8 ms·
I guess a "State-Sponsored Attack" sounds better than "we got pwned with a bug that was known since March that we didn't patch and could have been exploited by
by f055 9y ago
I guess a "State-Sponsored Attack" sounds better than "we got pwned with a bug that was known since March that we didn't patch and could have been exploited by a guy in a basement" [https://qz.com/1073221/the-hackers-who-broke-into-equifax-exploited-a-nine-year-old-security-flaw/ https://qz.com/1073221/the-hackers-who-broke-into-equifax-ex...]
- sillysaurus3 9y agoIt's a bad idea to dismiss this claim. I haven't worked through whether the claim has merit, but China has an entire division dedicated solely to finding these kinds of issues in other countries. They exploit them ruthlessly. I'm sure a lot of Russian hackers aren't as independent as they seem, either. And of course, the NSA does all of this vs the rest of the world, though I'm not sure they'd be interested in the Russian equivalent of the Equifax situation.
- alva 9y agoI hate this grubby finger-pointing to a state actor. Sadly, the majority of non tech readers will take is as given.
- zitterbewegung 9y agoI think it must be some crisis management / PR department that says to say "done by state actor".
- honestlyreally 9y agoCertainly minimises any anger for the 90m golden parachute given to the person at the helm now bailing out.
- trendia 9y agoIf anything, it turns the CEO into a victim. "No CEO would be able to withstand a targeted attack from such a motivated adversary!"
- RhodesianHunter 9y agoConsidering everything we now know about Russia's attempts to influence our elections and sew division, is it really unreasonable to think they might try to throw a wrench into our credit system?
- lowry 9y agoDid not they just buy ads on Facebook instead of hacking it?
- untog 9y agoYou'll notice the post you are replying to didn't use the word "hack", it said "attempts to influence our elections and sew division", which is something Facebook ads would do quite well. I agree that hysteria over "election hacking" is tedious, but so is blanket dismissal that a foreign state actor would have an interest in influencing a US election. Of course they would.
- heartbreak 9y agoWhy would you assume that a single actor used a single approach in attacking the election process? These election systems would have some extremely useful data for targeting those Facebook ad campaigns: https://www.apnews.com/cb8a753a9b0948589cc372a3c037a567 https://www.apnews.com/cb8a753a9b0948589cc372a3c037a567
- _jal 9y agoThey also attempted hacking (according to the intelligence services) 21 state's election systems, with varying degrees of success. Pretty sure that qualifies as 'unauthorized access'.
- zaroth 9y agoThe Washington Post basically exposed this as "Fake News". https://www.washingtonpost.com/news/the-fix/wp/2017/09/23/what-we-know-about-the-21-states-targeted-by-russian-hackers/ https://www.washingtonpost.com/news/the-fix/wp/2017/09/23/wh... And in case you're interested, here it is from a more colorful source; https://theintercept.com/2017/09/28/yet-another-major-russia-story-falls-apart-is-skepticism-permissible-yet/ https://theintercept.com/2017/09/28/yet-another-major-russia...
- mythrwy 9y agoI think if we look at motive and potential effects on the financial system it's very likely to have been a state sponsored attack. Coming right on the heels of economic sanctions and a stream of threats my wild guess is North Korean involvement. Or else that's who they'll eventually blame it on. Or who knows. Which none of this in any way excuses Equifax's shockingly bad behavior.
- ringaroundthetx 9y ago> Sadly, the majority of non tech readers will take is as given. Even tech readers. I worked with a veteran who would just take that kind of stuff as fact because "17 intelligence agencies cant be wrong"
- megamark16 9y agoI used to work for a company that had a big security hole that would allow you to log in as any user as long as you knew the user's UUID (I know, right?) I logged a ticket and raised the issue up the flagpole to let folks know that if someone slipped in some code (we ran a lot of third party javascript) to harvest UUIDs, they could fairly trivially log in as an admin and do some serious damage. The issue sat for months (MONTHS!) until finally a user complained about some non-https content being loaded on our login page, which sparked a whole security review, and gave me an opportunity to bring additional attention to my ticket, which finally got fixed. This kind of crap is out there, and people don't give it the attention it deserves until they get bitten in the ass. Thankfully, my company didn't get bitten, but if we had, it could have been very bad, and the fact that the issue was called to people's attention and they didn't do anything about it would have made it look that much worse.
- blktiger 9y agoWhy didn't you fix it? (I don't mean this harshly, just curious.) Ultimately, this kind of stuff is something IMO a professional programmer should just do. It's irresponsible to let stuff like this go and you should do whatever it takes to make management understand. In a healthy organization it shouldn't even be questioned by management, you just tell them you found a security issue that will cost the company billions and has to be fixed immediately. In an unhealthy organization, maybe you just slip this into some other work without telling management.
- sillysaurus3 9y agoNegatory. I vividly remember being chewed out at a mega-company for even downloading the source code to `touch`. Yes, touch. Obviously I got out of that environment pretty quickly, but you're not in a position to just do things at big companies. Probably most of them.
- megamark16 9y agoGreat question, and in the end it comes down to politics and team siloing. A large corporation with a lot of projects and priorities, and no single Security person to raise the issue with. At the time I wasn't in a position to Just Do It and then tell everyone "Hey, this needed to be done, I got it done, now I need a QA resource to test it and then we need to deploy it to prod" without some backlash from multiple source (my boss, the team that owned the product, etc). Now (and given everything that's happened in the industry in recent years) I would definitely push more, and maybe fix it on my own, but at the time I just shook my head, and sent follow-up emails every few months to try to keep visibility on the issue.
- pvarangot 9y agoIt's fun how when a big corporation is hacked it's always "a sate sponsored group with 0-days worth millions of dollars", but then again nation states themselves keep getting hacked by "a lonely autist in a basement that's just very smart for his own good".
- AsyncAwait 9y agoWhat isn't a 'state-sponsored attack' nowadays? Seriously it's been a while since I've heard of an attack that wasn't eventually claimed to be state-sponsored.
- mi100hael 9y agoWell, someone was a citizen of a particular state, and received tax-funded benefits like roads, ergo "state-sponsored."
- jcrawfordor 9y agoA lot of people seem to feel like 'state-sponsored attack' and 'attack enabled by massive security management problems' are mutually exclusive. It is completely possible, and history indicates very likely, that Equifax was both massively incompetent and attacked by a state-sponsored organization. The state actors are working very hard to find these kinds of vulnerabilities, so it makes perfect sense that gaping security issues are being exploited by the people who are putting the most time into finding them.