3 ms·
This is exactly the kind of theatrics I expect from the "security" industry. Couldn't just call Russia "Russia", that would be too simple and understandable. Ha
by throwawaylinux 3y ago
This is exactly the kind of theatrics I expect from the "security" industry. Couldn't just call Russia "Russia", that would be too simple and understandable. Have to make up cool and scary sounding code words and logos like we're in Hollywood's version of the CIA, doing secret missions.
"Nation-state actor" is another hilarious one. For some strange reason everybody in the computer security industry decided to misuse the term (https://www.e-education.psu.edu/geog128/node/534 https://www.e-education.psu.edu/geog128/node/534) because... it sounds cool or scary or something. Why? Certainly doesn't signal anything positive about their understanding of geopolitics. If they'd just communicate like normal people then they would be taken more seriously. It all just reeks of snake oil salesman behavior, where words are not used to communicate and create mutual understanding, but to confuse and conjure the appearance of authority and grandiosity.
- er4hn 3y agoWired has their own take on it (https://www.wired.com/story/hacker-naming-schemes-spandex-tempest/ https://www.wired.com/story/hacker-naming-schemes-spandex-te...) where they actually interview the team that made this change. The overall scheme was driven by wanting more searchable names (I guess even threat intel needs SEO) but as for how they choose them... it feels like a fun way to personalize. FTA: `“There’s some origin story to each one,” Lambert says, “or it could just be a name out of a hat.”` Also closes with this banger of a paragraph: Until then, well, just watch out for Periwinkle Tempest. Last year, Periwinkle Tempest launched crippling ransomware attacks across the entire nation of Costa Rica, leading the country's government to declare a national emergency. Periwinkle Tempest are some of the most dangerous hackers in the world. Periwinkle Tempest. Seriously.
- aww_dang 3y agoIt is even worse when your sites are on the other end of these absurd accusations. "Verified threat incident", because public user data was aggregated? Hope you enjoy a long, accusatory email exchange with a sub-literate employee in their overseas (a Gulf state) based office. Best you can do is learn to laugh at these people. Don't do it too contemptuously though, they might send your site's data along to their own aggregators. That would cost you an entire domain name. Basically, Microsoft Threat Intelligence (formerly RiskIQ) craws the web, sends automated abuse complaints and backs them up with people who cannot even speak English, much less understand the context of their task. For independent publishers, the sword of Damocles is dangling. They can easily have your entire domain flagged and nuked from search. See also: "Google Safe Browsing".