Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
?
This poll is closed.
Yes 44 35.20%
No 81 64.80%
Total: 125 votes
[Edit Poll (moderators only)]

 
  • Post
  • Reply
Nick Soapdish
Apr 27, 2008


https://twitter.com/madebyhistory/status/1338197952754544641?s=20

I realize the news cycle has long blown past Morocco and Western Sahara business five years ago but good article from a history professor at my alma mater

Adbot
ADBOT LOVES YOU

lightpole
Jun 4, 2004
I think that MBAs are useful, in case you are looking for an answer to the question of "Is lightpole a total fucking idiot".
gently caress spreading it. I'm going once to get everything I can so I get all the suffering out of the way in a weekend.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

RFC2324 posted:

This vaccine is going to turn out horrible and decimate our medical community

Our medical community is being decimated by the virus....seriously:

https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(20)32478-8/fulltext

mlmp08
Jul 11, 2004

Prepare for my priapic projectile's exalted penetration
Nap Ghost
lol

https://twitter.com/dave_brown24/status/1338536436425961479?s=21

quote:

Edward Nicolae Luttwak is a strategist and historian known for his works on grand strategy, geoeconomics, military history, and international relations. He is best known for being the author of ''Coup d'État: A Practical Handbook'.

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS

It’s actually a really good book. Present irony notwithstanding.

Edit: the Luttwak comment didn’t appear in the quote for someone.

Soylent Pudding
Jun 22, 2007

We've got people!


WaPo reporting DHS also affected by the solarwinds supply chain attacks: https://www.washingtonpost.com/nati...4aff_story.html

:rip:

Meshka
Nov 27, 2016

Soylent Pudding posted:

WaPo reporting DHS also affected by the solarwinds supply chain attacks: https://www.washingtonpost.com/nati...4aff_story.html

:rip:

Just finished grad cyber intel course yesterday when the news hit. Russian APTs are the best in the world with the quickest breakout time, followed by China who are couple hours behind. Basically nothing about this is surprising that it is Russia, how deep they got, and how unprepared the agencies were.

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS

Meshka posted:

Just finished grad cyber intel course yesterday when the news hit. Russian APTs are the best in the world with the quickest breakout time, followed by China who are couple hours behind. Basically nothing about this is surprising that it is Russia, how deep they got, and how unprepared the agencies were.

So what can we actually do in response? Besides defensive securing of stuff. I mean in terms of giving the Russian Government a strong “gently caress off” message.

Milo and POTUS
Sep 3, 2017

I will not shut up about the Mighty Morphin Power Rangers. I talk about them all the time and work them into every conversation I have. I built a shrine in my room for the yellow one who died because sadly no one noticed because she died around 9/11. Wanna see it?

MazelTovCocktail posted:

I mean in terms of giving the Russian Government a strong “gently caress off” message.

lol

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS

Well perhaps waiting until after the inauguration.

Soylent Pudding
Jun 22, 2007

We've got people!


Meshka posted:

Just finished grad cyber intel course yesterday when the news hit. Russian APTs are the best in the world with the quickest breakout time, followed by China who are couple hours behind. Basically nothing about this is surprising that it is Russia, how deep they got, and how unprepared the agencies were.

The fun thing about supply chain attacks is that they hit even prepared agencies hard. That said between the notPetya and CCleaner attacks something like this was inevitable. Supply chain vulnerability awareness has been growing but not fast enough to head this off alas

Meshka
Nov 27, 2016

MazelTovCocktail posted:

So what can we actually do in response? Besides defensive securing of stuff. I mean in terms of giving the Russian Government a strong “gently caress off” message.

I don’t think there is anything to do, but shore up defenses. It would be fair to assume that US does the same thing and this is the new way of doing espionage. If both sides do it, an over retaliation by one side is not good and will lead to future consequences.

Vincent Van Goatse
Nov 8, 2006

Enjoy every sandwich.

Smellrose
Pornhub nuked all their user uploaded videos this morning. RIP jerkin' it, I guess.

shame on an IGA
Apr 8, 2005

The thing about offensive cyber is you have to assume your weapons only work once, so if you've got the capability to melt their power grid, blowing it on "sending a message" is less than prudent

That Works
Jul 22, 2006

Every revolution evaporates and leaves behind only the slime of a new bureaucracy


Vincent Van Goatse posted:

Pornhub nuked all their user uploaded videos this morning. RIP jerkin' it, I guess.

shame on an IGA posted:

The thing about offensive cyber is you have to assume your weapons only work once, so if you've got the capability to melt their power grid, blowing it on "sending a message" is less than prudent

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

MazelTovCocktail posted:

So what can we actually do in response? Besides defensive securing of stuff. I mean in terms of giving the Russian Government a strong “gently caress off” message.

The reality is: You are going to get hacked. Its inevitable, and no we shouldn't talk physical retaliation over it.

Lessons learned, patch, cleanup, and train.

A Bad Poster
Sep 25, 2006
Seriously, shut the fuck up.

:dukedog:
Can someone explain what exactly happened, to whom, and what it means? Everything I've seen linked is a little too technical for my dumb brain.

Coasterphreak
May 29, 2007
I like cookies.

even a broken clock...

Slim Pickens
Jan 12, 2007

Grimey Drawer

Soylent Pudding
Jun 22, 2007

We've got people!


A Bad Poster posted:

Can someone explain what exactly happened, to whom, and what it means? Everything I've seen linked is a little too technical for my dumb brain.

https://mobile.twitter.com/KimZetter/status/1338389130951061504

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Between this:

Solarwinds is a fairly old company with some bad practices in exposing certain devices (common in Enterprise), one way or another an attacker managed to gain access to the build server (the box that takes your code, compiles it, and then signs the compiled package to be deployed), and slipped in a compromise. The compromise modified a DLL in Solarwinds, and allowed the attacker access to any Solarwinds box that applied the patch, which allowed them to deploy another DLL that looks like a Windows native DLL, that allowed the attacker to send "Jobs" to the compromised system to execute recon and attacks against the system and network.

Solarwinds is a Network Monitoring tool used heavily in Fortune 500s and Government.

TL;DR: They poisoned the watering hole that is used by A LOT of IT departments, and it spready itself under a legitimate application with a signed certificate saying it was "valid"

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS

Meshka posted:

I don’t think there is anything to do, but shore up defenses. It would be fair to assume that US does the same thing and this is the new way of doing espionage. If both sides do it, an over retaliation by one side is not good and will lead to future consequences.

Fair enough.

brains
May 12, 2004

CommieGIR posted:

Between this:

Solarwinds is a fairly old company with some bad practices in exposing certain devices (common in Enterprise), one way or another an attacker managed to gain access to the build server (the box that takes your code, compiles it, and then signs the compiled package to be deployed), and slipped in a compromise. The compromise modified a DLL in Solarwinds, and allowed the attacker access to any Solarwinds box that applied the patch, which allowed them to deploy another DLL that looks like a Windows native DLL, that allowed the attacker to send "Jobs" to the compromised system to execute recon and attacks against the system and network.

Solarwinds is a Network Monitoring tool used heavily in Fortune 500s and Government.

TL;DR: They poisoned the watering hole that is used by A LOT of IT departments, and it spready itself under a legitimate application with a signed certificate saying it was "valid"

one way or another

https://twitter.com/vinodsparrow/status/1338431183588188160
https://twitter.com/Viss/status/1338575536793083906?s=20

lightpole
Jun 4, 2004
I think that MBAs are useful, in case you are looking for an answer to the question of "Is lightpole a total fucking idiot".

CommieGIR posted:

The reality is: You are going to get hacked. Its inevitable, and no we shouldn't talk physical retaliation over it.

Lessons learned, patch, cleanup, and train.

I studied this in grad school and those lessons are far from learned. Everyone should have an interest in best practices for cybersecurity and there should be a minimum level of understanding. Unfortunately, due to the complexity of the subject actual professionals are rare and expensive, and everyone vastly underestimates their need and exposure. Companies want to try using traditional marketing for this but it is insufficient to break through the complexity wall and I believe a more basic approach of supporting mandatory cybersecurity classes in schools is necessary.

Coasterphreak
May 29, 2007
I like cookies.

A Bad Poster posted:

Can someone explain what exactly happened, to whom, and what it means? Everything I've seen linked is a little too technical for my dumb brain.

It's the BOFH except at the international espionage level

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

lightpole posted:

I studied this in grad school and those lessons are far from learned. Everyone should have an interest in best practices for cybersecurity and there should be a minimum level of understanding. Unfortunately, due to the complexity of the subject actual professionals are rare and expensive, and everyone vastly underestimates their need and exposure. Companies want to try using traditional marketing for this but it is insufficient to break through the complexity wall and I believe a more basic approach of supporting mandatory cybersecurity classes in schools is necessary.

Yup. So many enterprise IT systems are GENERATIONS of tech debt and old growth, its impossible to really secure without burning down the stuff that makes the money. You can secure it better, but the best infosec strategy is to make sure you've got good, offline backups and monitor, log, and practice.

Soylent Pudding
Jun 22, 2007

We've got people!


I have a lot of thoughts on the subject and not much time to give my Ted talk. The short, short, short version is we have about three (human) generations of IT technology never designed with security in mind now globally interconnected. Security is still seen as an optional upgrade strongly encouraged to be purchased by the end user. So you don't get economies of scale because no one has the incentive to remove generations of poor design choices and rearchitect our digital infrastructure in a secure way. Basically the public only sees the wildfires but the actual issue is the decades of abysmal digital forest ecosystem management.

Meshka
Nov 27, 2016

Soylent Pudding posted:

I have a lot of thoughts on the subject and not much time to give my Ted talk. The short, short, short version is we have about three (human) generations of IT technology never designed with security in mind now globally interconnected. Security is still seen as an optional upgrade strongly encouraged to be purchased by the end user. So you don't get economies of scale because no one has the incentive to remove generations of poor design choices and rearchitect our digital infrastructure in a secure way. Basically the public only sees the wildfires but the actual issue is the decades of abysmal digital forest ecosystem management.

Yep, organizations are also as strong as their weakest link which is the idiot who always open the email attachment. Groups doing it are also very good, government or criminal. Russians and Chinese put a lot of resources in offensive operations and criminal groups are now organized into franchises where you can buy all the tools to do a ransomware attack for a % of payout

EBB
Feb 15, 2005

MazelTovCocktail posted:

Also for people who want to deep dive into the data.

There is no deep dive, I'm waiting for somebody to god drat publish something

Woofer
Mar 2, 2020

Dumb poo poo like this is why your password has to be random hieroglyphics and a mating call from an ancient and extinct language, plus a capital and lowercase letter.

Marshal Prolapse
Jun 23, 2012

by Jeffrey of YOSPOS

Woofer posted:

Dumb poo poo like this is why your password has to be random hieroglyphics and a mating call from an ancient and extinct language, plus a capital and lowercase letter.

Look at this scrub who doesn’t have to use numbers and special characters. :smuggo:

I swear 1Pass is the only thing that makes this tolerable...until some app doesn’t allow for logging on an app or website instead of typing it in. Worse a website that doesn’t support copy and paste or auto fill.

Also I feel the guy who came up with a lot of password recommendations said using three unique words (or some variation) and not requiring people to constantly change them (which for a long time was a reason for some truly truly lovely passwords).

Radical 90s Wizard
Aug 5, 2008

~SS-18 burning bright,
Bathe me in your cleansing light~
Man, fuuuuuuuck Dan Crenshaw.

Immanentized
Mar 17, 2009
I run InfoSec, particularly AppSec for a major tech firm. AMA about how today is going. (No we don't have SolarWinds and it loving owns.)

This was essentially a Zero-day type attack, while it wasn't due to any inherent insecurity in the Solarwinds/Orion application, it might as well fuckin been. To the average company, there was no way to mitigate this from happening, unless you were running an internal blue/red team on all of the applications you used and had some pretty gnarly contractual provisions to do the same on your vendors.

There's a reason why the attackers explicitly avoided the IP ranges of certain companies when deploying this sort of attack.

To the point of the Russians/Chinese being the "best" that's simply not true. They're the fastest to blow their exploits for sure, and they are able to quickly and thoroughly exploit open networks, but the rating of "best" goes to either the US or Israelis due to the fact that they're able to exploit, compromise, and operating within systems for years without blowing their load like this. The Russian model, and the derivative Chinese methodology is to breach hard and fast to shame or cause an adverse reaction on the target, most other nation-state actors (and honestly, there are really maybe 5 at that level) are more low and slow about it.

Pine Cone Jones
Dec 6, 2009

You throw me the acorn, I throw you the whip!
So what's these folks angle, besides just creating propaganda for internal consumption?
https://twitter.com/koi529/status/1338566044055646213
Is that just it?

Zamujasa
Oct 27, 2010



Bread Liar

Pine Cone Jones posted:

So what's these folks angle, besides just creating propaganda for internal consumption?

Is that just it?

Yes. "They tried to vote for Trump who totally won and were rejected! Fraud!"

Immanentized
Mar 17, 2009

Pine Cone Jones posted:

So what's these folks angle, besides just creating propaganda for internal consumption?
https://twitter.com/koi529/status/1338566044055646213
Is that just it?

They didn't though. No map is backing this up?

Zamujasa
Oct 27, 2010



Bread Liar
That's because it's a random twitter dipshit.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Pine Cone Jones posted:

So what's these folks angle, besides just creating propaganda for internal consumption?
https://twitter.com/koi529/status/1338566044055646213
Is that just it?

Doing a song and dance for GOP voters to keep the faith.

Pine Cone Jones
Dec 6, 2009

You throw me the acorn, I throw you the whip!

Immanentized posted:

They didn't though. No map is backing this up?

Yeah, it's just a trump internal propaganda piece, there's no reality to it.

Adbot
ADBOT LOVES YOU

CBJSprague24
Dec 5, 2010

another game at nationwide arena. everybody keeps asking me if they can fuck the cannon. buddy, they don't even let me fuck it

lightpole posted:

Last time I saw my Dr I told him I didn't want the flu shot cause I didn't want autism. He said it was too late.

:tviv:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply