Earlier quoted context omitted.
> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…
Maybe not feasible now, but maybe it could be feasible at some point in the future if things are built on top of seL4 , with similar techniques used to demonstrate that the programs in question also have some desired security properties, building on the security properties the kernel has been proven to have? Of course, one might still be concerned that the hardware that the software is running on, could be compromise…
F5 says hackers stole undisclosed BIG-IP flaws, source code
91–100 of 109 posts
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#92Earlier quoted context omitted.
Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#93Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#94It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.
Their customer base are enterprise, so the issue can be addressed in private channels. There's little to be gained from making this particular breach public, from their point view. If anything, it's F5 customers who should advise their own customers downstream about the risks, when risks apply. Disclosure: I'm affected by this breach downstream at several sites and we have not been informed of risks by anyone but hav…
completely missed your point
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#95A cybersecurity company was hacked — what an irony
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#96Earlier quoted context omitted.
Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
The Crowdstrike Falcon Sensor agent (with a kernel module) establishes TLS connections to several random AWS endpoints. I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#97It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#98Earlier quoted context omitted.
What I'm saying is they often actually mean "country", but that is less fancy sounding. A nation-state is just one specific type of polity, certainly not the only type which organize attacks.
You’re overthinking it. “Country” is simply more ambiguous when used as an adjective. “F5 announces attack from country hackers” sounds silly and confusing.
Not that "F5 announces attack by state sponsored hackers", "F5 announces attack by nation-state backed hackers", or "F5 announces attack from nationally backed hackers" have to be invalid, particularly since the latter is often what is actually most specifically correct anyways.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#99Earlier quoted context omitted.
Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.
No, it's a real thing with a real meaning. Nation-state actors are, in general, very well-funded and sophisticated, and therefore much more difficult (and expensive) to defend against and clean up after. They tend to have different motivations than the normal crime groups, and therefore go after different things.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#100Earlier quoted context omitted.
Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.