A Closer Look at the Lapsus$ Data Extortion Group
krebsonsecurity.com
krebsonsecurity.com
Okta’s Investigation of the January 2022 Compromise - https://news.ycombinator.com/item?id=30775180 - March 2022 (112 comments)
New Updated Okta Statement on Lapsus$ - https://news.ycombinator.com/item?id=30774193 - March 2022 (24 comments)
Updated Okta Statement on Lapsus$ - https://news.ycombinator.com/item?id=30769537 - March 2022 (220 comments)
Also:
DEV-0537 (LAPSUS$) Criminal actor targeting organizations - https://news.ycombinator.com/item?id=30774406 - March 2022 (0 comments)
Lapsus$ hackers leak 37GB of Microsoft's alleged source code - https://news.ycombinator.com/item?id=30763623 - March 2022 (117 comments)
> The woman said she was unaware of the allegations against her son or the leaked materials. She said she was disturbed that videos and pictures of her home and the teen’s father’s home were included. The mother said the teenager lives at that address and had been harassed by others, but many of the other leaked details couldn’t be confirmed.
> She declined to discuss her son in any way or make him available for an interview, and said the issue was a matter for law enforcement and that she was contacting the police.
https://www.bloomberg.com/news/articles/2022-03-23/teen-susp...
Thats when you know you are in the zone! I love the zone.
It's scary to think what someone with actual knowledge of common practice could do with the same kind of approaches.
Tell’s quite a bit about the snake oil that is the current cybersecurity industry and its counterparts sloppy software development and lazy pointy haired boss.
- "cybersecurity industry"
- "sloppy software development"
- "lazy pointy haired boss"
Combine the three, and you end up with breaches like these, although I agree that "sloppy software development" is probably the least likely source of these issues. Thinking that security is just checklists that have to be checked (thinking done by party #1 and party #3) probably carries most of the blame here.
They should have used login mechanism that didn't failed so spectacularly as passwords. Anything that forces server to prove its identity to client, should be a good start.
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-...
Ah, MFA because bolting more passwords(things user knows and by knowing is able to prove his identity) on top of first one is a great idea. I'm sure no bad actor will try to get this information too.
MFA might or might not authenticate server. And relaying on user action for security is asking for problems. Does user is a security expert to be able to choose appropriate action? Because sometimes even security experts get phished.
I'm thinking about something simple, that have minimal user interactivity. Something like WireGuard, but not with random keys in plain text. There are ways to prove identity/exchange keys without directly using private keys.
Something like tpm/yubikey.
It is about building a level of trust and psychological safety between software developers and their managers. This way, blameless postmortems can be done in the event of an incident without finger-pointing.
Many companies concentrate all the security efforts at the perimeter.
One day I was on IRC talking to him while at home in the evening. He said "Watch this." My wife's cellphone rang and someone screamed down the phone at her. That was the breaking point for me. I put it a €15,000 bounty out there for someone to ID him. A few weeks later I had leads and tracked him down to Germany.
I had German friends dig into it. They found he was a 15-year-old kid working at a video store. My friends called his boss first and gave him the details. Then they called his dear old mother at home and regaled her with the stories of her son's other life.
Never had any trouble from him again after that.
> “[He] slowly began making money to further expand his exploit collection,” reads his Doxbin entry. “After a few years his net worth accumulated to well over 300BTC (close to $14 mil).”
> KrebsOnSecurity is not publishing WhiteDoxbin’s alleged real name because he is a minor (currently aged 17)
> “After a few years his over 300BTC [appreciated] to $14 mil.”
5 years ago, BTC popped up to around $20k, and then fell down to near $3k. It took until December of 2020 to get back up to 20k.
If they were on Tor, they would have known about BTC, and if they were interested in black-hatting, BTC would have probably been the most accessible financial instrument for them to use in that pursuit. I'm 99% sure someone like that would have had a stash kicking around somewhere.
Think anyone paid the group for work? That'd be a good way to fill the coffers.
Considering that Okta say they already do "Zero Trust security" and giving people least possible authorization (and also that they were never breached in the first place, still), I don't have a lot of fate in the industry realizing anything from this breach.
I also think that things aren't as bad as we think security wise. The attacker's lack of industry experience helps with marketing to media who also lack industry experience. Somehow "Lapsus$" are "the world's most dangerous hacking syndicate", but in reality they've fully compromised several Portuguese companies with poor information security to begin with, released a treasure trove of mostly only curiosity-interesting source code from some big names, and posted some screenshots of restricted-access customer support tools. Breathless excitement about each new discovery has whipped the media into a frenzy over disclosures which sound juicy but ultimately aren't altogether that impactful - another accidental benefit of youth, I think.
To me the scariest thing in "cyberspace security terms" probably isn't that a minor has done all this - that seems reasonable to me - but what happens when an adult is inspired to adopt the same approaches? IMO this is the leading edge of something, an innovative approach pioneered by an outsider, less so than it is the trailing edge of "even a teenager could do this."
I think the biggest insight here is the power of chat tools like Slack. These tools need much more robust controls than are currently present at most companies. At most large enterprise software companies I've seen, there is little-to-no role based or level based access control applied to chat, and a vast amount of information is accidentally available in messaging logs, even to employees like contractors or low-trust employee accounts which have been locked out and just "need to Slack someone to get back in." Chat apps need much more access control from both a role and trust level point of view.
Reminds me of: https://en.wikipedia.org/wiki/Ender's_Game
Hoping to earn himself expulsion from the school for his ruthlessness, he sacrifices his entire fleet to fire a Molecular Disruption Device at the planet. The Device completely destroys the planet and the surrounding bugger fleet. He is shocked to hear the I.F. commanders cheering in celebration. Mazer informs Ender that the "simulations" he has been fighting were real battles, directing human spacecraft against Formic fleets via an ansible's instantaneous communication, and that Ender has won the war.
The threat of wilful cooperation by sympathetic employees with loyal ties to their homeland has also been a widely covered in several Chinese cases, less so by Russia. This isn’t isolated to those countries either - it’s almost certainly being done by the west too.
More like, imagine what a state-level actor has done already. Heck they don't even need to carry out hacks of this nature. It would be trivial for a government to embed an agent at any tech company at a way higher level than customer support. Do people really think a top CS graduate recruited to a coveted intelligence role can't pass a FAANG interview?
Think of our top political enemies and consider which direction the Visas go.
Unfortunately, for these countries, H1Bs are very easy to locate.
There are no top CS grads working for any government, other than perhaps academy graduates, and then only temporarily. For a top CS grad, private sector salaries are 5-20x what government will pay, and if they are top CS grads, they'll be smart enough to do the math.
Are they victims or co-conspirators? These people were paid to provide access.
https://camas.github.io/reddit-search/#{%22author%22:%22okla...
And that target is what made me first think of one or more government agents infiltrating and financing the group.
>"... prior to launching LAPSUS$, WhiteDoxbin was a founding member of a cybercriminal group... specialized in SIM swapping targets of interest and participating in “swatting” attacks, wherein fake bomb threats, hostage situations and other violent scenarios are phoned in to police as part of a scheme to trick them into visiting potentially deadly force on a target’s address."
I don't have the answer, but grinding subsections of society into the dust is not the answer.
So he’s paying some individuals to commit crimes doesn’t make him a horrible person by default, in my opinion, the law is just there to protect the wealthy, is not something that defines what is just, correct or fair. There is nothing intrinsically noble in respecting the law and there is nothing intrinsically horrible in not respecting it
Company screws up, the only option available is "contact customer service." And actually getting in touch with customer service is made as difficult as possible by design.
If you do have the patience and persist, it turns out the customer service agent doesn't have the power to do anything either. In a lot of cases (as it was for the Okta incident) they don't even work for the company in question!
However...
> The "customer service" role itself is an invention for companies to absolve themselves of core responsibilities.
This seems like a pretty extreme take. Are you saying that customer service shouldn't exist?
I could easily reframe this to say "Companies employ customer service departments to fulfill their responsibilities which they otherwise could not scale without a department dedicated to it".
Even if software is perfect and has no bugs, most software that has a customer service department behind it is also sufficiently complex that at some point, support is going to need to get involved. This is especially true in the enterprise software space where Okta plays.
What is the alternative?
> the fact that companies employ ... a team of people who it treats as second class citizens and does not give the necessary tools to fulfill these responsibilities
Again, I acknowledge that there are orgs that do exactly what you describe, and sure, call out the bad where it exists, but it's also not fair to generalize this to "companies".
I wouldn't say that they are badly paid compared to local wages.
One of the FAANG's outsourced customer support accounts here start at $11,000 yearly.
It may not seem that much compared to U.S. wages, but that would easily place you in the highest 10% wages here.
* $11K/year would place you in the top 16% wages
* $14K/year would place you in the top 10% wages.
This stats don't include commissions (like the ones sales teams get), people who are self employed, informal sector or business owners that don't receive a wage.