3 ms·
I'm gravely naive to modern security methods (both defense and offence) but I work closely with some infosec guys in a big-fish company and they often share tal
by Jenk 2y ago
I'm gravely naive to modern security methods (both defense and offence) but I work closely with some infosec guys in a big-fish company and they often share tales/experiences that I find fascinating because of their ingenuity and temerity.
Some examples:
We have had multiple attempts to use AI as imposters to convince well-wishing colleagues into doing things they shouldn't - a complicated technique that has seen success for the hackers on some occassions[0] - which requires infilitrating numerous accounts etc. This one is the "hollywood romanticized" idea of hacking because it is in realtime with actual people operating the stolen accounts, but using AI to mask their appearance and voice.
Sleeper infiltration - someone will find and breach an exploit, only to patch it, but leave a new backdoor. They then let it sleep for many months, eventually coming back to use it only to (attempt to) completely remove any trace of their presence. inb4 anyone says "ah but they probably copied/did something else you don't know about!" We've had those, too, but some really do just exploit, patch, then leave. Probably to deny someone else or something.
A really fascinating moment for me was watching a seceng spinup a honeypot and it took less than a minute for some attacks to start hitting it.
[0]: https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-k...