CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
1–10 of 106 posts
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#2Hacker competitions mirror this. Red teams are allowed to bring in any exploits and do just about anything (as criminals would be expected to do) and the blue team are stifled by bureaucracy and not allowed to bring in anything.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#3This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#4This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#5This happens in many corporations as well. It's fun and exciting to be on the red-team (doing the penetration testing, writing exploits, etc) but the blue team (infrastructure teams and developer teams hardening things) is not only boring to most, but it's also the team that gets the most grief from developers for inducing friction. If your company has a red team, ask how big the blue team is and if they have the sam…
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#6Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#7Earlier quoted context omitted.
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
What would be a less gimmicky setup?
Moreover, the outcomes are different for both teams:
- RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent
- RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the budget for the cybersec can be reduced.
So, for RedTeam, it's either a win or a tie. And for BlueTeam it's either a tie or a loss...
If the BlueTeam could fight back, maybe this could change...
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#8Earlier quoted context omitted.
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
What would be a less gimmicky setup?
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#9Earlier quoted context omitted.
What would be a less gimmicky setup?
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the…
Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure
#10Earlier quoted context omitted.
Hacker competitions often seem very contrived to me. I suspect that in order for the red team to make any progress you have to tie the blue teams hands behind their backs. Most of what I see from the penetration testing community is pretty gimmicky and situational generally and often doesn't take into account the attackers risk/reward ratio.
What would be a less gimmicky setup?