Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Why Russia Hacks
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
JJack154
50%
50%
JJack154,
User Rank: Apprentice
2/5/2015 | 12:13:30 PM
Re: Why ANY Nation Hacks
Putin's KGB roots and his belief that Russia will again become a major world power have given an attitude and the will to do what it takes! That's why Russin Hackers can do their thing in a sheltered environment sanctioned by their government.
lynnbr2
50%
50%
lynnbr2,
User Rank: Strategist
1/26/2015 | 8:52:24 AM
Re: Financial gain?
Russia & China both have a long history of hacking for over fifty years. Their primary reason is military. Remenber the Buran shuttle - amazinging similar to our old Space Shuttle. And now look at the Chinese J-20 & J-31 stealth fighters.

It is incrediby more cost effective to steal information, than it is to invest in the time and resources to design them yourself.

To be able to do this in a way without any fingerprints is a bonus. While military is their state primary goal, to employ third parties, they need a carrot - financial, to keep these third parties motivated and compensated, and up-to-date in their techniques.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/25/2015 | 8:41:28 PM
FWIW...
I recently saw former DHS chief Michael Chertoff speak at a cybersecurity conference, and he himself outright accused Russia of actively working with and supporting criminal organizations so as to perpetrate cyberwarfare.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/23/2015 | 4:36:04 PM
Re: Why ANY Nation Hacks
Well said, @aws0513! Thanks.
aws0513
50%
50%
aws0513,
User Rank: Ninja
1/23/2015 | 4:32:58 PM
Re: Why ANY Nation Hacks
Hello @Marilyn,

I think what Mike is providing is a better understanding of the threat side of the risk assesment equation.

The understanding of why state actors may want to target any organization can better help any risk assessment effort for any organization.  This kind of information can help analysts to determine a better threat score to assess against known state actors when compared to their line of business or valued properties. 
Understanding the why could have helped Sony change their risk assessment when they know that the movie they were making would upset or embarrass a dictator.  Although the why seems to be insanity in this case, it is a tangable fact that could have changed the threat value of a risk assessment involving North Korea as the possible threat actor.

This is rock solid analysis @Mike.  Thank you for all of this.

Keep fighting the good fight out there sir!
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/23/2015 | 1:32:19 PM
Re: Why ANY Nation Hacks
To you r point, @Gonz "Everybody who thinks that nations do not hack to further their geopolitical ambitions raise their hand." True, but what I'm taking away from this series is that the what, where and why nations hack are very different.

So my question to Mike is: what can security professionals take away from understanding the various motivations of nation-states, to help them better secure corporate systems and data? Does the "why" really matter?

 
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
1/23/2015 | 12:40:23 PM
Re: Why ANY Nation Hacks
@Mike Walls: And thank you for yours, shipmate! It really was an honor to serve; I come from a military family. At last count, around 20 veterans (some still serving) in all branches except the Coast Guard.

You are correct; it is an exciting time for young folks to be in IT security right now, as it is a wide open field with many openings in all industry segments. When I teach, I emphasize to my students that in addition to the technical skills, they must also strengthen their business savvy, soft skills like interpersonal relationships, presentation and communication skills, both oral and written. It is tough enough to get the security agenda pushed forward, and even tougher if you cannot communicate it in a way that is fit for executive consumption and for the lay person, and not just for their peers.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/23/2015 | 12:12:57 PM
Re: Financial gain?
Absolutely. Most governments to governments hacking are mainly initiated with a strategic gain, what they end up with is mainly show off and disruption tough, they hardly gain anything that they do not know already in my view.
mwallsedgewave
50%
50%
mwallsedgewave,
User Rank: Author
1/23/2015 | 12:11:53 PM
Re: Why ANY Nation Hacks
GonzSTL,

Glad to exchange thoughts with a "Shipmate" and thanks for your Service!  There are defintely opportunities both in the military (I prefer Navy for obvious reasons) and in the private sector...cyber security is an exciting place to be for young folks looking to make a difference.

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/23/2015 | 12:08:09 PM
Re: Why ANY Nation Hacks
The main reason US has best capabilities to hack is simply because more systems were design out of here and one way or another the most traffics is passing through resources in US regardless where you are in the world.
Page 1 / 2   >   >>


Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19668
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to preve...
CVE-2019-12882
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2017-6363
PUBLISHED: 2020-02-27
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for...
CVE-2017-6371
PUBLISHED: 2020-02-27
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.
CVE-2017-5861
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000020. Reason: This candidate is a reservation duplicate of CVE-2017-1000020. Notes: All CVE users should reference CVE-2017-1000020 instead of this candidate. All references and descriptions in this candidate have been removed to...