Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

61–70 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#61

Earlier quoted context omitted.

Crowdstrike attributed the 2015/2016 DNC "Hacks" to Russia based solely on a file creation timestamp in the same timezone as Moscow and the presence of Cyrillic in a Word document's metadata, and the western world ran with it for years. Don't expect much.

Why would you think this? They found shared infrastructure and TTPS related to other attacks for the actors. edit: And what's with the "hacks" scare quotes? We know exactly how the attack happened, step by step... in what way was it not a very straightforward hack?

This was still straw grasping. Tactics and techniques get imitated all the time. Covering your tracks and laying down false trails is standard opsec.

This hack wasnt special in this respect though. Hack attribution is usually based on pathetically thin evidence.

For a high profile hack attack it really isn't feasible politically to say that you aren't sure who the attacker is, though. It makes you look weak and powerless.

Not being sure who the enemy is or being utterly sure and wrong for long periods of time is a weird feature of cyberwarfare that I'm not sure any country is capable of adapting to yet.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#62
post #41

Earlier quoted context omitted.

CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks. Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise. If I had a static environment with no new software or business processes, then NO PROBLEM. I can lock it down in every kinda way and it stays locked down to a known baseline. Add to that new…

Those are all reasons why a network/company cannot be 100% invulnerable to hacks, but it doesn't answer the question of if a company can be be significantly more resistant to ransomware. My answer to that question is "absolutely". These ransomware attacks are so devastating in no small part due to decisions Microsoft made many years ago. Combining authentication, remote administration, file sharing, printing, event m…

>These ransomware attacks are so devastating in no small part due to decisions Microsoft made many years ago.

This is true for almost all types of malware these days, especially when it comes to privilege separation/escalation attacks. All of your observations about segmentation/AD are true here.

As for ransomware specifically, a lot can be done to stop most ransomware, especially small-time stuff. Unlike most malware ransomware is intentionally loud, and performs the same generic actions of enumerating and encrypting files, which makes detecting and stopping most samples with heuristics much more effective than a lot of people would admit: https://www.youtube.com/watch?v=3pH13DxClag

A lot has happened with ransomware in the past five years, but a lot really hasn't - this stuff still works, and would have an effect against the big RaaS strains that people are talking about today.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#63
post #61

Earlier quoted context omitted.

Why would you think this? They found shared infrastructure and TTPS related to other attacks for the actors. edit: And what's with the "hacks" scare quotes? We know exactly how the attack happened, step by step... in what way was it not a very straightforward hack?

This was still straw grasping. Tactics and techniques get imitated all the time. Covering your tracks and laying down false trails is standard opsec. This hack wasnt special in this respect though. Hack attribution is usually based on pathetically thin evidence. For a high profile hack attack it really isn't feasible politically to say that you aren't sure who the attacker is, though. It makes you look weak and power…

So there's lots of evidence to support attribution, but your flimsy hand waving about uncertainty is supposed to carry weight?

Once again, we have:

* Shared infrastructure

* Shared TTPs

* Clues like language

* No evidence to the contrary

And that's just what's public. I assure you that quite a lot stays between people. I know many people in the field who can't share public details about breaches due to pending legal issues - Dropboxers couldn't talk about aspects of the 2012 breach until just this last year.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#64

Earlier quoted context omitted.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

>That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. Well, no, because obviously the Chinese government's teams don't want to get tracked and attributed, and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity. Of course, their saying "just take…

> and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity.

Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses."

>Of course, their saying "just take my word for it" doesn't mean you should trust them or their findings, but it doesn't mean you should necessarily distrust them just because they don't reveal their methods.

I should assume their statement is false until evidence is provided. That's a fairly universal concept.

>What's the source on this one? Sounds like an interesting story.

https://www.crowdstrike.com/blog/two-birds-one-stone-panda/

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#65

Earlier quoted context omitted.

That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

Well, it's also fair to say your comment is designed to cast doubt on the article's claim, despite the fact that you have no proof whatsoever to the contrary. > One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization. Did they say it was the only evidence…

>Well, it's also fair to say your comment is designed to cast doubt on the article's claim, despite the fact that you have no proof whatsoever to the contrary.

I have proof that they have not printed any evidence for their statement in this article. It's your decision whether you believe they should be trusted without evidence, I personally don't think so.

>Did they say it was the only evidence they had to tie the incident to China linked hackers, or was that one thing they were willing to share?

They also found a supposed job listing with tenuous links as well, I linked it elsewhere. I have no clue if they have better evidence.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#66
post #61

Earlier quoted context omitted.

This was still straw grasping. Tactics and techniques get imitated all the time. Covering your tracks and laying down false trails is standard opsec. This hack wasnt special in this respect though. Hack attribution is usually based on pathetically thin evidence. For a high profile hack attack it really isn't feasible politically to say that you aren't sure who the attacker is, though. It makes you look weak and power…

So there's lots of evidence to support attribution, but your flimsy hand waving about uncertainty is supposed to carry weight? Once again, we have: * Shared infrastructure * Shared TTPs * Clues like language * No evidence to the contrary And that's just what's public. I assure you that quite a lot stays between people. I know many people in the field who can't share public details about breaches due to pending legal…

What specific evidence did you find most compelling? Please, share it, if it's more convincing than Cyrillic in a document header or a Russian IP address.

Or, you could just hit us with the oft repeated 2003 weapons of mass destruction talking point of "the evidence is there it's probably just classified" if you want to make me reminiscent for the good old days.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#67
post #66

Earlier quoted context omitted.

So there's lots of evidence to support attribution, but your flimsy hand waving about uncertainty is supposed to carry weight? Once again, we have: * Shared infrastructure * Shared TTPs * Clues like language * No evidence to the contrary And that's just what's public. I assure you that quite a lot stays between people. I know many people in the field who can't share public details about breaches due to pending legal…

What specific evidence did you find most compelling? Please, share it, if it's more convincing than Cyrillic in a document header or a Russian IP address. Or, you could just hit us with the oft repeated 2003 weapons of mass destruction talking point of "the evidence is there it's probably just classified " if you want to make me reminiscent for the good old days.

Yeah, unrelated things decades ago were wrong or something therefor... uh, something.

I'm not really interested in doing research for you.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#68
post #66

Earlier quoted context omitted.

What specific evidence did you find most compelling? Please, share it, if it's more convincing than Cyrillic in a document header or a Russian IP address. Or, you could just hit us with the oft repeated 2003 weapons of mass destruction talking point of "the evidence is there it's probably just classified " if you want to make me reminiscent for the good old days.

Yeah, unrelated things decades ago were wrong or something therefor... uh, something. I'm not really interested in doing research for you.

I researched it a while back. That's how I reached this conclusion - in particular, the idea that one hacker used broadly similar techniques to another ("shared TTPs" as you so obliquely put it) being used as evidence stood out precisely because of how flimsy it was. Likewise when IP addresses from specific countries are cited it's like waving a red flag saying "we actually don't know" to anybody with a rudimentary understanding of networking.

I asked in case I missed or misinterpreted some specific piece of evidence that was particularly compelling.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#69

Earlier quoted context omitted.

>That kind of statement is designed to make you think they have good reasons to make the claim, but if they did they would just share the reasons. Well, no, because obviously the Chinese government's teams don't want to get tracked and attributed, and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity. Of course, their saying "just take…

> and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity. Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." >Of course, their saying "just take my word for it" doesn't mean you should trust them or their findings, but it doesn't mean you should necessarily distrust them just…

>Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses."

Yes, a decent chunk of it comes down to that general idea, but in practice you're dealing with a ton of permutations of that idea. You don't want the adversary to know the specific data types or values you were pivoting off of and correlating against.

So it's not about the general methodology but the specific applications and indicators. Plus there are many other attribution methods beyond just that.

>I should assume their statement is false until evidence is provided. That's a fairly universal concept.

I don't think that's how that works. You just have no evidence or reason to believe their statement is true. That's different from assuming their statement is false. "Failing to reject the null hypothesis" isn't the same thing as "confirming the null hypothesis".

>https://www.crowdstrike.com/blog/two-birds-one-stone-panda/

>One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.

That seems like a major misrepresentation. Here're the two posts that that CrowdStrike post is based on:

https://intrusiontruth.wordpress.com/2018/08/02/who-is-mr-ga...

https://intrusiontruth.wordpress.com/2018/08/15/apt10-was-ma...

I'm not going to summarize everything IntrusionTruth and CrowdStrike reported, but it definitely wasn't just "someone they suspected as a hacker taking a rideshare to a large office building that rented space to a government organization". It was someone whose name and other personal information they already had likely associated with APT10 - through several different means - allegedly also appearing on multiple Uber ride receipts with a destination of the regional headquarters of the Ministry of State Security, which is in the city he appears to work and live in. (Among several other indicators pointing to his likely involvement, including potential associations between local companies he was affiliated with and the Ministry of State Security Tianjin Bureau + APT campaigns.)

What are you basing this "rented space to a government organization" on? Could you imagine the NSA putting a regional headquarters in some rented office space, for example?

In my opinion, the totality of the combined analyses makes a pretty good case that Gao was part of APT10, and a moderate case that he may have worked for or with the Ministry of State Security Tianjin Bureau. Combined with other reports published by both parties, the case for associations between APT10 and MSS Tianjin Bureau is additionally strengthened.

Then a few months later, the Justice Department announced this indictment: https://www.justice.gov/opa/pr/two-chinese-hackers-associate...

>Two Chinese Hackers Associated With the Ministry of State Security Charged with Global Computer Intrusion Campaigns Targeting Intellectual Property and Confidential Business Information

>Defendants Were Members of the APT 10 Hacking Group Who Acted in Association with the Tianjin State Security Bureau and Engaged in Global Computer Intrusions for More Than a Decade, Continuing into 2018, Including Thefts from Managed Service Providers and More Than 45 Technology Companies

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#70
I'm John Williams from the United State of America, i was scammed by two hacker's while trying to look for a recovering agent and Mobile spy access to my girlfriend's iPhone 12 pro Max. I lost a lot of money online to fake broker's and as well fake hacker's who I came across in the first place when I searched on google engine. I was on trust pilot trying to see some review when i came across (wizardharry@programmer.net) i quickly contact him but was nervous because i have had a lot of bad experience over the internet, it was hard to believe him but i put it to try anyway, then i discover he is a legend and honest hacker, both my lost funds where recovered and i got more than i lose, right now i have mobile spy remote access to my girlfriend phone without her knowledge. All thanks to wizard Harry. You can also WhatsApp him (+1-807-808-6168)
Post reply on HN