Comments
Why Russia Hacks
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
JJack154
50%
50%
JJack154,
User Rank: Apprentice
2/5/2015 | 12:13:30 PM
Re: Why ANY Nation Hacks
Putin's KGB roots and his belief that Russia will again become a major world power have given an attitude and the will to do what it takes! That's why Russin Hackers can do their thing in a sheltered environment sanctioned by their government.
lynnbr2
50%
50%
lynnbr2,
User Rank: Strategist
1/26/2015 | 8:52:24 AM
Re: Financial gain?
Russia & China both have a long history of hacking for over fifty years. Their primary reason is military. Remenber the Buran shuttle - amazinging similar to our old Space Shuttle. And now look at the Chinese J-20 & J-31 stealth fighters.

It is incrediby more cost effective to steal information, than it is to invest in the time and resources to design them yourself.

To be able to do this in a way without any fingerprints is a bonus. While military is their state primary goal, to employ third parties, they need a carrot - financial, to keep these third parties motivated and compensated, and up-to-date in their techniques.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/25/2015 | 8:41:28 PM
FWIW...
I recently saw former DHS chief Michael Chertoff speak at a cybersecurity conference, and he himself outright accused Russia of actively working with and supporting criminal organizations so as to perpetrate cyberwarfare.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/23/2015 | 4:36:04 PM
Re: Why ANY Nation Hacks
Well said, @aws0513! Thanks.
aws0513
50%
50%
aws0513,
User Rank: Ninja
1/23/2015 | 4:32:58 PM
Re: Why ANY Nation Hacks
Hello @Marilyn,

I think what Mike is providing is a better understanding of the threat side of the risk assesment equation.

The understanding of why state actors may want to target any organization can better help any risk assessment effort for any organization.  This kind of information can help analysts to determine a better threat score to assess against known state actors when compared to their line of business or valued properties. 
Understanding the why could have helped Sony change their risk assessment when they know that the movie they were making would upset or embarrass a dictator.  Although the why seems to be insanity in this case, it is a tangable fact that could have changed the threat value of a risk assessment involving North Korea as the possible threat actor.

This is rock solid analysis @Mike.  Thank you for all of this.

Keep fighting the good fight out there sir!
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/23/2015 | 1:32:19 PM
Re: Why ANY Nation Hacks
To you r point, @Gonz "Everybody who thinks that nations do not hack to further their geopolitical ambitions raise their hand." True, but what I'm taking away from this series is that the what, where and why nations hack are very different.

So my question to Mike is: what can security professionals take away from understanding the various motivations of nation-states, to help them better secure corporate systems and data? Does the "why" really matter?

 
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
1/23/2015 | 12:40:23 PM
Re: Why ANY Nation Hacks
@Mike Walls: And thank you for yours, shipmate! It really was an honor to serve; I come from a military family. At last count, around 20 veterans (some still serving) in all branches except the Coast Guard.

You are correct; it is an exciting time for young folks to be in IT security right now, as it is a wide open field with many openings in all industry segments. When I teach, I emphasize to my students that in addition to the technical skills, they must also strengthen their business savvy, soft skills like interpersonal relationships, presentation and communication skills, both oral and written. It is tough enough to get the security agenda pushed forward, and even tougher if you cannot communicate it in a way that is fit for executive consumption and for the lay person, and not just for their peers.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/23/2015 | 12:12:57 PM
Re: Financial gain?
Absolutely. Most governments to governments hacking are mainly initiated with a strategic gain, what they end up with is mainly show off and disruption tough, they hardly gain anything that they do not know already in my view.
mwallsedgewave
50%
50%
mwallsedgewave,
User Rank: Author
1/23/2015 | 12:11:53 PM
Re: Why ANY Nation Hacks
GonzSTL,

Glad to exchange thoughts with a "Shipmate" and thanks for your Service!  There are defintely opportunities both in the military (I prefer Navy for obvious reasons) and in the private sector...cyber security is an exciting place to be for young folks looking to make a difference.

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/23/2015 | 12:08:09 PM
Re: Why ANY Nation Hacks
The main reason US has best capabilities to hack is simply because more systems were design out of here and one way or another the most traffics is passing through resources in US regardless where you are in the world.
Page 1 / 2   >   >>


Cybersecurity's 'Broken' Hiring Process
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/11/2017
How Systematic Lying Can Improve Your Security
Lance Cottrell, Chief Scientist, Ntrepid,  10/11/2017
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO Advisor,  10/12/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.