Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

61–70 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#61

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

[deleted]

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#62
post #59
post #44

Earlier quoted context omitted.

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I'd actually expect this to be the opposite. Insurance is heavily risk analysis based. It sounds like they were choosing to take the risks because either you didn't show them properly, or you don't realize how cheap the actuated cost of non compliance is.

I follow your reasoning... but no, that wasn’t the case here. A number board members of this org fought for and succeeded in getting increased investment in a true info-sec program due to years of very lax security culture and a series of internal audits elaborating the risk to the org. The CEO and CIO were constantly grossly over budget on pet software dev initiatives, which the board was becoming increasingly concerned with - then here come the info-sec folks with a laundry list of gaping security holes in said over-budget software projects, to which the CEO and CIO proceeded to dodge meetings, ignore risk assessment communications, direct their underlings to exclude and shut out the sec team, and keep the board in the dark. It was a toxic culture, glad I left when I did.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#63

I find it ironic that the CIA didn't bother to have it's systems secured/verified by the NSA. I'm sure the CIA thought that they were good enough, coming from an organization that was infiltrated from its inception, their hubris isn't surprising.

Maybe they saw a benefit in having no logs?

No logs, no congressional investigation.

These are smart well-resourced people. They don't do things like this for no reason.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#64
post #44

Earlier quoted context omitted.

Another, related paradox is that in corporate org structures, the CIO is responsible for making sure the company's systems are available and working correctly, but the CISO is responsible for securing systems. Departments of CIOs can frequently be seen as a profit center which unlocks potential for the company while CISOs are almost always seen as a cost center which (ostensibly) slows the potential of the company. T…

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I have hoped that "Cyber Insurance" might be able to price these risks, and also price information assurance best practice into premiums.[1] Do you think this has, or could work?

If an insurance company is unable to price it's own internal IA risks either at all, or at a non-zero value, I'm discouraged from hoping for a market solution to the problem that, as the truism states, "offense is easy, defense is impossible." I think the intelligence services and LE have also done a bad job, as evidenced by the hoarding, instead of reporting or fixing, of vulnerabilities.

Schneier has lately argued that regulation is necessary. The idea of GDPR for infosec is unappetizing, but I have trouble thinking of any other solution that hasn't already failed.

1.https://en.wikipedia.org/wiki/Cyber_insurance

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#65
post #56
post #44

Earlier quoted context omitted.

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue…

Agreed, It doesn’t seem appropriate for info-sec people to be making decisions about what which risks to mitigate, ignore, etc. They should provide input into that process though. We struggled to even get the CIO and CEO to acknowledge and discuss info-sec risk and make decisions regarding what to do about that risk.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#66
post #55

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.

That's completely untrue.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#67
post #56
post #44

Earlier quoted context omitted.

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue…

> As much as I respect the technical acumen and creativity of my colleagues in the industry...we do a pretty bad job of communicating it.

This is the root of so many problems for technical teams in ostensibly non-technical businesses. More developers and engineers really need to embrace the reality that your work doesn't always speak for itself - sometimes you have to speak convincingly on its behalf.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#68
post #55

Earlier quoted context omitted.

The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.

You're either misleading or ill-informed. Since 2016 it is well documented Russia intervened through hacking and disinfo operations.

It's my understanding that nothing truly concrete has been shown to the public?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#69

Earlier quoted context omitted.

No, Russian interference allegations were confirmed through other means, mainly human intelligence and other types of intercepts. The dutch even filmed the meddling operations through GRU hacked security camera.

I don't see how the Dutch story is relevant, if it's the one I looked up, and it sounds therefore like there is at best circumstantial evidence. Even motive isn't very reliable because all kinds of people are out to do things like influence the elections.

It is intelligence, not "at best circumstantial evidence". And no, "all kinds of people" did not have the same explicit motives highlighted by the Muller Report, the Senate Committee, or 18 US intelligence agencies showed. I guess spitballing theories on hn is always more accurate than thousands of analysts sharing this analysis in Western countries.

Just one source: https://www.intelligence.senate.gov/sites/default/files/docu...

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#70

Earlier quoted context omitted.

You're either misleading or ill-informed. Since 2016 it is well documented Russia intervened through hacking and disinfo operations.

It's my understanding that nothing truly concrete has been shown to the public?

There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public.

When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.

Post reply on HN