CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
91–100 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#92Earlier quoted context omitted.
Agreed, It doesn’t seem appropriate for info-sec people to be making decisions about what which risks to mitigate, ignore, etc. They should provide input into that process though. We struggled to even get the CIO and CEO to acknowledge and discuss info-sec risk and make decisions regarding what to do about that risk.
Oh yeah, if they aren’t going to even show up to the conversation then it’s time to yank the ripcord.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#93Earlier quoted context omitted.
Oh yeah, if they aren’t going to even show up to the conversation then it’s time to yank the ripcord.
By yank the ripcord do you mean leave the organization? I see this type of behavior at just about every company I have worked. There is no real priority to fix security holes even when they are discovered.
Moral of the story is determine how it impacts your career goals and chose.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#94How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…
You'd think at least some of these inept cyberspooks would have read Neal Stephenson's Cryptonomicon. Or Brian Krebs. Or Bruce Schneier. Or even the news story of how their old boss(!) John Brennan had his AOL(!) email account(!) cracked(!) by a teenager(!) guessing his password(!). The teenager exfiltrated something sensitive, a job application I believe, and was prosecuted for it. Meantimes, the former Director of…
Source: lived around DC when it happened, had contractor friends complaining out loud about it
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#95Earlier quoted context omitted.
I left a high pay info-sec position at a large insurance corporation for this very reason. CIO trumped CISO (fractional) on literally every security issue that was surfaced - and worse yet the CIO and CEO refused to acknowledge the risk being onboarded/ignored. The irony of insurance execs refusing to acknowledge information security risk was just too much.
I have hoped that "Cyber Insurance" might be able to price these risks, and also price information assurance best practice into premiums.[1] Do you think this has, or could work? If an insurance company is unable to price it's own internal IA risks either at all, or at a non-zero value, I'm discouraged from hoping for a market solution to the problem that, as the truism states, "offense is easy, defense is impossible…
Basically, insurance only works when the insured has faith that the insurer will pay and that both parties understand the boundaries of the contract. One of the lawsuits involves the effects of WannaCry, which the insurer claims was a state-sponsored attack. "Acts of War" is one of those common exclusions to insurance policies, so the insurer has an incentive to always claim cyber attacks are nation-state sponsored if the insurer wins that case.
The other case I think is about the difference between a general corporate insurance policy which has some coverage related to fraud and the insurer who claims the insured should have purchased a standalone cyber insurance policy. I think that case partially revolves around "when fraud happens on a computer network, is that a 'hack' or is it traditional fraud?"
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#96I saw a screenshot of a CNN article which said that that the CIA frequently used tactics to make hacks appear as though they were from Russia. Which is something I always suspected was relatively easy to do...change some logs, some timestamps, use some existing code...I'm not a hacker per se, but most of us write code here and deal with these kinds of things... So does anything in this vault possibly call certain rec…
Remember folks: there are disinformation campaigns on HN too.
Maybe they're right, but it's a little suspicious, no?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#97Earlier quoted context omitted.
No, Russian interference allegations were confirmed through other means, mainly human intelligence and other types of intercepts. The dutch even filmed the meddling operations through GRU hacked security camera.
I don't see how the Dutch story is relevant, if it's the one I looked up, and it sounds therefore like there is at best circumstantial evidence. Even motive isn't very reliable because all kinds of people are out to do things like influence the elections.
Maybe they're right, but it's a little suspicious, no?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#98Earlier quoted context omitted.
My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.
It's less about budget and more about we're not the DoD and can do whatever we please, stay the hell off our lawn. Even if it was a "hey, could you look at this and tell us what you think" with no obligation to address issues, it is undesirable to establish a precedence. They do use standards and recommendations from NSA/OMB for enterprise systems. But even the US Courts went that route, just with a lot of renaming o…
Same idea in reverse with the CIA -- maybe someone in the CIA is a bad actor and now knows the secret 0-days the NSA is using -- because they're busy locking them down -- and those get leaked.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#99Guess it's good to know that even big gov orgs are disfunctional