe some Critical Infrastructure companies) companies to secure things. We are in the very early stages of figuring out how to hold companies accountable for security breaches, and part of that is figuring out if they should have stopped it.

A lot of that comes down to a few principles:

* How resourced is the defender versus the attacker? * Who was the attacker (attribution matters - (shoutout @ImposeCost on Twitter/X) * Was the victim of the attack performing all reasonable steps to show the cause wasn't some form of gross negligence.

Nation state attacker jobs aren't particularly different from many software shops.

* You have teams of engineers/analysts whose job it is to analyze nearly every piece of software under the sun and find vulnerabilities.

* You have teams whose job it is to build the infrastructure and tooling necessary to run operations

* You have teams whose job it is to turn vulnerabilities into exploits and payloads to be deployed along that infrastructure

* You have teams of people whose job it is to be hands on keyboard running the operation(s)

Depending on the victim organization, if a top-tier country wants what you have, they are going to get it and you'll probably never know.

F5 is, at least by q2 revenue[0], we very profitable, well resourced company that has seen some things and been victims of some high profile attacks and vulns over the years. It's likely that they were still outmatched because there's been a team of people who found a weakness and exploited it.

When they use verbage like nation-state, it's to give a signal that they were doing most/all the right things and they got popped. The relevant government officials already know what happened, this is a signal to the market that they did what they were supposed to and aren't negligent.

[0] -https://www.f5.com/company/news/press-releases/earnings-q2-f...

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#60

[flagged]

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone militar…

[dead]
Post reply on HN