It also seems incredibly risky. This US admin might be okay with it, but will the next? For multi-national corporations, will other nations be okay with it? I wouldn't think countries unassociated with the conflict would be happy with digital privateering.
imagine hacking back and accidentally hitting a hospital killing someone in the process
that is a fast line to get an Interpol terrorist arrest request on your head, sure the US won't hand you over, but have fun to never leave the US and get assets abroad sized
not about highly specialized groups hacking first
but also "professional hackers" have screwed over hospitals before and confirmed it was accidental, so potentially yes
worse Iranian terrorist with hacking skills might intentional target hospitals and they might not sit in Iran so disconnecting Iran is unlikely to help at all with such a threat
Then you end up with collateral damage if your wife or roommate or whatever works at a hospital and they take their infected device to work.
worse hacker do like using jump hosts
so wherever you "hack back" to has a good chance to be another victim
it's also a good point to remind people that most cases of "knowing who was it but not catching the people behind it" are either wild guesses without proof or the attacker leaving recognizable traces (like a literally "it has been us <group>" note /not a joke). But the problem with that is any other advanced enough hacker group/apt could also have made it look like that...
That fact that they have money to hire someone to do it?
Now one might ask why didn't they use that money to defend themselves to start with.
Having worked in the space, the normal flow would look something like:
1. Random WordPress blog is hacked, hosts a fake iCloud page, the is linked to in phishing emails. 2. We find it, either by direct reporting or by our internet crawling 3. We reach out to the hacked company, their hosting provider, and their DNS. The goal being take this site offline no matter how.
This worked for the vast majority of hacks. Some random plumbing company has no clue their marketing site is compromised and happily works with us. Or maybe they host at GoDaddy and we have a privileged relationship with them and they disabled the site. Last resort the DNS company will just delete their records.
Sometimes, though, we get a compromised site on a host in a foreign land that won’t cooperate. Then what? Well, it’s a legal grey area that our in-house counsel felt was perfectly fine: hack the site and take it down the hard way. We didn’t advertise or document when we did this. It was an open-secret inside the company however.
All this does is legitimize the sadly necessary work we face in a modern world.
1.https://videocardz.com/newz/nvidia-allegedly-hacked-the-rans...
The real question is if they can even properly attribute to the correct target. Nobody hacks from their home IP. Anyone remember Uplink? You'd make it way easier to avoid getting arrested (which wipes your save) if you proxied through the tutorial machine first and wiped its logs after you were done. Likewise, even the most basic cybercriminals know to hack with machines they've already compromised, so that all the owners of those machines and their ISP's abuse desks spend all their time pointing the finger at each other.
Not required. This is unlikely to be random SecOps and SecEng corporate employees as the legal risk is too high as government administrations are replaced every few years.
Just like real piracy at sea companies would hire mercenaries or nowadays referred to as private military contractors. The fight back would just be to initially identify them (attribution) then activate PMC's at or near their location and neutralize the root cause.
With time countries will tire of random PMC's showing up and will take a stronger approach to dealing with their own hackers in addition to making the internet less anonymous. The effort to make the internet less anonymous has clearly already started as HN have been witnessing. Efforts like bcp38, 84 [1] authenticated packets likely using a nonce after government ID based auth and many other methods will be implemented as previous efforts have stalled.
Sony's movie division financed a movie North Korea disapproved of, and DPRK retaliated[1] by hacking Sony Pictures and released executive salaries, emails, private employee information, unreleased movies, scripts, and set loose wiper malware on Sony Pictures' internal network. Sony was also forced to cancelled the theatrical release because there were threats of terrorist attacks at theaters that showed the film.
"Hacking back" is not a great strategy for most companies, except those that were already juicy targets and are battle-tested against state actors. But what do I know, I'm no fancy CSO.
Companies have a very visible what, where, who in most cases.
Hacker don't, and take extra steps to obscure it (e.g. jump hosts, bot nets etc.).
Now if it's idk. a spear phishing campaign or similar "hacking back" by giving them trapped data or reverse social engineering attacks might work.
But if it's a technical security vulnerability some one found by scanning and sneaked into using multi-country jump hosts and cleaned up behind them. Then you have little chances to find them and to do so likely requires getting information from telcoms which require judge orders to be handed over, and from multiple countries, too.
Announce a change that is believable and all the corporate software will change to match the utility that is no longer a liability.
and also is related to common war crimes iff in a conflict combatants frequently hide as civilians (as a defense by offense will sooner or later lead to attacking random civilians due to mistaking them for hidden combatants)
so I would take that saying with a bit of salt
Also, why burn the resources? Attacking isn’t free.
It's like saying "the police doesn't care any more citizen, so you know just punch back". It's also incredibly dangerous btw to tell private firms they have the authority to engage in what is basically an act of warfare.
There's also a quote from Prez in The Wire, "Nobody wins. One team just loses more slowly"
If the goal is simply breaking shit (versus e.g. exfiltrating data) offense is way easier than defense. Also, security is an ongoing expense. Retaliation is one time.
Disagree. Retaliating draws a larger target on you. Increasing need for ongoing security. And increasing need to retaliate. You’re retaliating against multiple fronts and vectors. It’s all very expensive and an arms race.
Does it? I feel like I could pretty easily pay a mercenary group to fuck around with Iran without being particularly concerned about blowback. (My main risk would be getting scammed.)
They could do all this now, but they generally don’t. Poke the bear and it might bite.
We used to receive routine threats from the IRGC on top of the usual DDoS attacks on our systems. Turns out cybercriminals don’t like it when you disrupt their cash flow. Thankfully we never got SWAT’d or had a box of heroin shipped to our office like that one journalist.
But yes, I think it’s understood that you’re on your own on this front and the government isn’t going to come to your rescue or protect you, which I feel like isn’t really a change from status quo but just being more direct in admitting it
Making criminals' lives more complicated is a good strategy. Corporate vigilantism, I don't know.