10 ms·
Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extreme
by deft 6y ago
Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.
- Aaronstotle 6y agoAssuming it was a state actor, what type of proof could they release? Presumably the FBI wouldn't want to disclose how it came to this conclusion
- _wldu 6y agoSeems like they are seeking attention more than anything.
- enkid 6y agoThey are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?
- _wldu 6y agoIt reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage". It's way over-the-top.
- enkid 6y agoI mean, it's only over the top of it isn't true. Those are all words people have used to describe intrusions in the past, like Stuxnet or Sandworm.
- frakkingcylons 6y agoOf course it was written by a marketing department. They're a $3B public company with 3,400 employees. And you're proposing they faked a security breach and lied to the FBI so they could get media attention? Please be joking.
- deleted 6y ago[deleted]
- enkid 6y agoI mean, FireEye has a pretty good reputation for attribution and investigation of nation state intrusions. This doesn't seem like the type of thing they would just make up. Bot saying we should take them 100% at their word, but investigating intrusions is their entire reason for existence
- stefan_ 6y agoThey have a reputation for making up salacious stories based on totally inconclusive, inadequate "evidence". No wonder they turned it up to 11 when it was themselves getting breached.
- TameAntelope 6y agoCan you describe what you'd consider adequate and conclusive evidence necessary for attribution of a cyberattack?
- corty 6y agoDocumentation verifiably obtained from the attacker about the intent to attack, the methods used, the results and people involved. Preferrably with means to tie everything to a plausible timeline. Attribution is hard to impossible. What passes for attribution these days is laughable.
- TameAntelope 6y agoWould you require this level of certainty when prosecuting crimes domestically? Why or why not? Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?
- sudosysgen 6y agoThat is pretty much the level of certainty required for prosecuting crimes domestically, yes, or very close to it. Time-frame, proof of intent, and motive. There is of course a way of doing so, as long as the attacker made a mistake. If they didn't, then it very well might be completely impossible to know who did it, and that's just how it is.
- Veserv 6y agoWell they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than that, then it would be unprofitable for people to claim their prize and provide pretty good evidence for their security. However, if somebody does claim the prize, then we can reasonably assume that their security level is less than the prize as it is profitable for somebody to claim the prize despite the unknown level of risk involved in a blind uncontracted penetration test. So, what do we all think would be a level of resources that only a state could support? I think we can just start somewhere pretty low like $1,000,000,000. Fortune 500 companies and many criminal organizations could reasonably afford that, but the total number of organizations is still pretty limited, so it is probably a good lower bound. I do not think we can go much lower because if we drop down to $100,000,000 then even FireEye, which is not a Fortune 500 company, could theoretically fund such a venture with its revenue of $890,000,000. Okay, so starting with "only a state" resource level of $1,000,000,000, we should probably divide it by 10 to make it highly unlikely people will do it just to prove they can even if it is unprofitable to get the prize. That leaves us with a simple open prize of $100,000,000 for the first person to demonstrate that they can breach their systems. If nobody claims the prize, then it is highly likely that this attack would take a state-level actor. If somebody does claim the prize, then it is probably doable by somebody who is not a state-level actor. This would provide an unbiased answer about the truth of their implications. If they think such a prize is too high, then they can just set it to a lower X that will give us an unbiased answer to the question: "Does it take more than X resources to breach their systems?"
- late2part 6y agoThis is a very peculiar thought experiment.
- Veserv 6y agoIndeed. It would, however, provide very strong evidence for most such claims. The primary problem with actually implementing it in general is the risk of getting unlucky if you have a very large payout. Say you claim $100,000,000,000. Even if it is an accurate assessment, somebody could randomly luck into a vulnerability that would normally actually take $100,000,000,000 to find and suddenly you are dead since it is highly unlikely you are one of the few companies that can actually survive such a payout. You could alleviate that to some degree with insurance in the middle range, but it is highly unlikely that would work at the very high payouts. Luckily, in this case, a payout of $100,000,000 is actually within FireEye's reach given their revenue and market cap. In fact, they lost more in market cap on this breach news than such a payout. So, if their claims are actually true, this is an entirely feasible and useful demonstration to run. Personally, I think if they actually announced a $100,000,000 prize they would be breached within a week on the outside. At $100,000,000 people can burn dozens to hundreds of zero-days to be the first to get the payout and still come out ahead. Even at $10,000,000 I doubt they would last more than 1 month. At $10,000,000 the prize would be the most attractive bounty in the entire industry by a factor of 3-10x and people could still burn some zero-days and still come out ahead.
- Ansil849 6y ago> The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses This was precisely my read of it as well. Exaggerated usage of superlatives coupled with no actual explanation suggests trumping up an adversary's capabilities to excuse one's own security lapses. Like claiming a highly sophisticated burglar broke into your home, while neglecting to mention you left a window open.
- eoinboylan 6y agoMore likely the FBI telling them not to speak publicly as to not impede an investigation.
- 4354362626 6y agoInteresting that they don't even name the adversary.