Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

91–100 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#92
post #77
post #65

Earlier quoted context omitted.

Agreed, It doesn’t seem appropriate for info-sec people to be making decisions about what which risks to mitigate, ignore, etc. They should provide input into that process though. We struggled to even get the CIO and CEO to acknowledge and discuss info-sec risk and make decisions regarding what to do about that risk.

Oh yeah, if they aren’t going to even show up to the conversation then it’s time to yank the ripcord.

By yank the ripcord do you mean leave the organization? I see this type of behavior at just about every company I have worked. There is no real priority to fix security holes even when they are discovered.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#93
post #92
post #77

Earlier quoted context omitted.

Oh yeah, if they aren’t going to even show up to the conversation then it’s time to yank the ripcord.

By yank the ripcord do you mean leave the organization? I see this type of behavior at just about every company I have worked. There is no real priority to fix security holes even when they are discovered.

Depends on the circumstance and what your career goals are. If you want to develop your leadership skills, stay put and try to drive change. If you're developing your IR/SOC/threat hunting skills, maybe stay put b/c you're likely to be needed (assuming org is large enough target to get interesting attention). If you're doing assessment/red team/pen testing I'd stay a short while then move on b/c your reports are going to start to be recyclable. If you're doing security architecture/engineering/etc you're going to be resource starved so maybe move on.

Moral of the story is determine how it impacts your career goals and chose.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#94

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

You'd think at least some of these inept cyberspooks would have read Neal Stephenson's Cryptonomicon. Or Brian Krebs. Or Bruce Schneier. Or even the news story of how their old boss(!) John Brennan had his AOL(!) email account(!) cracked(!) by a teenager(!) guessing his password(!). The teenager exfiltrated something sensitive, a job application I believe, and was prosecuted for it. Meantimes, the former Director of…

He did not keep his reputation, at least not among the people who care about that sort of thing.

Source: lived around DC when it happened, had contractor friends complaining out loud about it

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#95
post #64
post #44

Earlier quoted context omitted.

I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.

I have hoped that "Cyber Insurance" might be able to price these risks, and also price information assurance best practice into premiums.[1] Do you think this has, or could work? If an insurance company is unable to price it's own internal IA risks either at all, or at a non-zero value, I'm discouraged from hoping for a market solution to the problem that, as the truism states, "offense is easy, defense is impossible…

There are currently (or were recently) 2 large lawsuits regarding cyber insurance claims working their way through litigation. If they both go in a certain direction, the concept of cyber insurance may be much less appealing (far fewer claims could be paid out, making the concept relatively expensive for less benefit than many companies anticipated).

Basically, insurance only works when the insured has faith that the insurer will pay and that both parties understand the boundaries of the contract. One of the lawsuits involves the effects of WannaCry, which the insurer claims was a state-sponsored attack. "Acts of War" is one of those common exclusions to insurance policies, so the insurer has an incentive to always claim cyber attacks are nation-state sponsored if the insurer wins that case.

The other case I think is about the difference between a general corporate insurance policy which has some coverage related to fraud and the insurer who claims the insured should have purchased a standalone cyber insurance policy. I think that case partially revolves around "when fraud happens on a computer network, is that a 'hack' or is it traditional fraud?"

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#96

I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…

An account from 3 days ago alleges that the CIA is faking Russian hacking info.

Remember folks: there are disinformation campaigns on HN too.

Maybe they're right, but it's a little suspicious, no?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#97

Earlier quoted context omitted.

No, Russian interference allegations were confirmed through other means, mainly human intelligence and other types of intercepts. The dutch even filmed the meddling operations through GRU hacked security camera.

I don't see how the Dutch story is relevant, if it's the one I looked up, and it sounds therefore like there is at best circumstantial evidence. Even motive isn't very reliable because all kinds of people are out to do things like influence the elections.

An account from 3 days ago alleges that the CIA is faking Russian hacking info. Remember folks: there are disinformation campaigns on HN too.

Maybe they're right, but it's a little suspicious, no?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#98

Earlier quoted context omitted.

My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.

It's less about budget and more about we're not the DoD and can do whatever we please, stay the hell off our lawn. Even if it was a "hey, could you look at this and tell us what you think" with no obligation to address issues, it is undesirable to establish a precedence. They do use standards and recommendations from NSA/OMB for enterprise systems. But even the US Courts went that route, just with a lot of renaming o…

Plus there is a reason you secure and compartmentalize information. The NSA may be comprised in some way, and giving them access means that deliberately or accidentally leak something vital.

Same idea in reverse with the CIA -- maybe someone in the CIA is a bad actor and now knows the secret 0-days the NSA is using -- because they're busy locking them down -- and those get leaked.

Post reply on HN