8 ms·
Breach at IT Outsourcing Giant Wipro
- bk_avalara 7y agoSite down ATM, Google Cache doesn't have it, but good old Wayback machine has it: https://web.archive.org/web/20190415214511/https://krebsonsecurity.com/2019/04/experts-breach-at-it-outsourcing-giant-wipro/ https://web.archive.org/web/20190415214511/https://krebsonse...
- 3xblah 7y agohttp://web.archive.org/web/20190415214511/https://krebsonsecurity.com/2019/04/experts-breach-at-it-outsourcing-giant-wipro/ http://web.archive.org/web/20190415214511/https://krebsonsec...
- nodesocket 7y ago> "The company has robust internal processes and a system of advanced security technology in place to detect phishing attempts and protect itself from such attacks." Somehow I don't think this is a phishing attack.
- mc32 7y ago>”Wipro’s systems were seen being used as jumping-off points for digital fishing expeditions targeting at least a dozen Wipro customer systems.“ Well, it looks like it was used as a launching point to phish their (Wipro’s) clients. They probably had s pretty good catch. I imagine one of their clients alerted them to the issues.
- rdasm 7y agoHumans are the weakest link
- rdasm 7y agoConfirms phishing. https://www.reuters.com/article/us-wipro-cybercrime/indias-wipro-investigating-potential-breach-of-some-employee-accounts-idUSKCN1RS0B0 https://www.reuters.com/article/us-wipro-cybercrime/indias-w...
- panarky 7y agoMight be interesting to annotate the biggest data breaches with each victim's outsourcing partner. https://en.wikipedia.org/wiki/List_of_data_breaches https://en.wikipedia.org/wiki/List_of_data_breaches
- dsl 7y agoI know of at least one very large customer where management of the VPN appliance and firewall controlling access of Wipro vendors was outsourced... to Wipro.
- duxup 7y agoI had a problem with traffic black holing all of a sudden everything going nowhere with Wipro once. What we found was that suddenly a some ports with traffic distended for the internet bounced and the black holing started. A Wipro rep proudly announced that they had caused the port bouncing. You see they found that someone (Wipro... but they didn't know it was their own people at this point) had cabled around the firewalls a year earlier because something wasn't working, and never hooked them back up. So now we were cabled to the firewalls properly... the firewalls that as far as anyone could tell had nonsensical configs that all pointed to a null route. So for at least a year, maybe more, there was no firewall. The end customer was a large financial institution.
- joe_the_user 7y ago"India’s third-largest IT outsourcing company — was dealing with a multi-month intrusion from an assumed state-sponsored attacker. "Both sources, who spoke on condition of anonymity, said Wipro’s systems were seen being used as jumping-off points for digital fishing expeditions targeting at least a dozen Wipro customer systems." Well, I suppose it's the step you'd expect but a state-actor engaging in a broad fishing trip still seems like a new thing. Can we expect whatever state will be installing their official botnet in whatever country next?
- IOT_Apprentice 7y agoWhelp, life comes at you fast: https://www.bankinfosecurity.asia/interviews/wipros-new-ciso-on-frictionless-security-i-4239 https://www.bankinfosecurity.asia/interviews/wipros-new-ciso...
- geodel 7y agoDude has 11 industry-recognized certifications in the domains of IT, information security, security framework and secure enterprise architecture. So I guess Wipro will have everything under control.
- cannonedhamster 7y agoHoly crap... That's not what frictionless means. That's literally the definition of appropriate levels of security based on risk profile, but even high levels of security should be frictionless, i.e. they should work the same way every time and should be relatively easy to do, which is what 90% of MFA apps are. What's not frictionless is when your security team needlessly causes you to change your very secure password every 90 days because someone told them that was a good idea. It leads to sticky notes and easily cracked passwords that use formulas i.e. Spring2019! Summer2019! And so on like in so many corporations due to poorly thought out security implementation. Longer time before forced password changes coupled with either a physical key or software token that don't have to be remembered are way better.
- hn_throwaway_99 7y agoMy lord the "frictionless" buzzword BS in that made me feel like I was actually losing brain cells: > He offers insights on: > How privileged access management will fit into a frictionless security approach; > The role of artificial intelligence, machine learning and blockchain in enabling frictionless security and faster threat detection; I seriously considered registering justaddblockchain.com after reading that to document all the places where people feel they look smarter by just adding "blockchain!" to random technical discussions.
- aluminussoma 7y ago"State-sponsored attacker": A euphemism to deflect blame for your own inadequate security practices.
- btown 7y agoThe attacker is happily sponsored by the state of affairs at the company.
- Aeolun 7y agoThis surprises me... not one bit. I have yet to find the first multibillion outsourcing company that was any good. All the great people are immediately hired by the company they’re actually working for, so they’re always left with the mediocre and terrible.
- Bombthecat 7y agoMaybe, they could pay market price than? Oh, the only target is to be cheap.. Okay then
- mikekchar 7y agoTo be fair, the OP was referring to all large outsourcing companies. There are a lot of outsourcing companies that charge well over the rate for a full time hire (they don't necessarily pay their employees that, but...) I worked briefly for one such "body shop" and I found that the company billed my time at a rate of about twice what they paid me. As far as I can tell, it tends to slot in between a full time employee and an independent consultant/contractor in terms of price. Why do companies pay this premium? For one, it may be because they have a budget for a "6 month project" (wink, wink, nudge, nudge) but not for a full time hire. Sometimes it's because they think that they'll be able to pick and choose the best developers from inside a large organisation (and sometimes it works out that way... almost never, but sometimes...) But really it's just a matter of being naive, I think. The company I used to work for (as an independent contractor... ahem...) went through a phase where the CEO was absolutely convinced that it didn't pay to hire developers -- they were a PITA (always demanding weird things, never showing up before 10:30 am, never dressing properly for work, etc, etc). They always wanted raises and you have to track progress and negotiate with them on price every year. You have to pay benefits and if a person is on disability on maternity, you've got to do something about it. You constantly need to be reviewing CVs, interviewing and hiring. If you get someone really bad, you can't actually reasonably fire them for a long time. Etc, etc, etc. So he tried a few experiments with hiring from outsourcing companies (all of which were charging considerably more than any of us were getting paid, I will add)... and it wasn't a disaster, but it wasn't really any better. But the cherry on the cake was, as soon as the project was done, they fled and no amount of pleading could get those developers back again (as you can imagine). So the CEO realised that having a crack development team was definitely worth the effort and the company really transformed as a result. However, a lot of companies are still stuck in the mindset where it's best to have as few full time developers as possible.
- suff 7y agoIn my best Wipro-excuse voice: "... see, thing is:..." ... they have a process for everything. It's just a very convoluted, silo'd, circuitous process that takes several days to get anything done, with several steps including: throw a support ticket over the wall, and let a subprocess pick it up. On and on we go, until we have a lax process that is impossible to fix, on to which, all we can do is pump more, cheap, low skilled talent. But hey, it's creating a middle class somewhere.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- yalogin 7y agoWhat doesn’t surprise me is Wipro refusing to comment. This would have never come out if they weren’t targeting from inside the house.
- forks25 7y agowould we classify this as a friction-less security breach?
- duxup 7y agoA few years ago I worked with Wipro as they would contact me (technical support for some products) on behalf of their customers. The incompetence was astounding, and I worked in support for a long time, and Wipro was really astounding. Everything from security to just understanding what we were telling them was mindbogglingly bad. It wasn't a language barrier, they simply didn't have many / sometimes anyone who understood the technology on the most basic level. Wipro would open tickets dozens at a time claiming there was some sort of technical issue, but they often couldn't explain what if anything they tried. We would find the equipment at factory defaults, last boot time was when it was in the factory.... but now it was a P1 ticket because "it didn't work and it needs to be up and running by the end of the day". Then we'd ask what how they wanted it configured and they ... wouldn't know. Then they'd escalate through sales and the executives claiming we had been "working with them for weeks and were not helping". Then they would go silent and not respond for days or weeks only to reappear later as angry as ever that we hadn't done anything when our last questions to them might be as simple as "what isn't working?". It was worse when they actually tried configuring things as they were masters at nonsensical configurations, looping cables back into the same equipment they came from and etc. You could look at their systems that were "working" and it was errors everywhere and you couldn't trust anything you saw. Even internally Wipro would tell us that they "can't tell" the "other team" (another team inside Wipro working with the same customer) that they need to change their configuration. They would just repeat that they can't tell them that ... and we'd be stuck because it's obvious the "other team" is configured wrong. I'd tell them to let me be the bad guy and tell them on a call, but nope. So things would just not work. It was a common occurrence as things got worse that we would eventually end up on a conference call with Wipro and their end customer and their customer's perception was entirely off. There was no way it was miscommunication, they were straight lying to their customer all along. Often we'd have to break the news to the customer that we haven't been working on the issue for weeks, we just heard about it today, nobody can tell us how they want the product configured on the most basic level... The only thing worse than that situation was to look up these customer's of Wipro and see they scrapped their own IT departments in favor of outsourcing, and I'm not sure they had more than a couple people who understood what was really going on.
- pts_ 7y ago
- lifeisstillgood 7y agoCan any of the security folks on here tell me what good secure systems really look like? If I wanted to build a company infrastructure from scratch what would "default secure" look like? I am fairly sure I know what a good software engineering process looks like, but if I guessed a secure infrastructure I would be concerned I am missing basics. (Hence no examples to get us started)
- baybal2 7y agoFoucs... You can't protect everything, but can ensure that handling of at least some truly important data is as paranoid as it can be. Protecting a company's FTP server that is open to thousands of employees is not a doable task, for example And the same is true of human knowledge, a company saying that all and everything within its walls is super secret, can't truly hold anything secret. At one of my first jobs in Canada, an owner of the company was very clear on the point what is a commercial secret and what isn't. Whenever there was a meeting genuinely demanding it, he clearly stated at the start "this is a commercial secret covered by confidentiality agreement."
- baybal2 7y agoFocus* typo...
- ocdtrekkie 7y agoCorporate mindset understanding the importance of security is more important than "implement LAPS" or "follow modern password policy guidelines instead of ones from 2002". If you look at a lot of the big breaches, they have some pretty common patterns. Old operating systems (XP, 7, etc.), unpatched software, excessive vendor access. This isn't because they don't have money to manage these things, it's that other business priorities with immediately visible results have taken priority. "This business software sales needs was designed for Windows XP" takes prioritization over "It's unsafe to use anything older than Windows 10 on our network". If another department and IT have a conflict, the other department wins because it brings in revenue. If you have people in the chain of authority above IT who support IT, and understand that securing your infrastructure prevents catastrophes on the same level as fires and the PR disasters, you will generally do much better than businesses who don't. People need to understand that IT/security personnel are not "annoying" them, but trying to help them avoid catastrophes they don't even understand.
- Neil44 7y agoWith the increase in MSP style operations with an IT companys systems having root access across all their client's systems IT companies are going to be massive targets for bad actors. There's already been a few cases of all of a compaies clients being ransomwared.
- bechampion 7y agoIf you've ever had the pleasure to work with people from wipro,ipsoft,atos etc to name a few this should not surprise you.
- throw2016 7y agoHow do we understand these kind of threads of HN? In the last 6 months there have been security breaches at Facebook [1] Google [2] Cisco [3] and look at those threads and some of these breaches are extremely amateurish and the general consensus is these things happen and the top voted responses mirror this attitude. Yet on the same site on the threads about India, China and non US companies we see some kind of dissonance where these are reframed as showhow affecting these companies uniquely because of 'poor standards' and 'mediocre engineers' and the top voted responses reflect this. Far from informed discussion this not only demonizes entire groups but creates and perpetuates prejudice that will no doubt impact everything from recruitment to general behavior. And this continues on discussions beyond security to things like corruption, surveillance and other issues. [1] https://news.ycombinator.com/item?id=19565918 https://news.ycombinator.com/item?id=19565918 [2] https://news.ycombinator.com/item?id=18170174 https://news.ycombinator.com/item?id=18170174 [3] https://news.ycombinator.com/item?id=19507225 https://news.ycombinator.com/item?id=19507225
- throwvatars 7y agoHN has a predominant US reader base. Its natural that they compare everything else in the world vs US. For ex: If China excels in bullet trains, a common rhetoric will be that they copied something from the US, China's human rights issues and then goes on to say about some failed bullet train project in California. I am not sure how those discussions invokes "intellectual curiosity", but still gets to the top of HN. I got sick of this. So I created a filter with some ML out of HN RSS feeds which filters posts that it thinks is not on par with "intellectual curiosity" theme. The filter has shown great improvements as I continue to give it valid inputs. This includes all those toxic bashing like in this one.
- ryanlol 7y ago1 is not a FB breach.
- matt_s 7y agoA breach that involves a technical vulnerability is one of those things that happens, gets patched and everyone moves on. One of the things when establishing a contract with a company like Wipro is that they operate on your systems from locked down rooms where disks, thumb drives, etc. are not allowed. A secure private link is setup to your corporate environment to ensure that your customer's data is not available to the outsourced firm to do with as they please. A breach on Wipro which allowed an attacker to gain access to 11 customer systems (i.e. maybe some Fortune 500 companies) to me means they should pretty much go bankrupt because any sane customer will stop doing business with them as soon as they can. It speaks of incompetence and complete disregard for common safeguards. How can a breach into Wipro's corporate system in any way lead an attacker to Wipro's customer's data? An obvious one could be their employees sending customer credentials via the Wipro corporate email.