A cybersecurity company was hacked — what an irony
Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
F5 says hackers stole undisclosed BIG-IP flaws, source code
81–90 of 109 posts
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#82[flagged]
> Something about this statement screams that companies are setting themselves up for free money from big old gov'ment welfare titties. From the published CISA mitigation[0]: A nation-state affiliated cyber threat actor has compromised F5’s systems and exfiltrated files, which included a portion of its BIG-IP source code and vulnerability information. The threat actor’s access to F5’s proprietary source code could pr…
Until this happens, its just CYA at its best to hide flaws in their systems and procedures.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#83Earlier quoted context omitted.
This is a mean-spirited interpretation of what happens when you claim nation state. Generally the government (as of now) is not paying private (but maybe some Critical Infrastructure companies) companies to secure things. We are in the very early stages of figuring out how to hold companies accountable for security breaches, and part of that is figuring out if they should have stopped it. A lot of that comes down to…
HN can be unnecessarily vicious when it comes to these situations. They have a very narrow slit in which they see companies because they extrapolate their understanding into the large corporation. The attacker needs to find 1 fault in a system to start attacking a system, the company needs to plug ALL of them to be successful, continually for all updates, for all staff, for all time. Having been on both sides of that…
Being on the defenders side, I would say it is not a losing battle.
It is a matter if convenience versus security: not using up to date libraries because it requires some code rewrites and “aint nobody got time for that”, adding too much logic to functions and scooe creep instead of segregating services, not microsegmenting workloads, using service accounts with full privileges because figuring out what you actually need takes too much time; and the list could go on.
I am not blaming all developers and engineering managers for this because they might not know about all the intricacies of building secure services - part of the blame is on the ops and security people who don’t understand them either and think they’re secure when they are not. Amd those folks should know better.
And third, hubris: we have all the security solutions that are trendy now, we’re safe. Do they actually work? No one knows.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#84It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.
Sony & many others have proved pretty comprehensively that brand reputation isn't really impacted by breaches, even in high profile consumer facing businesses. That trickles down to B2B: if your clients don't care, why should you.
That leaves legal risk as the only other motivating factor. If that's been effectively neutered, it doesn't make economic sense for companies to do due diligence with breaches.
As far as I'm aware, Yahoo were the last company to suffer any significant impact from the US legal system due to a breach.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#85Earlier quoted context omitted.
What I'm saying is they often actually mean "country", but that is less fancy sounding. A nation-state is just one specific type of polity, certainly not the only type which organize attacks.
You’re overthinking it. “Country” is simply more ambiguous when used as an adjective. “F5 announces attack from country hackers” sounds silly and confusing.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#86It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.
But you are right, at F5's size and moneys, incentives for public disclosure are not aligned in the public's favor. Damage control, in all its meanings, has taken priority lately over transparency.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#87Earlier quoted context omitted.
HN can be unnecessarily vicious when it comes to these situations. They have a very narrow slit in which they see companies because they extrapolate their understanding into the large corporation. The attacker needs to find 1 fault in a system to start attacking a system, the company needs to plug ALL of them to be successful, continually for all updates, for all staff, for all time. Having been on both sides of that…
> Having been on both sides of that fence, I dont envy the defenders, it is a losing battle. Being on the defenders side, I would say it is not a losing battle. It is a matter if convenience versus security: not using up to date libraries because it requires some code rewrites and “aint nobody got time for that”, adding too much logic to functions and scooe creep instead of segregating services, not microsegmenting w…
Many of these companies can keep up to date assuming their vendors report correctly, The exploits that are not publicly documented are rarely fixed.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#88Earlier quoted context omitted.
Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#89I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)
BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#90Earlier quoted context omitted.
> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…
> zero day procurement budgets bigger than most company market caps do you mean they pay companies to put backdoors into products? or you mean they just go hunting for vulnerabilities. maybe both?