Earlier quoted context omitted.
I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue…
> As much as I respect the technical acumen and creativity of my colleagues in the industry...we do a pretty bad job of communicating it. This is the root of so many problems for technical teams in ostensibly non-technical businesses. More developers and engineers really need to embrace the reality that your work doesn't always speak for itself - sometimes you have to speak convincingly on its behalf.
CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
81–90 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#82Earlier quoted context omitted.
What would be a less gimmicky setup?
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#83Earlier quoted context omitted.
> As much as I respect the technical acumen and creativity of my colleagues in the industry...we do a pretty bad job of communicating it. This is the root of so many problems for technical teams in ostensibly non-technical businesses. More developers and engineers really need to embrace the reality that your work doesn't always speak for itself - sometimes you have to speak convincingly on its behalf.
Or you wait until it explodes and then get the money either way. Plus, you don't have to bother with people who do not want to understand, which is the second problem commonly faced by technical teams. I've seen more than enough technical people doing anything they could to make people understand, but at the end of the day Sinclairs adage about people not understanding something if their income depends on not underst…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#84Earlier quoted context omitted.
I'm trying to find a citation here, but it's difficult because "Backtrack 2 ssh exploit defcon" is going to produce a lot of content which is unrelated. Anyway I can give you the skinny of the situation: 1) Backtrack 2 did not have an installer, it was a live-CD. But that doesn't stop you installing it by just copying the live environment to a disk (with some mount-binding and grub install, you're all good!) There we…
>4) someone at defcon unveilled an sshd exploit, a pretty nasty one, they had disclosed responsibly and everyone had been patched for at least 6 months, except the people who went against recommendations and installed backtrack2. They all got rooted. Yeah, I don't think this happened. Nobody has publicly exploited an opensshd rce for ages.
This was like 2007-8.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#85How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
Or even the news story of how their old boss(!) John Brennan had his AOL(!) email account(!) cracked(!) by a teenager(!) guessing his password(!). The teenager exfiltrated something sensitive, a job application I believe, and was prosecuted for it. Meantimes, the former Director of Central Intelligence gets to keep his reputation.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#86Earlier quoted context omitted.
There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.
>When intelligence agencies share clear evidence a dictator gassed his own civilian population Funnily enough, there's no clear evidence of this. According to OPCW leaked documents there's a higher probability the gas was manually placed at the site. [1] Which of course, calls into question the Syrian government's involvement, especially given earlier intelligence showing ISIS had possession of such chemical weapons.…
Clear evidence you can't fake: a rush of hundreds of people (including children) to the different hospitals near the Khan Sheikhoun site while all showing the same respiratory and neurological symptoms. How can one fool so many doctors?
Here's a breakdown of the exact, and single email/document used to "discredit" all chemical attacks perpetrated by Al-Assad on his population https://www.bellingcat.com/news/2019/11/25/emails-and-readin...
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#87How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
What are the tools to help orgs notice exfiltration?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#88Earlier quoted context omitted.
There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.
All of that was based on the opinion of a private organization. No intelligence official ever had possession of the server or was involved at any time.
Here are more details and evidence if you are sincere and want to dig deeper: https://www.intelligence.senate.gov/sites/default/files/docu...
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#89Earlier quoted context omitted.
Absolutely. So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use. Put another way: perhaps it's not an accident? And perhaps some of what was leaked was a decoy? Yes, keeping secrets is difficult. All the more reason to take advantage of that.
>So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use. Like leaving data of their secret assets available on Google searches, leading to hundreds of deaths? And firing the employee who warned then of the problem seven years before it was exploited?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#90Earlier quoted context omitted.
>So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use. Like leaving data of their secret assets available on Google searches, leading to hundreds of deaths? And firing the employee who warned then of the problem seven years before it was exploited?
I would suggest you research a bit on how intelligent and counter-intelligence actually works; not the Hollywood version.
https://finance.yahoo.com/news/cias-communications-suffered-...