FireEye Shares Details of Recent Cyber Attack
fireeye.com
fireeye.com
For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't being blocked - just the specific implementation. This is why we build our own tools: to demonstrate to defenders that while they are blocking a specific implementation they have not addressed the underlying vulnerability.
I do want to call out FireEye for doing an amazing job recovering from this situation. They did the responsible thing and released fingerprints [2] that could be used to detect every single one of their tools. They effectively burned their entire catalog and put them in to the class of "public" tools that are easily identified. I've browsed over the list of signatures and didn't see anything that popped out as giving a malicious attacker any advantage other than saving them work of building it themselves (of course I don't have access to look at the actual tools so YMMV).
Also, everyone gets hacked. No matter how good you are or how many cyber security engineers you have on staff... there is still Matthew in accounting that will open that invoice attachment so he can pay it.
1. https://github.com/gentilkiwi/mimikatz 2. https://github.com/fireeye/red_team_tool_countermeasures/tre...
Edit: To be clear I do work on an internal red team - we hack ourselves. I don't work for FireEye or a competitor.
Edit 2: Don't pick on Matthew. :)
This is painfully accurate. A chain is really only as strong as its weakest link :/
Even better is that the company should have its own internal ordering system.
This always becomes a war where the seller wants you to send orders 1 way, and the buyer wants to send all orders another way.
It would be really cool to have an invoice format that contains payment and tax information in a machine readable way and a way to send that information around with a verifiable channel.
pdf.js lacks capabilities to extract the XML or verify signatures, so the usual way will be to use Acrobat Reader or the usual bunch of "industry-standard" invoice-processing crap that now suddenly has to deal with malicious input.
The idea to do it differently might be nice in theory, but is lacking a smooth way to change over from the old paper-invoice ways. PDF will be the thing for some decades and we will have to deal with it.
This means that while you might be able to use something other than PDF for the human-readable part, I don't think anything other than PDF will be used. All the other stuff (XML with embedded SVG or PNG, Word, plaintext) will have acceptance problems in one form or the other.
EDI is big business to big business, as evidenced by you mentioning SAP. There, you may be completely right, I don't know.
With 30 years of daily experience in this field, I am ashamed about how we fail Matthew & my mother in the sense that they can still not just enjoy the internet and open random emails without one of us blaming them for how stupid they are.
I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday.
Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the internet (or other forms of connectability) comes into the picture. But the reality is that most such systems will probably soon be connected in some way, so the challenge grows.
So I think it is very important that we push for more information/education instead of going into the direction of more locked down, closed off and proprietary systems because these can easily "not respect" the end user.
I think we need to all realize that most people aren't cut out for computer science, per se, but most people are cut out to learn to responsibly use a computer.
As a matter of fact though, the same people do _not_ use computers responsibly. What do you do, then? Metaphorically jail them?
There are lots of areas where as humans, it's easy to reach a "sufficient" level, _and_ the dangers of an insufficiency are well known. Punishments or strict measures just don't work.
Everybody knows that they can be sufficiently and with little effort fit, but especially, that unsufficient fitness leads to sicknesses and earlier death. In this sense, which punishment can be worse? Yet, this doesn't work.
It’s like we’ve given every Tom, Dick and Harry a F1 supercar then we blame them when they crash the thing. The mistake is ours for not making better security models. Desktop apps should be sandboxed by default, and isolated like we isolate phone apps. For all the justifiable fear people have about apple’s control over what software can run on their machines, I think the app sandboxing and signing security model they’re working towards is the right one for 95% of computer users.
They don't understand the concept of files as separate from applications. They just don't. They understand the concept of sharing -- that seems to be intuitive enough -- but not of files as objects in themselves.
A system which works this way would, of course, be completely rage-inducing to myself.
Leaning to driving is not the correct analogy. Almost everyone can use a mouse or a touch screen to operate a computer.
I guess one benefit might be to push the development of new detection techniques to detect the underlying implementation of these tools.
If you are doing penetration testing and basic security work, there is no value in having private tools. It becomes important in red team work because you are trying to emulate a real attacker that has access to non-public tools.
If they didn’t have a binary that looked reasonably different to those that already exist, then it would instantly get triggered. It is worth noting that there are tools to obfuscate sourcecode/bins.
Matthew in accounting shouldn't have permission to run an untrusted binary.
And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet.
It could also be literally anything.
Executable files are blocked by pretty much all corporate e-mails systems. Zero-days for PDF viewers are rare. After all, most hacking attacks are things like ransomware campaigns, where everyone is a potential victim and phishing mails are sprayed all over the internet. A zero-day would be burnt pretty quickly.
However, many users legitimately need office macros and also need to open office documents to collaborate with contractors or customers. Many times, the phishing mail comes from a legitimate address because the other company has been compromised already.
The solution would be to only allow signed macros, but depending on the size of the organization, that can be costly.
^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Curious if this is feasible.
0: https://www.amazon.com/REDDOTMOBILE-Detachable-Magnetic-Ligh...
As often.
If the networks were air gapped, it wouldn't be Matthew's fault. Someone who had access to the engineering network would need to screw up. Which is of course perfectly possible—engineers make mistakes too. (Furthermore, if they were hacked by a nation state... for all we know it really could have been done without any user action at all.)
Even if you got all of the issues caused by e-mails figured out, somehow you have to transfer them from one network to another. You'll either have to poke holes into your firewall or use USB sticks.
My point is: even in airgapped networks you usually want to exchange some data. The moment you want to exchange data, you have a path where a virus can be smuggled in.
Either that or one of the Siemens engineers who showed up at the plant's laptop was infected in anticipation of them showing up there to fix stuff.
What other security features claim that performance?
- The CFO doesn't understand why we need separate server infrastructure (and the associated licensing and maintenance costs) for accounting and engineering.
- Software vendors can't answer the most basic questions about how their software communicates to allow network ops to build reasonable access control lists for network segmentation.
- The network gear doesn't have sufficient horsepower to do wire-speed stateful packet filtering because, apparently, that's still an exciting new idea in 2020, and we can't slow everybody's access down.
- Individual departments have end-run IT by using "cloud" offerings that effectively bridge different segments of the network together at layer 7.
- Everybody has to be able to open their email and click random links on any PC.
The problem with any defence based on filtering is that first you have to decide what to filter. In an enterprise-scale network, this is not an easy problem, despite the number of shiny and expensive tools available that are selling the hope that it is.
Individual departments have end-run IT by using "cloud" offerings that effectively bridge different segments of the network together at layer 7.
This might be the most challenging problem for modern IT security, perhaps along with BYOD. The software and equipment accessible by staff might no longer be fully controlled by the organisation. That changes the emphasis for IT security from "just" securing your own software and systems to also somehow securing your data against unauthorised transfer to other systems. And this is a hugely complicated problem with (at least) technical, legal and management dimensions.
Microsoft provided him a nifty protocol for that.
> Mimikatz first became a key hacker asset thanks to its ability to exploit an obscure Windows function called WDigest. That feature is designed to make it more convenient for corporate and government Windows users to prove their identity to different applications on their network or on the web; it holds their authentication credentials in memory and automatically reuses them, so they only have to enter their username and password once. While Windows keeps that copy of the user's password encrypted, it also keeps a copy of the secret key to decrypt it handy in memory, too. "It’s like storing a password-protected secret in an email with the password in the same email," Delpy says.
https://www.wired.com/story/how-mimikatz-became-go-to-hacker...
A technique we used at Blekko (and hopefully you guys do as well) was logging/tracing statistical traffic flows for normal cluster operations such that we could alert on atypical traffic (which in our case meant something was likely kinda broken but limping along and needed to be fixed/replaced.). We also didn't have to deal with APTs before we were acquired so the stakes were way lower.
Agreed that getting hacked is inevitable if the prize is worth it, always interested in adding new ways to instrument the world to detect sniffing or attacks.
Am I missing something?
The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach with any high degree of certainty.
The second is that bad actors (of wildly varying skill) are very active on the Internet. The threat of hackers used to be curious teenagers trying to learn more about computer systems; it didn't take long for that to devolve into criminal activity and "hacktivism." Now, the intelligence services of major nations regularly attack public and private organizations across the Internet.
It's the job of contemporary security teams to defend against any and all threats -- but many (if not all) private organizations are ill equipped to defend against a well-organized intelligence agency in an attack such as this.
I didn't see any what the attack vector used against FireEye might have been, but those same attackers are now very well "armed" with FireEye's red team arsenal. It's going to be an interesting future for security teams as we learn what and whom these adversaries will attack next.
Are systems more secure now than they were in the past? Maybe. A targeted attack against an arbitrary target would generally take a few 10 to 100s of thousands of dollars. This is probably orders of magnitude more than the past of teenagers hacking for giggles. But, there are like 6-8 orders of magnitude between teenagers hacking for giggles and a "nation-state actor" and about 3 orders of magnitude between a random company/organization and a nation-state. The best systems deployed systems are about as close to adequate as a house is to a skyscraper.
While this is true for e.g., Equifax (see https://ciexinc.com/blog/quick-assessment-of-a-companys-secu...), if FireEye (aka Mandiant) says it, I tend to believe it to be quite true.
I would expect that hacking them would be far from easy.
Second, that is kind of a non-sequitur. I did not say that a nation-state did not pull off the attack, my gripe is that they are implying, like every other company that gets breached, that only a nation-state has the resources to pull off such an attack with their wording. These attacks are extremely cheap and easy, that is why we see governments running literally hundreds to thousands of such attacks/programs in parallel as evidenced by the CIA Vault 7 leaks. A single branch of the US government was literally developing hundreds of independent tools/programs that could successfully compromise anything they cared to target.
Third, define "easy". I define easy as ~$1,000,000-$10,000,000 since almost any moderately-sized corporation, of which there are millions, could fund such an operation. To put it in perspective, $10,000,000 is only ~1% of FireEye's revenue. I define "only a nation-state" at 1,000x more at ~$1,000,000,000-~$10,000,000,000 since although it is still technically doable for a large multinational or organized crime, it is unlikely to be profitable outside of theoretical large-scale extortion attacks.
Do you think a penetration test of 3 engineers working fulltime for a year would fail to materially breach FireEye's corporate systems? Almost every penetration test by a competent company takes a fraction of that effort even against well-funded security teams. And 3 engineers for one year is only 3 engineer-years which at $300k/engineer-year is ~$1,000,000, the bottom end of "easy" and 1,000x less than "only nation-states can pull it off". If engineer-years is too abstract, the Google ProjectZero case I mentioned earlier was a zero-click iOS RCE from zero starting understanding in 0.5 engineer-years. So, doing some sloppy extrapolation, is it easier to find 6 zero-click iOS RCEs or breach FireEye's corporate systems?
Let's say we moved up an order of magnitude to 1% of FireEye's revenue at $10,000,000 which is the high end of "easy" and is 2 orders of magnitude less than the bottom end of "only nation-states can pull it off". That would be enough to fund 30 engineers working fulltime for a year or 10 engineers working fulltime for 3 years. Do you think FireEye could prevent a material breach? I have literally never heard of a single person in enterprise security who has ever dared to make such a remark on the record that was not instantly taken down for a fraction of that. I know of no competent engineers in that space who would support making such a statement to anybody who could and would test it. Just think if FireEye announced a $10,000,000 prize at DefCon to breach their systems by the end of the year, do you think they would even last the month?
[1] http://www.cnmeonline.com/myresources/fireeye/fireeye-cso-le...
[2] https://web.archive.org/web/20120610031926/https://www.firee...
I feel that with respect to FireEye, that it isn't just an implication; more that they would claim this with strong evidence. They are about attribution.
I think this argument is making some false equivalence. Just because every other company that was breached (e.g. Equifax) claims "Wow State Actor Sophisticate Beyond Anything Before Seen By Man" for something as simple as failure to update your software leaves a yawning hole has tarnished the dialog for those who know what they are doing.
While CSO at Relativity, and now for my clients, I strongly suggest that you don't use the phrase "Security is Very Important to us" since that is the first thing out of the mouth of companies who didn't until they got hacked.
>Do you think a penetration test of 3 engineers working fulltime for a year would fail to materially breach FireEye's corporate systems?
Bluntly, yes. I expect that their defenses are much better than most companies, including security companies.
>I have literally never heard of a single person in enterprise security who has ever dared to make such a remark on the record
Enterprise security is in a different category altogether. Few non-security enterprises will withstand much of an attack. FireEye is in a different category altogether.
If you are interested in the topic, a useful book to read is https://www.amazon.com/Incident-Response-Computer-Forensics-.... I think this is more informative than these BOEC cost calculations.
It is hardly a false equivalence. If everybody constantly fails with little to no evidence of any success by anyone ever despite continuous assurances of success by everyone, there is exactly zero evidence that a layperson should trust any statement on that topic without good, solid, objective evidence to the contrary. Given the track record in the industry, there is no reason to give the benefit of the doubt to any company. The burden of proof is on them to demonstrate their claims in a relatively objective, quantitative manner. If they have no means of proving a quantitative claim in a relatively objective manner, there is no reason to believe their claims given their track record. To provide an analogy, if somebody you trust to not be malicious asks you to follow them, but they can not justify why, then the smart thing to do is judge them based on their track record as that provides some part of an objective statistical basis for evaluating their prevailing success rate.
If you really must have evidence of a trend of insecurity amongst security companies. Then we can look no further than McAfee, Symantec, and Trend Micro all being breached between 2017-2019 that was attributed to "fxmsp" [1][2], a private Russian hacking group that was selling the contents of the breaches for a few $100k which demonstrates how easy it must have been for it to be profitable at that price point (to be fair they could sell it multiple times, but I doubt they sold it hundreds of times). So, what justification do you have for why FireEye's security should be any different than other companies or even other security companies?
Also, you only provided an answer to the low end of "easy" rather than the high end at 30 engineers for a year or 10 engineers for 3 years which would be needed to pull them out of the "easy" category by my standards. If you do claim they can survive that, can you provide either some reasonably quantitative evidence or public statements to that effect or the same for literally any other company in the world you think can do so as I have not once ever heard of a single company ever justifying such a claim in any verifiable manner. Thank you.
[1] https://gdpr.report/news/2019/05/15/mcafeesymantec-trend-mic...
[2] https://www.zdnet.com/article/fxmsp-hacker-indicted-by-feds-...
As is the GitHub repo with their red team tool countermeasures, which they admirably released immediately: https://github.com/fireeye/red_team_tool_countermeasures/
It's way over-the-top.
Attribution is hard to impossible. What passes for attribution these days is laughable.
Short of a full written confession, is there any way whatsoever to gain an understanding of who perpetrated an attack? Or are you saying it’s impossible to even begin to build evidence?
There is of course a way of doing so, as long as the attacker made a mistake. If they didn't, then it very well might be completely impossible to know who did it, and that's just how it is.
Just to remind you where we started, as a contrast to the new goalposts you've established.
So, what do we all think would be a level of resources that only a state could support? I think we can just start somewhere pretty low like $1,000,000,000. Fortune 500 companies and many criminal organizations could reasonably afford that, but the total number of organizations is still pretty limited, so it is probably a good lower bound. I do not think we can go much lower because if we drop down to $100,000,000 then even FireEye, which is not a Fortune 500 company, could theoretically fund such a venture with its revenue of $890,000,000.
Okay, so starting with "only a state" resource level of $1,000,000,000, we should probably divide it by 10 to make it highly unlikely people will do it just to prove they can even if it is unprofitable to get the prize. That leaves us with a simple open prize of $100,000,000 for the first person to demonstrate that they can breach their systems. If nobody claims the prize, then it is highly likely that this attack would take a state-level actor. If somebody does claim the prize, then it is probably doable by somebody who is not a state-level actor. This would provide an unbiased answer about the truth of their implications. If they think such a prize is too high, then they can just set it to a lower X that will give us an unbiased answer to the question: "Does it take more than X resources to breach their systems?"
Personally, I think if they actually announced a $100,000,000 prize they would be breached within a week on the outside. At $100,000,000 people can burn dozens to hundreds of zero-days to be the first to get the payout and still come out ahead. Even at $10,000,000 I doubt they would last more than 1 month. At $10,000,000 the prize would be the most attractive bounty in the entire industry by a factor of 3-10x and people could still burn some zero-days and still come out ahead.
No it wouldn't, because--
> the risk of getting unlucky
-- oh, you do understand. Why are you proposing this again?
I believe not a single cyber offensive op performed by a nation state had a budget of $1B. I'd say $1M is an upper bound here. Cyber warfare is used because it's cheap.
I doubt Stuxnet cost only $1M.
Licensing costs for law enforcement "remote access tools" (state trojans) can be millions (distributed among dozens of uses, but IMHO easy to see spending as much on a high-value single use).
From the wiki article about the iPhone-encryption debate: "On April 7, 2016, FBI Director James Comey said that the tool used can only unlock an iPhone 5C like that used by the San Bernardino shooter, as well as older iPhone models lacking the Touch ID sensor. Comey also confirmed that the tool was purchased from a third party but would not reveal the source,[59] later indicating the tool cost more than $1.3 million and that they did not purchase the rights to technical details about how the tool functions"
In this case they went after the tools to avoid detection and/or attribution in future ops. They could instead contract a company like their victim to develop such tools from scratch for about $10M.
Also, we're talking about nation states other than US.
This was precisely my read of it as well. Exaggerated usage of superlatives coupled with no actual explanation suggests trumping up an adversary's capabilities to excuse one's own security lapses. Like claiming a highly sophisticated burglar broke into your home, while neglecting to mention you left a window open.
If this was the primary objective of the attackers, why is it buried in the seventh paragraph of FireEye's blogpost, after a lengthy discussion of the attackers targeting -- though apparently not primarily targeting -- FireEye's internal tooling?
I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. One slip up, one old server version, is all it takes. I've seen it.
In this case, it's a security company, so I'm sure the irony seems a bit thick. But it's helpful to recall that security companies are companies. And no one is immune to security threats.
hardware airgap can go a long way
One of the most common is interdiction of computers in shipping and installation of hardware implants.
A great book on Russian, state-backed hacking group was by a senior Wired writer, Andy Greenberg, called "Sandworm" [0]
[0] https://www.amazon.com/Sandworm-Cyberwar-Kremlins-Dangerous-...
https://github.com/fireeye/red_team_tool_countermeasures/blo...
It'll be interesting to see if these get any hits from scanners in the next couple weeks...
They’ve also released signatures to detect the use of the compromised tools: https://github.com/fireeye/red_team_tool_countermeasures
None. Both the CIA and NSA have been hacked too. The only entity that should hold private keys should be the person or organization using those keys.
See for example: https://www.washingtonpost.com/national-security/pompeo-says... https://foreignpolicy.com/2020/01/24/crowdstrike-trump-impea...
Russian government doesn’t do any hacking, it’s all a fabrication by the Democrats :)
And there is, of course, very strong incentive to make such claims.
I'd imagine my experience isn't unique, and that many people came to the same conclusion.
I'd say that your conclusion isn't warranted.
There have been comments stating with high detail why exactly it's probably not a nation state actor, but ultimately it's a case of the burden of proof being on the party that makes the claim, and generally those parties just can't substantiate it.
This is where it does not pay to be a public company. If they weren't a public company they wouldn't have to disclose this or acknowledge it and there most likely would not be a credibility damaging story which is easy to find. Sure the story could have gotten out but it would not be easy findable and would not be broadcast widely. An event like this makes major papers and nightly news.
Read that again. There is nothing that says you need to air your dirty laundry. That's not a business or legal principal (other than whatever the public company requirements might be and I am not even 100% certain this was needed but I don't know).
Also as others have pointed out indicating that it was a state sponsored actor is to me (for lack of an elegant way to put it) is 'chicken shit'. Why say that? Why not just say you were attacked and going to try and determine why and make any changes. All it does it sound like an excuse and further to say 'well others are not attacked like this and we can protect against them fine' doesn't fly.
Because they would be out of business tomorrow if they say they think it was a 13 year old from Ohio just fooling around on a Sunday.
This is FireEye marketing itself for the F500 by selling fear of an invisible adversary with unlimited resources that already deliver innovative black hat capabilities.
How could you read my comment and think that is what I thought they should say?? I said not to say anything. And why use hyperbole ie 'they would be out of business tomorrow'.
And no it's not marketing anymore than if a Karate expert airs that he was beat up in an alley and then says 'but the person was 9 feet tall that's why!'. (But sure to your point if they said 'by a 13 year old' that would not be better but once again I didn't say that.)
This is the scary part. FireEye and the others have been studying and watching APTXX nation-state teams for many years. They should have some idea by now. It is entirely possible that a new team is out there.
If it's something novel indeed, the entire industry would like to know please.
Seems like a massive amount of energy to devote to stealing tools, that by and large, probably have public equivalents sitting around on GitHub.
Besides that, I care little about "attribution specialists" and what they say (sorry if anybody is in the audience :p). Evidence can be faked, it's all bits and bytes in the end (and some server locations, usually rented boxes) and things have been misattributed constantly in the past and will be in the future. I think the most you can infer is the general sophistication of the attackers and their resources, but that doesn't require an "attribution specialist". Attributing it to some specific nation state is guess work at best based on mistakes they made in their camouflage (if those mistakes aren't a deliberate or accidental red herring; e.g. [1]). And such "It was China/Russia/North Korea/underpants gnomes" claims are made by people claiming to be "attribution specialists" all the time. It's extremely rare that there is compelling evidence to supporting such attributions.
So if FireEye provided evidence or at least a reasonably detailed post mortem backing their claim of a sophisticated attack, then I'd probably believe them on that. If they made claims about a particular nation state (and so far they did not, as far as I can tell) then I would find that a dubious claim to make.
[1] https://theintercept.com/2017/03/08/wikileaks-files-show-the...
You're probably never going to get evidence that will satisfy a message board.
The Wikileaks post you cited repeats the fallacy I mentioned earlier --- the idea that analysts are simply attributing exploit code. I think if you stop and think about it, you can probably rattle off a number of things besides exploits that a single attacker group will share in common across its attacks.
To fake the evidence we're discussing, you have to know what it looks like. A bored teenager doesn't.
I think it's unlikely that you can derive the entire practice of attribution axiomatically from your own intuitions about how attacks work, unless you've had some real exposure to IR and forensics as a practitioner.
Code can be faked, meta data can be faked, MO can be imitated, and so on. And the nation states at the very least - and their contractors and (former) employees in the areas of concern - will know what it has to look like. Motive isn't always clear, and quite often there are multiple parties with motives.
>unless you've had some real exposure to IR and forensics as a practitioner.
I'll bite on your argumentum ad verecundiam... who says I didn't? ;)
But I agree, we'll likely never see evidence or a post mortem, and are expected to believe what FireEye and/or the FBI tells us.
That may be a rather untrusting/paranoid mindset that I employ, but it worked for me so far.
And consequences? In this case, probably none. We're here for news and entertainment, and reasoning about topics such as this one is enjoyable to me. But lively discussions and their takeaways can inform future arguments and decisions.
But in more general terms, I am a member of the electorate in my country, and misattributions and/or bad or even fake evidence quite often have direct influence on policy. E.g. I was quite happy that I, along with a majority of my fellow citizens, did not believe the "conclusive" "evidence" of WMDs in Iraq the US had put forth, and stayed out of that war.
"Worked for me so far" can turn out to be inadequate if you discover that your stuff has been leaking to the bad guys for a year.
It will be interesting to see how this plays out, and if true, this may be the first of many compromises to be revealed.
[1] https://twitter.com/Bing_Chris/status/1336431664478687239
I hope to see these tools on Github soon.
Or at least get an idea of what tools your target company was red teamed with.
Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.
No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that it's tapping into their phone line using SS7. Probably the hardest way is to first hack a security agency, which I'd imagine have some of the better intrusion detection out there.
Not fun.
I'm interested to know what you're proposing, but I suspect you simply misunderstood what I meant, and perhaps what your (and everyone else's) file at the TLAs looks like. It's a mighty plump target, and not comparably secure.
>>> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies
> You can get a database of everyone's metadata communications by sending them a phishing message? Certainly, I don't keep even all my information on my computer, or even a single phone, and I think phishing _everyone_ is harder than you're making out.
You're moving the goalposts: before your ninja edit, you were only talking about the easiest way to spy on someone, not everyone.
If you phish someone, you can get the content. Why settle for just metadata? And what good is metadata for your blackmail use-case? The difference between metadata and content is the difference between knowing you communicate with your coworker and knowing you're cheating on your wife with her. Only one of those things is useful to a blackmailer.
Also, what exactly is a foreign power's use case for targeting everyone in the US, or being really interested mainly in metadata, when their goals mean they're mainly really interested in specific people and organizations and the content or systems they have access to?
https://www.washingtonpost.com/national-security/russian-gov...
https://www.reuters.com/article/us-fireeye-cyber/u-s-cyberse...
https://www.nytimes.com/2020/12/08/technology/fireeye-hacked...
(via https://news.ycombinator.com/item?id=25354426 and https://news.ycombinator.com/item?id=25351349, but we've merged the comments hither)
did their best to bury the lede. they say they were targeted multiple times, but dont say they were breached until the fourth paragraph, something like 40% of the way through - even then the admission is intentionally mentioned vice announced. i understand fireeye is a security company, but pussyfooting is pussyfooting and weasel words are weasel words.
idk, politics is part of the game at the highest level. maybe im not destined for the c-suite.
There can be times when the "factually accurate" narrative conflicts with the correct one, there's a reason why most corporations have dedicated resources for engaging with the public.
What one normally consider to be "weasel words" are often carefully chosen to polish the truth while alleviating harm to key stakeholders.
While not necessarily the case here, every big tech company puts blame on an APT aka a nation state actor.
In fact, the very same FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds. By those same measures one could have implicated East Palo Alto High School.
You never regain your credibility for attribution and provenance once you have committed such a public blunder.
https://en.wikipedia.org/wiki/Sony_Pictures_hack#Doubts_abou...
It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath.
https://www.realclearinvestigations.com/articles/2020/05/13/...
Is sworn testimony the only way we will get them to tell the truth?
There exists very little doubt that NK was behind the Sony hack, there's even a federal indictment.
>It is the same as Crowdstrike going back on their wild claims while their CEO testified under oath.
This is a complete fabrication by you, utterly unsupported by the link you shared which only contains meaningless bickering regarding forensic traces of data exfiltration.
https://intelligence.house.gov/uploadedfiles/sh21.pdf
You can peruse the whole pdf or jump straight to the money quote on page 32.
As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking Sony. In fact, there was a smoking gun to a disgruntled ex employee. On a side note Sony and Sony entities were publicly hacked over 18 times prior to this as “revenge” for the PS lawsuit against the hacker who exposed encryption keys of the Playstation.
https://www.wired.com/2014/12/evidence-of-north-korea-hack-i...
https://en.wikipedia.org/wiki/Sony_Pictures_hack#Doubts_abou...
https://www.wired.com/2014/12/evidence-of-north-korea-hack-i...
It feels like you're being deliberately dishonest. Your "money quote" is about whether there were was concrete evidence of the hackers exfiltrating data from the DNC, not about "Russian hacking of the DNC" .
What Shawn Henry is saying there is that they have evidence of the hackers preparing data for exfiltration, but no concrete evidence of the data being transferred out. Unless the malware used by the hackers stores detailed logs, this is to be expected. It would be unreasonable to doubt that the exfiltration happened on this basis.
>In fact, there was a smoking gun to a disgruntled ex employee
There wasn't. None of your links substantiate this claim.
The wikipedia section consists of uninformed clowns like Sabu and hilarious quotes like "State-sponsored attackers don't create cool names for themselves like 'Guardians of Peace' and promote their activity to the public.". There's no genuine attempt at convincing criticism of the NK attribution to be found here.
>As for federal indictment on North Korea, that means nothing on the merits or dubiousness of the North Koreans hacking Sony
The federal government has a pretty good track record of getting these things right. The DOJ certainly believes that NK did the Sony hack.
> ... FireEye attributed the Sony Pictures hack to North Korea on extremely flimsy grounds.
What grounds are flimsy that they used? Do you have details about what FireEye actually saw?
> Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities.
I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?
I would confidently say that the top 50 countries by GDP have a solid offensive capability. Some, like Japan, have very specific interests that don't align with what makes the news.
At some point you start getting in to the territory of Hacking Team, NSO Group, Gamma, VASTech, etc. Effectively combining the resources of many smaller governments in to a for-hire enterprise that can provide near-nation-state capabilities.
Here is a list of well known attributions of groups to get you started: https://docs.google.com/spreadsheets/u/1/d/1H9_xaxQHpWaa4O_S...
Not saying it didn't happen, but it looks like it has become the goto defense in recent times.
so usa, russia, china, poland, ukraine, japan.
https://arstechnica.com/information-technology/2020/12/secur...
https://nakedsecurity.sophos.com/2019/09/13/fin7-sysadmin-pl...
It probably depends whether (and how) they confirm it was a nation state, though.
> In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts.
What does it mean to "create an internet protocol address," in this context? Did they use VPNs? VMs on cloud services? Residential proxies, luminati-style? Something else?
More: https://www.ripe.net/participate/policies/proposals/2019-08, https://www.manrs.org/2020/12/whats-the-as0-roa-policy-and-w..., https://blog.cloudflare.com/rpki-details/
The 'many inside the US' is kind of laughable. I mean what would you do to pull this off use IP addresses in China or Russia just to draw attention?
I mean if you want to pull off a burglary in a residential neighborhood you don't drive in with an auto that draws attention you go with an auto that looks like many others that have been seen before and isn't noticed.
You can build a case on the flimsiest of IOCs, and anyone who questions you gets smeared as a foreign agent or cutout, without a shred of evidence. Really, quite neat.
And somehow, these companies immediately "know" that it was a nation-state actor. Same case here. There are only claims, but no facts, no evidence.
And lately, it's always "the russians" :) I'm just noticing the pattern.
Lastly, what I really can't understand is - how in the world these "highly sophisticated attackers" are so bad at covering their tracks. :)
Edit: For the downvoter, this isn't spam. It's an insight from a former CTI analyst.
EDIT: Nevermind they added something to the countermeasures repo that goes against that.
So there certainly could be zero-day exploits for vulnerabilities that are known but not yet fixable, perhaps because the vulnerability did not seem easily exploitable and thus not urgent to the vendor.
Later in same article...
>Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies.
??? Which is it?