How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
What are the tools to help orgs notice exfiltration?
CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
71–80 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#72Earlier quoted context omitted.
It's my understanding that nothing truly concrete has been shown to the public?
There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#73Earlier quoted context omitted.
The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.
That's completely untrue.
Sorry, but "high degree of confidence" is not proof, especially not from the organization that told us Iraq had WMDs with high degrees of confidence.
Additionally, at no point in time did they have access to the hardware.
Are you forgetting that this is the same collection of people responsible for being unable to secure their own hacking tools?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#74Earlier quoted context omitted.
It's my understanding that nothing truly concrete has been shown to the public?
There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.
Funnily enough, there's no clear evidence of this. According to OPCW leaked documents there's a higher probability the gas was manually placed at the site. [1] Which of course, calls into question the Syrian government's involvement, especially given earlier intelligence showing ISIS had possession of such chemical weapons.
[1] https://www.independent.co.uk/voices/douma-syria-opcw-chemic...
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#75I find it ironic that the CIA didn't bother to have it's systems secured/verified by the NSA. I'm sure the CIA thought that they were good enough, coming from an organization that was infiltrated from its inception, their hubris isn't surprising.
My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.
The NSA does some seriously insane stuff, but I don’t think even they take themselves as seriously as the CIA does.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#76How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
Absolutely. So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use. Put another way: perhaps it's not an accident? And perhaps some of what was leaked was a decoy? Yes, keeping secrets is difficult. All the more reason to take advantage of that.
Like leaving data of their secret assets available on Google searches, leading to hundreds of deaths? And firing the employee who warned then of the problem seven years before it was exploited?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#77Earlier quoted context omitted.
I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue…
Agreed, It doesn’t seem appropriate for info-sec people to be making decisions about what which risks to mitigate, ignore, etc. They should provide input into that process though. We struggled to even get the CIO and CEO to acknowledge and discuss info-sec risk and make decisions regarding what to do about that risk.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#78A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…
You screw up at offense if your weapons are destroyed or disabled. In case of exploits, this is exactly what happens when they leak out. Your ability to attack in this case is equivalent to keep your arms useful.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#79The article tries to make it sound like the failure is a lack of prioritization and if they just focused correctly the problem could have been avoided, but I do not see why anybody would assume they would be able to protect their systems even if they tried. How well protected do you think cyber-weapons designed to surveil countries, disable infrastructure, and destabilize governments should be? How capable and well-f…
I guess it's safe to say that even with $1M of funding and small team of dedicated security researchers coupled with right people for social engineering you can break into any network. Everyone can be fooled and humans are always the weakest spot. Especially now when information about everyone is publicly available on social networks so you can gather all information you need remotely.
And when it's come to hacking into networks of company with no dedicated budget for cybersecurity cost of attack would be one or two orders of magnitude lower. Some self-organized groups of hobbyists prove you can even do it with no funding at all.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#80A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…
It's more analogous to saying "the defense contractors for a new stealth plane failed to protect the designs and prototypes, so the enemy now has all of the detailed info they need to build countermeasures against this stealth technology". Securing the plans for stealth is a key requirement of the stealth continuing to work. Also, I'm sure those members of "the hacking team" weren't allowed to discuss their work with…
Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it. Risk is proportional to threat and attack surface, for an org like the CIA they have not-so-small attack surface and the whole world as their threat, so reduction in risk by means of common security controls and hygeine will not reduce risk from the most persistent and resourceful attackers.analogy to your reasoning would be "Google has an army of devs and security pros, so Chrome should never have a remote code execution vuln" ,no, as much as they may have money and talent, modern software is too complex for those resources to eliminate all bugs. Perspective is important.