4 ms·
Lot of comments here hand waving away cybersecurity attack attribution as being arbitrary or guesswork, but I think it’s important to note industry leaders like
by asynchronous 4y ago
Lot of comments here hand waving away cybersecurity attack attribution as being arbitrary or guesswork, but I think it’s important to note industry leaders like Mandiant don’t point blame lightly.
There are plenty of ways for an attacker to give clues to researchers about where they are based out of and who is funding them.
- rightbyte 4y ago> There are plenty of ways for an attacker to give clues to researchers about where they are based out of and who is funding them. How exactly would you know who is founding what by looking at a bitstream originating from anywhere on earth but last jump in Iran to your server?
- asynchronous 4y agoThis comment is a key example of what I’m talking about: Researchers and analysts don’t just look at where the physical address of the packets came from when leveling an accusation as serious as nation state attacks. They take into account things like previously known threat actor capability, nation state actor characteristics, malware specialization, enumeration and exfiltration toolkit, command and control infrastructure, and finally motive. When coming from an industry giant that’s been working with US intelligence groups, it’s really a rigorous process.
- LtWorf 4y ago> They take into account things like previously known threat actor capability, nation state actor characteristics, malware specialization You mean they pin it on whomever they want to. It's all meaningless. It's like telling how someone voted from their shoe print.
- hardnose 4y ago>How exactly would you know I wouldn't worry about it.
- hobo_in_library 4y agoThey also only claimed "moderate confidence" in their assessment