Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

501–510 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#501
post #374

Earlier quoted context omitted.

Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…

They should also have the old wisdom of not connecting critical systems to Internet.

It is becoming harder and harder to install software on systems without internet connectivity. More and more things assume they can hit maven or npm or random other places at deploy time; even expensive well regarded third party software. At least Golang deploys are ok. (Source: running prod systems with a mandate of no internet connectivity).

Re: US companies hit by 'colossal' cyber-attack

#502
What I'd like to see come out of this is for corporations to view customers' collected data as a liability, not as an asset. Then maybe they would think twice before collecting and storing unnecessary customer data. Or if they have to collect it, they would expire it as soon as possible. This is somewhat hampered of course by regulations that may require hanging on to data.

Re: US companies hit by 'colossal' cyber-attack

#503

Earlier quoted context omitted.

I mean you're not even putting any efforts into your delusions. These are things that have been long debunked with very simple logic. My favorite part is how you believe that the big bad conspirators removed Trump and are pushing the vaccine, but back here in reality, Trump was the biggest champion of the vaccines. He created the program that got them into production so quickly. I don't know why I'm wasting the keyst…

The presumption I support trump is inaccurate - I do not, I think he’s incompetent. You also assume what conspiracy theories I believe possible vs which are provable conspiracies. I made minimal claims, but pointed out all feel something is wrong. I then provided some clear issues in my life. Regarding vaccines, nothing I said was a delusion. I stated a few facts and pointed out the prior post _may_ indeed be correct…

> Target just closed all their stores in SF.

Not true, they are closing early (6pm). There are 6 stores.

> I have a feeling people who don’t get the vaccine are going to end up in camps. I know that’s already true in some countries.

Not true.

> We’ve been in a feudalist system really since WWI in the US

Not true.

> The media suppressed literally any opposition the past 18 months. Including banning the acting president of the United States, senate testimony, Biden laptop, highly supported research discussions about covid, etc etc

Not true.

> The pandemic isn’t like others in history, because this pandemic is only slightly worse than the flu.

Not true.

Some of what you have said has elements of truth to it, but you completely blow any semblance of respectability with silly and obviously incorrect hyperbole.

> if you feel someone is wrong, try to (on a human level) convince them they are wrong.

It takes effort to respond to someone who talks like you do, and there is little reward in doing so.

Re: US companies hit by 'colossal' cyber-attack

#504

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

Fun fact: the word “security” comes from the Latin word for carelessness - “securitas.” se = without, curitas = care.

I wonder if the Swedish security company "Securitas" knew this when changing name.

https://en.m.wikipedia.org/wiki/Securitas

Re: US companies hit by 'colossal' cyber-attack

#505

Earlier quoted context omitted.

You do not have to "trust" the OS at some level. Use Linux or BSD, demand open hardware. You only feel like you "have to trust" shitty closed-source OSes because the orgs behind those OSes have been able to abuse market-dominant positions to stifle competition. Security by obscurity is laughable nonsense. We should all be demanding transparency in hardware and software from our vendors. I'd pay handsomely for it.

I think that in this context the meaning of the term trust is different. Any code executing in privileged mode can bypass security, and is therefore inherently part of a system's trusted computing base (TCB). (Linux is a monolithic kernel running in ring 0) Most companies are not Linux contributors, they are trusting the kernel developers to write bug free, secure code. Minimizing the TCB and opting for an auditable…

I agree with you.

>Any code executing in privileged mode can bypass security, and is therefore inherently part of a system's trusted computing base (TCB). (Linux is a monolithic kernel running in ring 0)

It's way nicer to be able to look at the code running in Ring 0 =)

Re: US companies hit by 'colossal' cyber-attack

#506

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

I did write an answer before but now it seems like only Internet facing VSA servers are effected and some other measures may have stopped the attack. It could be all the servers they could find...

Re: US companies hit by 'colossal' cyber-attack

#507

Earlier quoted context omitted.

>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…

In many cases you don't want to let an hostile party read confidential data, and if he takes control of the machine aren't all bets off? Moreover what if a hostile party constantly hammers-disrupts your IT, letting you teams "rebuild and reload" 24 hours/day (in other words you don't have any information system anymore)?

I think the idea is that after you get compromised, you do forensics to address the vulnerability that exposed you, then after addressing the fixes in your perimeter, you reset the compromised systems. The attacker wouldn't be able to hammer you again without having another vulnerability in that case

Re: US companies hit by 'colossal' cyber-attack

#508

Earlier quoted context omitted.

FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic) So it's a spectrum

That's not even close to what happened. The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.) When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet…

I mean it's reasonably close - but FWIW thanks for the correction, it's been a wild year

Re: US companies hit by 'colossal' cyber-attack

#509
post #504

Earlier quoted context omitted.

Fun fact: the word “security” comes from the Latin word for carelessness - “securitas.” se = without, curitas = care.

I wonder if the Swedish security company "Securitas" knew this when changing name. https://en.m.wikipedia.org/wiki/Securitas

I’ve often wondered this. I see them around a lot, and I’m like “someone doesn’t know their Latin.”

Re: US companies hit by 'colossal' cyber-attack

#510
I wonder how much (if at all) the new Windows 11 security features would protect against this sort of thing.

Given the fairly vocal resistance to the TPM 2.0 requirement, if the answer is nothing, then I wonder why it is even necessary.

As a Mac/Linux user, I’m out of the information flow on this topic except for a surface level understanding, so please person my ignorance, as I’m genuinely curious.

Post reply on HN