Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

91–100 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#91
post #76
post #55

Earlier quoted context omitted.

> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…

Maybe not feasible now, but maybe it could be feasible at some point in the future if things are built on top of seL4 , with similar techniques used to demonstrate that the programs in question also have some desired security properties, building on the security properties the kernel has been proven to have? Of course, one might still be concerned that the hardware that the software is running on, could be compromise…

Sure, every little bit helps. But, keep in mind formal verification isn’t going to prevent configuration errors, and it remains to be seen if, for example, automated verifiers can do anything like the sel4 proof at scale. sel4 is tiny compared to most other software systems. There will still be technical avenues to attack, and if those get closed off nation state actors will just go back to spying the old fashioned way.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#92
post #75

Earlier quoted context omitted.

Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.

Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.

They are also telling you how to cover-your-ass once a breach happens.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#94
post #72

It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.

Their customer base are enterprise, so the issue can be addressed in private channels. There's little to be gained from making this particular breach public, from their point view. If anything, it's F5 customers who should advise their own customers downstream about the risks, when risks apply. Disclosure: I'm affected by this breach downstream at several sites and we have not been informed of risks by anyone but hav…

why did you purpose one hypothesis and then right after offer first hand evidence that contradicts it?

completely missed your point

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#96
post #88

Earlier quoted context omitted.

Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.

The Crowdstrike Falcon Sensor agent (with a kernel module) establishes TLS connections to several random AWS endpoints. I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.

Well honestly, this security person thinks its a terrible idea - but needless to say the people selling those systems disagree - and for non-technical management, it ticks the compliance box and they get back to their jobs.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#97
post #72

It took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.

My understading is that the hackers had a copy of the source code for their app so they had to patch all their outstanding CVE that they where sitting on so the DOJ let them hold back until that was ready. It's not ideal but I suppose there is at least something people can do right now. Feels like they could have been a bit quicker with some of the information though.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#98

Earlier quoted context omitted.

What I'm saying is they often actually mean "country", but that is less fancy sounding. A nation-state is just one specific type of polity, certainly not the only type which organize attacks.

You’re overthinking it. “Country” is simply more ambiguous when used as an adjective. “F5 announces attack from country hackers” sounds silly and confusing.

"F5 announces hack by foreign country" (or the infinite variations of) is less silly than "F5 announces attack from nation-state hackers", you're just used to hearing the latter repeated every incident. Anyone can intentionally use a phrase poorly, pointing out a silly sounding phrasing exists adds nothing.

Not that "F5 announces attack by state sponsored hackers", "F5 announces attack by nation-state backed hackers", or "F5 announces attack from nationally backed hackers" have to be invalid, particularly since the latter is often what is actually most specifically correct anyways.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#99

Earlier quoted context omitted.

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

No, it's a real thing with a real meaning. Nation-state actors are, in general, very well-funded and sophisticated, and therefore much more difficult (and expensive) to defend against and clean up after. They tend to have different motivations than the normal crime groups, and therefore go after different things.

Of course nation-state actors are real, that was never in question.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#100
post #75

Earlier quoted context omitted.

Not so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.

Every time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.

You will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.
Post reply on HN