9 ms·
A Cybersecurity Firm’s Sharp Rise and Stunning Collapse
- deleted 7y ago[deleted]
- marcoperaza 7y agoHere is a proper news article for those who can do without a dozen pages of drivel about the CEO's hairdo, flying lessons, and underwear shopping: https://www.theregister.co.uk/2016/03/18/fbi_raids_cybersecurity_firm_tiversa/ https://www.theregister.co.uk/2016/03/18/fbi_raids_cybersecu...
- jvehent 7y ago> 76-97 minutes read indeed...
- ianhawes 7y agoThats a good way to phrase it. About 1/4 way through the article I realized I wasn't anywhere close to the end.
- notzuck 7y agoWhilst theregister.co.uk does get straight to the point. the newyorker article tells a very interesting story about his work in hacking P2P, working with the secret service, trying to sell his software to the FBI, GPS tracking his mates cheating wife etc.
- Ozumandias 7y agoYeah, people on here don't seem to understand that you read the New Yorker for narrative and literary craft, not for getting information as fast as possible.
- SilasX 7y agoAnd New Yorker article submitters don't understand that the HN crowd tends to prefer the Register style, at least for providing a focal point where everyone can get up to speed quickly for a productive discussion.
- notzuck 7y agoI don't think that's true and there appears to be room for both. I read both, one is good for quickly understanding what's happening / happened and the other is a much richer and interesting story. Twitter can exist in the same universe as novels you know.
- SilasX 7y agoI didn't say no one should ever enjoy NYer style articles, only that the Register is better for getting everyone to the point where they can productively discuss the article. A flowery style no one will ever finish isn't as good for that.
- notzuck 7y agoThe register is liberal trash from a bunch of 70's labour marxists.
- danso 7y agoBut the Register article is from 2016, when the firm had recently been raided. The New Yorker article covers the years afterward, including how the firm managed to sell its assets to Kroll, a well-known private-eye/corporate-intel firm. I can't speak for the average HN reader, but I honestly don't give a shit that a small cybersecurity firm I've never heard about got raided and shut down, whether it was in 2016 or 2019. I am much more interested in the story of the people who created the firm, how they managed to find success, and what led to their downfall. Such information is often not satisfactorily communicated in a news brief style.
- ThrowawayR2 7y ago
- willbw 7y agoSome people find the details interesting. Life isn't always about processing information as quickly as possible
- robocat 7y agoNormally I prefer El Reg but that is dry and uninformative, whereas the New Yorker article rocks a heap of other critical information. Most importantly they are colouring in the people and their flaws, without specifically labelling them (e.g. psycho/sociopathic is never said, but the behaviours are). The interactions with politicians and federal entities are critical to understanding the story. What you see as irrelevant information is all extremely relevent if you care about protecting yourself against fraud, manipulation, bad actors, etcetera. Think about the legal and social context of this article, and you will see other facets of the reporting that are clever.
- robocat 7y agoThe El Reg persona: I am a middle aged intelligent man who used to be an engineer, and now I have moved up the ranks. I work in IT for a droll company, so I can afford some toys and vacations, and a bit because I just like hardware. I treat El Reg like a British pub, where wit is appreciated, and sometimes we talk about "the war" (our collective past), and certainly taking the piss out of ourselves and everyone else is a good laff. I also need to know some of what El Reg writes about for work; at least they make it fun, unlike most of the rest of my job where much of the pleasure is black.
- SlowRobotAhead 7y agoI thought it was going to be Crowdstrike. But I suppose that hasn’t happened yet. Whatever tech, whatever assets, whatever they have, you can do as you will, I would need to have my head in the sand to be doing business with them. Too much smoke not to be at least a little fire. Just my opinion of course! Edit: One of those times practicality clashes with politics apparently. Can’t say anything bad about the company that failed to protect high profile clients, then used that failure to help start the Trump/Russia fiasco before quietly walking their statements back - because to be aware of that would mean supporting the bad man.
- katbyte 7y agoCould you elaborate on Crowdstrike?
- chelmzy 7y agoJust purchased their product as it is at the top of the EDR market. Could you explain your comment?
- SlowRobotAhead 7y agoAs CTO I looked at it as well. The product isn’t the issue. Well, let me fix that by saying if you don’t mind your all data being entirely entirely open to your cloud protection system and their partners and contractors in a way that is completely black box, there is nothing wrong with the product. It’s the practices and their work with the FBI that came up from the 2016 election and their protection of the DNC when they were allegedly hacked by Russia, statements they made then retracted, and everything that has come since are the issues. Like I said, maybe nothing, but a lot of smoke. At the very least, I don’t want my infosec suite to have such a high profile for failure to protect incidents. Too much for me and my company. We went a larger name alternative and deployed some more open and transparent solutions where we could. I’m expecting a rebrand of the CrowdStrike name sooner than later.
- chelmzy 7y agoThe logs they send to their cloud (which is just Splunk in AWS) seems pretty transparent. In fact you can pull the raw logs directly from them via S3 buckets to see exactly what data is uploaded. When you say it's a black box what portion of the product are you referring to?
- cerved 7y agoAhaha, the fake memoir
- baobabKoodaa 7y agoThe author seems to confuse peer-to-peer file sharing networks and onion routing. The explanations in the article don't make any sense.
- armitron 7y agoWhat doesn't make sense? Limewire is P2P. My impression of the -sparse- darknet mentions is that they were independently (= not through their P2P monitoring software) looking for useful data there and manually inserting it into their datastore.
- danso 7y agoI didn't see any mention of onion routing. There's several references to the "Deep Web", but that's in the context of file-sharing peer-to-peer networks.
- gwern 7y agoI was also a little puzzled by > In the nineties, Microsoft pursued a canonical FUD strategy, creating phony error messages to make consumers wary of using Windows on a competitor’s operating system—a tactic that resulted in a legal settlement exceeding two hundred million dollars.
- acdha 7y agoI believe that’s a reference to this code and the resulting court case: https://en.m.wikipedia.org/wiki/AARD_code https://en.m.wikipedia.org/wiki/AARD_code
- gwern 7y agoHuh. I was thinking it was something to do with MS Word or other MS apps (which I know often had cross-OS or alternate OS versions, like Mac support). But no, that is indeed about... running Windows on a non-MS OS (non-MS DOS). Back when Windows was a GUI shell around DOS. Now that is history.
- lanevsky 7y agoCybersecurity is not security? Like Anonymous cryptocurrencies are pseudo-anonymous? https://inechain.com/blog/what-are-anonymous-cryptocurrencies-and-how-do-they-work/ https://inechain.com/blog/what-are-anonymous-cryptocurrencie...
- gwern 7y ago> “Institutions will try to preserve the problem to which they are the solution.” — Clay Shirky https://kk.org/thetechnium/the-shirky-prin/ https://kk.org/thetechnium/the-shirky-prin/
- GhettoMaestro 7y agoWhat the hell did I just read? Wow.