Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

1–10 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#4
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

This def seems like corpo disaster PR copy. Not the kind of content I expected and love HN for

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#7
I'm not sure if item #2 in the linked advisory ("identify if the networked management interface is accessible directly from the public internet") indicates whether compromise is only likely in that situation or not, but... lots of remote workers are going to have some time for offline reflection in the next week, it seems regardless.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#8
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#9

Source: https://my.f5.com/manage/s/article/K000154696

> highly sophisticated nation-state threat actor

Sure thing. It's so hard not to hate this PR stuff when they can't even be a tiny bit humble. "The hackers were so sophisticated and organized, we didn't even have a change! They could've hacked everyone!"

> In response to this incident, we are taking proactive measures to protect our customers

Such as, fixing the bugs or the structural problems that led to you being hacked and leaking information about even more bugs that you left undisclosed and just postponed to fix it? This wording sounds like they're now going the extra mile to protect their customers and makes it sound like a good thing, when keeping your systems secure and fixing known bugs should've been the first meters they should've gone.

Just be honest, you fucked up twice. It's shit, but it happens. I just hate PR.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#10

“No one will ever find these vulns without source access! Fix deferred” oh wait…

Yeah, I was trying to make sense of what was described here.

Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products?

If so, lol.

Post reply on HN