Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

71–80 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#71
post #55

Earlier quoted context omitted.

>it shifts accountability away I agree. I think what we are split on is purpose/intent. >could not reasonably be expected to protect against. Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation. > “get out of jail free” This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire…

> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…

> zero day procurement budgets bigger than most company market caps

do you mean they pay companies to put backdoors into products? or you mean they just go hunting for vulnerabilities. maybe both?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#72
It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#74

Earlier quoted context omitted.

They say the attacker exfiltrated data, including source code. They claim the vulnerabilities discovered through the exfiltration were not used though.

Not sure why I'm downvoted. Literally quoted from their incident page. > We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. > We have no knowledge of undisclosed critical or remote cod…

The fact that they didn't know for such a long time makes their statement completely unbelievable. Also pushing new updates? Sure, they'll say it's just a precaution but I'm willing to bet attacker did more damage than they are willing to publicly disclose

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#75
post #73

A cybersecurity company was hacked — what an irony

Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#76
post #55

Earlier quoted context omitted.

>it shifts accountability away I agree. I think what we are split on is purpose/intent. >could not reasonably be expected to protect against. Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation. > “get out of jail free” This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire…

> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…

Maybe not feasible now, but maybe it could be feasible at some point in the future if things are built on top of seL4 , with similar techniques used to demonstrate that the programs in question also have some desired security properties, building on the security properties the kernel has been proven to have?

Of course, one might still be concerned that the hardware that the software is running on, could be compromised. (A mathematical proof that a program behaves in a particular way, only works under the assumption that the thing that executes the program works as specified.) Maybe one could have some sort of cryptographic verification of correct execution in a way where the verifier could be a lot less computationally powerful while still providing high assurance that the computations were done correctly. And then, if the verifier can be a lot less powerful while still checking with high assurance that the computation was done correctly, then perhaps the verifier machine could be a lot simpler and easier to inspect, to confirm that it is honest?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#77
post #55

Earlier quoted context omitted.

>it shifts accountability away I agree. I think what we are split on is purpose/intent. >could not reasonably be expected to protect against. Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation. > “get out of jail free” This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire…

> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…

When I went through a tech school cyber security program (10+ years ago now) we were told that the situation was "If Canada wants to hack you, it is improbable you can stop them. If the US wants to hack you, they will. Therefore we will not be focussing on strategies to counter nation state actors." It was a forgone conclusion that you would lose against them. I imagine the situation hasn't improved much in the last ten years.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#79
post #72

It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.

Just to be clear, the attackers had access to the systems well before this date.

Sometimes when a company engages law enforcement, law enforcement can request that they not divulge that the company knows about the problem so that forensics can begin tracking the problem.

I won't speak how often or how competent law enforcement are though, but it can happen.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#80

[flagged]

This is a mean-spirited interpretation of what happens when you claim nation state. Generally the government (as of now) is not paying private (but maybe some Critical Infrastructure companies) companies to secure things. We are in the very early stages of figuring out how to hold companies accountable for security breaches, and part of that is figuring out if they should have stopped it. A lot of that comes down to…

HN can be unnecessarily vicious when it comes to these situations. They have a very narrow slit in which they see companies because they extrapolate their understanding into the large corporation.

The attacker needs to find 1 fault in a system to start attacking a system, the company needs to plug ALL of them to be successful, continually for all updates, for all staff, for all time.

Having been on both sides of that fence, I dont envy the defenders, it is a losing battle.

Post reply on HN