How Not to Acknowledge a Data Breach
krebsonsecurity.com
krebsonsecurity.com
The only reason these kinds of companies continue to exist is the continuing stupidity of American Executives who will go to any lengths to not pay a decent wage for their Software operations. Fuck them, and they deserve exactly this for fucking over good quality talent.
Nobody would be surprised if a bridge built by cheapo contractors failed. Its much the same way with Software.
I've never seen anyone happy with the arrangement, management is merely satisfied by the cost savings. Quality is far (far) lower, but price is far lower as well.
From their Q4 FY18 presentation: https://www.wipro.com/content/dam/nexus/en/investor/quarterl...
Supposedly they are used by 150 of the Fortune 500.
It can also be a stressful one if the tech you're familiar with goes out of style. Lots of re-training involved, years of experience is basically worthless, etc.
In retrospect, and as much as we in engineering hated their code, it was probably worth what they paid for it just because it got us 75% there and took pressure off the team while we created the replacement code.
Another thing they do is supply you with an endless cascade of developers who rotate in and out of your dev team on a 3-month basis. In those three months they will a) tell your IT team that they need a newer laptop because their current one gets slow when trying to run 3 instances of Visual Studio concurrently b) wonder why hard drive failures are correlated with rough handling of the laptop c) ask IT to troubleshoot their compilation errors d) only save their code locally instead of to a shared repo e) get upset when 3 months of said locally saved code, which IT was never told about, gets lost when the laptop, previously issued to the dev they replaced, is re-imaged before redeployment as per company policy/standard-procedure f) thereafter dodge turning in laptops to IT after their rotation ends, instead giving it directly to their replacement, causing IT's stores of deployable laptops to get depleted, and thus causing IT to come hunting after the never-turned-in laptops, because the next wave of 3-month devs is coming and hardware to issue them is needed, and finally g) treat company-issued laptops so roughly that when IT eventually does them back, what was brand shiny and new 3 months prior is now chipped, cracked, scratched and covered in grease and crumbs, and has a full kitten's worth of fluff accumulation in the cooling fan.
Okay, that last one was a bit hyperbolic, but every single point there did happen, and more than once.
Yes, I have been embittered by contractors from these large Indian IT firms, both as an end user 'supported' by them and as a co-worker supporting them. My experience with them has not been a positive one.
I'll skip all the drama - but one thing you could do is call the help desk to get your password reset because of one clusterf after another. It actually worked great. Hi, my username is JoeBob. Ok JoeBob, your new password is XXXX.
That was it. This is a system with super long passwords that had to be changed ridiculously often, and an account lock feature after a few messed up entries which required a password reset and lots of temp staff who came and went among other issues (there were two layers of passwords and people constantly got them confused).
So they had a metric TON of password calls. Despite all the drama with passwords, you could get your password reset just by knowing your username and the number to call for resets. It was brilliant and did save a TON of time, but I had to laugh at the security of the system given your username was derived directly from your name and was widely available in reports etc.
I never mentioned anything though because the thought of a more complicated procedure to deal with for all the staff would have been a nightmare.
I haven't worked there for years. When I was laid off during the acquisition, I didn't protest, because I was about to look for a new job anyway. My only regret was not being allowed to finish building the new image deployment system so the persons to take up my duties wouldn't have to deal with yet-another-half-finished-system-built-by-people-no-longer-working-here.
This place worse than most, tends to eschew in-jokes and memes as marks of belonging and membership, and rely instead on unexplained jargon.
The unexplained jargon isn't any worse here than anywhere else. Everything from motorcycling to woodworking to sewing has its own arcane terminology for simple concepts to ostracize the unlearned.
Yes, you too can get icy stares from a table full of middle-aged women at the sewing club for failing to be born with the knowledge that "the thing that does edges" is actually called a "serger."
"C-and-C", for "command-and-control," is particularly vague and has multiple presentations-- C+C (Music Factory? An equation?), CnC (machining for materials fabrication), C2 (tutoring? Dicarbons?), C&C (a law firm?), CC (credit card).
APT (advanced persistent threat or Aptitude package manager?) is also annoying.
If you're curious, a whole bunch of security-related acronyms are reflected in the various product names and descriptions here:
It's rough if you're skimming though (and who has time to read everything on the web?)
Couple of years ago I was working at the offshore office of a large internet company. They claimed that their platform touched nearly 15-30% of internet users. They had a large Security Operations Center to ensure every threat was monitored and mitigated.
Our software and systems were frequently flagged for security issues. Any suggestions to alleviate the issue fell on deaf ears.
The onshore US IT team always complained about how security changes will make life difficult for them. The biggest critic was someone who had once opened a phishing mail and got his password stolen (using memory dumps in Windows).
While the offshore team was afraid that pushing US onshore team too hard might put their jobs in danger.
And as if getting hacked wasn't enough, these guys exchanged plain text files containing everyone's salary via email. No amount of training or meeting helped.
Finally, a roundabout solution was put in place. Give US folks two laptops - one with heavy encryption for work and second, for checking mails.
But they wouldn't budge on spending salaries in plain text. They said, it was easier for them to manage this way.
Phishing is a numbers game. Make it convincing enough, send to enough people, and wait for someone who's too busy/tired to think to fall for it.
> The onshore US IT team always complained about how security changes will make life difficult for them.
Because that's absolutely true and valid complaint. From their point of view, they're being paid for doing jobs, and then the company starts spending money to prevent them from doing their jobs. I've been on the receiving end of this in the past, where only sanity of our internal IT team prevented making all software development take 3 times longer, because the company decided to apply some completely bullshit "security practices" they found in ISO-whatever compliance handbook.
Security needs to work with people, not against people. You can't just announce security changes that utterly destroy existing workflows, without helping develop equivalent replacement workflow (with all corner cases accounted for), and while still expecting the same amount of work from people. You'll just see people push back hard, and then ignore the new changes to the extent possible while still trying to meet their deadlines.
It was a huge waste of time. From what I understand a dev installed something bad one time so they punished everyone. Then again that's usually how these things happen.
They were some of the best IT people I've worked with, but they'd just run into a situation where they were the people who needed permission and they had to create exceptions on the fly. There's always going to be a place where the process breaks down and either you give the IT people room to adjust their policies or you make them sit on their hands and pretend nothing is going on.
† Not my terminology.
I agree that it is a valid complaint.
But simple rules like - Use a thick/thin client or terminals instead of hopping on to a server or use complex passwords with password manager if required or the easiest one - don't open personal emails on work machine, should be easy to follow.
And it is often a race against various competing priorities. For example, if there is an attacker actively working into your system, one temptation is to totally turn that ingress off. However, if the attacker is sophisticated, then they know that they have been detected, and may well find yet another route into your systems that is harder for you to spot.
This can be proactively addressed by having an IR plan, and occasional table-top exercises too address select scenarios. Executive buy-in is critical.
- Take all compromised or infected systems offline immediately and have them carefully examined to determine what data those systems contained (customer, internal, and employee) and what was exposed to attackers.
- look for additional signs of compromise in other systems as well paying close attention to those connected with the ones that were compromised
- log and record everything extensively throughout the process
- consult with your lawyers to see what legal obligations you have to disclose the breach publicly
- notify everyone directly impacted by the breach as soon as you've identified them so they can start taking steps to protect themselves. Don't wait until you have all the details, you can update them as more information is discovered.
- Make sure you have professionals to perform the investigation and re-secure your impacted systems before they are put back online. This isn't the time to count on that one guy in the office who "knows computers real good" to fix it.
- continue to keep extensive logs and keep a close eye on everything for a time after the attack to make sure you're not compromised again.
If you can manage even that much you're doing better than most of the companies I've seen who were hacked. I've seen banks leave compromised systems connected to the network for months after being notified. I've seen some pretty large companies refuse to bring in outside help because they don't want the expense even after they get hacked over and over. Many small to midsize companies try to handle everything as quietly as possible and never tell anyone what happened.
Graham Cluley