[HN Gopher] Hackers claim vast access to Western Digital systems
___________________________________________________________________
Hackers claim vast access to Western Digital systems
Author : NKosmatos
Score : 143 points
Date : 2023-04-13 17:33 UTC (5 hours ago)
(HTM) web link (techcrunch.com)
(TXT) w3m dump (techcrunch.com)
| Apocryphon wrote:
| I'm curious if Western Digital's cloud was built upon their
| acquisition of Bertrand Serlet's startup UpThere at all.
| anigbrowl wrote:
| I bought an external drive of theirs a few years ago and they
| were _so_ into selling me the cloud storage on the back of it. I
| 'm glad that I'm old-fashioned enough to have most stuff stored
| locally on my mediocre home-build systems rather than the super-
| duper high performance cloud servers in a data center somewhere.
|
| What mystifies me about ransomware attacks is how many targets
| don't notice that vast quantities of data are being
| systematically exfiltrated. I can see how it might be
| particularly difficult for a cloud provider (assuming the hackers
| didn't pull it all through a single set of credentials), but for
| many targets, any sort of unfamiliar outgoing data stream larger
| than a gigabyte ought to be suspicious.
| outworlder wrote:
| > I can see how it might be particularly difficult for a cloud
| provider
|
| It is really not, though. Unless they take it very slowly and
| to locations that are not suspicious. Even something like
| GuardDuty on AWS will flag 'interesting' traffic to new
| locations.
| andrejguran wrote:
| seems like their cloud is back online after 5 days:
| https://status.mycloud.com/os4 Wonder if they paid the ransom
| xyst wrote:
| Or restored to a backup?
| thricegreat wrote:
| the article states they have not run any ransomware on the
| systems as of yet and they have maintained access. a backup
| wouldn't do much in this situation. it's not confirmed if the
| attackers are the cause of the service going offline and it
| should be presumed if they were they can take it down again.
| JohnMakin wrote:
| article mentions them "spidering into an azure tenant." Wonder if
| that's related to the azure multi tenancy misconfiguration that
| resulted in the Bing CMS being accessed that was brought up a few
| times here recently:
|
| https://news.ycombinator.com/item?id=35363205
| steffanA wrote:
| Very common to get access to the Azure/Local AD in ransomware
| attacks.
|
| That Bing CMS bug was only exploited by the researchers who
| disclosed it to MS.
| JohnMakin wrote:
| I'm not saying it's literally the same attack, but the author
| of that Bing CMS bug identified the cause (misconfigured
| multi tenancy) and said up to 25% of Azure apps they scanned
| had this same vulnerability.
| readyplayernull wrote:
| Is OpenAI at risk with MS deal?
| flangola7 wrote:
| if someone hasn't stolen GPT-4's weights yet, they're
| definitely trying
| jacquesm wrote:
| I wonder what their personnel vetting processes are like.
| That would be my first worry.
| anonsec123 wrote:
| Western Digital has likely been compromised for years. I would be
| real concerned about their windows drivers and device firmware.
| qwertox wrote:
| What do they mean by "customer data"? Payment information and
| other PII, or real backup data from this cloud backup thing they
| have?
|
| I only know of this "My Cloud" service which appears to be
| somehow linked to some NAS-like HDD offerings they have. I never
| really read about it because it is irrelevant to me, so I don't
| know if they also mirror the data in the cloud, or if the cloud
| gives the attacker remote access to these NAS disks and that they
| exfiltrated data this way, or something else.
| bot999top wrote:
| Let's speculate!
|
| Probably a lot based on the 10 terabyte number... and the SAP
| Backoffice... and that it took 5 days for them to come back up
|
| Ah, the SAP Backoffice, the magical land where businesses store
| their most treasured data, and where hackers drool over the
| potential loot. The SAP Backoffice system is a complex beast,
| made up of several components, such as:
|
| ERP (Enterprise Resource Planning) - The backbone of the
| operation, keeping track of everything from finances to supply
| chain management. CRM (Customer Relationship Management) - The
| digital black book of customer interactions, preferences, and
| sales opportunities. SRM (Supplier Relationship Management) -
| The hub that orchestrates the delicate dance between a business
| and its suppliers. HCM (Human Capital Management) - The
| watchful eye over the company's most valuable asset: its
| people. PLM (Product Lifecycle Management) - The puppet master
| pulling the strings of a product's journey from inception to
| obsolescence. SCM (Supply Chain Management) - The maestro
| conducting the symphony of goods flowing from supplier to
| customer. BI (Business Intelligence) - The all-knowing oracle
| that uncovers hidden insights from the vast sea of data.
| dabluecaboose wrote:
| The MyCloud hardware line allows you to setup a NAS and
| optionally expose it to the internet through their online
| credential service so that you can access the files from
| anywhere.
|
| The data is not "in the cloud" per se, but the credentials and
| login portal are.
| tpmx wrote:
| Assuming the self-proclaimed vermin is operating from
| $mostly_defunct_state without risk of recourse, what would the
| arguments be against removing all internet routes to/from
| $mostly_defunct_state? (Yes, it's obvious that criminals can find
| ways out of that, please go deeper than that.)
|
| Edit: Seems like the downvotes made me hit my rate limit of HN
| comments. Can't reply to any more comments; sorry. :(
| csydas wrote:
| it's a bad idea that is only punishing persons who have nothing
| to do with what you're trying to stop. as you said, it won't
| even bother the actual criminals, so why punish people for
| actions that are not their own and not under their control? so
| they rise up and...get killed by an overbearing government? it
| would even strengthen the governments position likely as well
| as the will of the hackers and force the nation(s) in question
| to be even more dependent on their government and fearful of
| any disruption or protest.
|
| information is and must continue to be a fundamental human
| right, and the internet is information. you basically doom an
| entire nation (or nations) to try to stop a small group of
| actors. this is the same thought process that has gotten the US
| into pointless wars and allowed awful law to be created all in
| the name of good.
|
| making efforts to block the payment systems they use arguably
| is a more effective approach (which i am not recommending by
| any means, but if we want to be serious about this and lowering
| the reward for ransomware, crypto would be a far better target)
| tromp wrote:
| The argument would be that we want the Russian people to have
| access to Western news (and former independent Russian news
| sites that were forced to setup shop abroad e.g. [1]), to
| counter all the state fed propaganda.
|
| [1] https://dutchreview.com/news/tindependent-russian-news-
| chann...
| f6v wrote:
| That's like saying you should build a wall around ghettos.
| Would make for an interesting movie, though.
| neoromantique wrote:
| Internet being global and free brings peace and understanding
| to the world, using it as a weapon is to accept defeat to the
| totalitarian regimes of yesteryear.
|
| Let the $mostly_defunct_state die off with the rest of them
| without succumbing to their playbook.
| tpmx wrote:
| > Internet being global and free brings peace and
| understanding to the world
|
| Do you think that worked with China?
| neoromantique wrote:
| Internet censorship being self-inflicted by China hints at
| who benefits from censorship, and it isn't democracies.
| pc86 wrote:
| China's internet is neither global nor free (and on the
| flip side, the global and free (mostly-free?) internet of
| the world is not generally accessible in China. That's not
| a particularly strong argument against the GP's point.
| sennight wrote:
| Like how the US impotently tried to destroy the Russian economy
| by fully weaponizing the USD, how did that work out? Not so
| great - all that served to do is begin the process of
| displacing the dollar as the world reserve. There is a point
| when your attempts to isolate a target only serve to further
| isolate yourself - and we are well past it.
| tomcar288 wrote:
| i don't see why this was downvoted. It's entirely correct
| that the impact on the russian economy was far less than
| hoped for. One youtube documentary I saw stated -2% GDP,
| whereas the expected amount people wanted and expected was on
| the order of 20 to 30%. they go into quite a bit of detail on
| why this is the case. And USD, is well on track to be
| displaced in a few decades: central banks across the world
| are dumping dollars on average 6% of US dollar reserves per
| year (although this was already started abeit more slowly in
| 2008).
| DoItToMe81 wrote:
| No, we shouldn't arbitrarily cut off millions of people from
| communication because some westerners have bought into a new
| red scare. That's ridiculous and childish.
| last_responder wrote:
| I suppose you think the invasion of Ukraine is either fake or
| justified as well.
| filoleg wrote:
| Not the person you are replying to, but you are making an
| absolutely bad faith assumption here.
|
| Is it that impossible for you to imagine that someone could
| be extremely apalled by the invasion of Ukraine and be
| fully in support of their side (i.e., being fully opposed
| to the Russian side), while at the same time standing for
| the principles of open internet and not believing in
| wholesale disconnecting entire countries?
|
| Because that's my personal stance. I am fully on the side
| of Ukraine here, with no "ifs" or "buts", and I
| simultaneously don't believe in blackholing tens of
| millions of people like that being a good idea.
| pelorat wrote:
| Why not? I netblock everything from .ru and .cn from my own
| servers. It's the way to go.
| panki27 wrote:
| And what benefit do you gain from that? Still enough
| proxies and other ways around.
| consumer451 wrote:
| I did that as well. One benefit I got was learning that
| GeForce Now will store your PII on CCP controlled servers
| at nvidia.cn by default. This happened from the USA. I
| have never been able to come up with a non-conspiratorial
| reason as to why this choice was made.
|
| I was able to get around this is by changing the login
| POST to use nvidia.com and everything worked just fine,
| and the ping to .com was obviously faster.
|
| It is lightyears beyond dumb that this is even legal in
| the USA.
|
| Would love to be talked down from this with a rational
| explanation.
|
| NOTE: This happened in 2021
| rm_-rf_slash wrote:
| How did you catch the traffic? Wireshark?
| jacquesm wrote:
| That's the wrong question. The right question is what did
| he lose because of that. And the answer is likely
| 'nothing'. So it's a free gain with zero downside, makes
| good sense to me.
| hackinthebochs wrote:
| When that country is fomenting unrest in the west through
| various means utilizing the internet, why should the west
| allow themselves to remain at the mercy of these operations?
| Liberal principles should not be a suicide pact.
| pphysch wrote:
| The idea that this or that Big Bad state is fomenting
| _significant_ unrest in the West is a false narrative
| manufactured to scapegoat from domestic mismanagement and
| distract from the fact that Washington hosts a massive
| global industry dedicated to destabilizing states,
| especially those Big Bad ones, via organizations like GEC,
| NED, USAGM, USAID, etc.
| hackinthebochs wrote:
| Putin's disinformation tactics are well known and
| documented. There is certainly a question of how much of
| a causal factor they are as opposed to the pre-existing
| fissures in society. But it's not reasonable to act like
| this is all a false narrative manufactured by whomever.
| pphysch wrote:
| This just isn't true. There is a well known and
| documented _narrative_ that Trump is a Russian asset and
| Putin is puppeteering US politics and so on and so forth,
| but it doesn 't match the evidence when you _actually dig
| into it_ and abandon preconceived conclusions.
|
| Russia doesn't have anything remotely like the global
| propaganda apparatus based in Washington. They do a lot
| of propaganda, sure, but they are small fries in
| comparison. They are investing in changing that, however.
| jltsiren wrote:
| The Russian propaganda machine is more about useful
| idiots than actual puppets. If you are doing something
| that creates divisions among their enemies, they try to
| encourage that, regardless of your ideological positions.
| In Soviet times, the useful idiots tended to be
| communists and environmentalists. These days, right-wing
| populists and conservative nationalists form a better
| target audience.
|
| And when it comes to propaganda, it's good to remember
| that the US didn't win the cold war because it had a
| better propaganda machine. It won, because it had more
| substance behind the propaganda. As a kid in the 80s, I
| was exposed to blatant propaganda from both sides. The
| USSR fell, and I was left with an instinctive dislike to
| anything that suggests that America is somehow special.
| But I've never had any doubt of which side I would choose
| if I had to, because substance is ultimately more
| important than propaganda.
| hackinthebochs wrote:
| Putin's disinformation tactics in the west go far beyond
| anything specifically related to Trump. Putin's facebook
| ad buy and relationship to Cambridge Analytica is well
| known. So is Putin's playbook for fomenting unrest in
| Eastern Europe. It's some serious myopia to think Putin's
| relevance is entirely related to Trump.
| pphysch wrote:
| Please show me an example of an ad that Putin used on
| Facebook (or anywhere).
| filoleg wrote:
| I don't think it is some big "Washington and the buddies"
| conspiracy theory, but something much simpler.
|
| Fearmongering and doomer attitudes drive clicks for news
| publishers. Clicks drive money. Money drives their growth
| and influence. Which, in turn, drives more clicks.
|
| And guess who is thrashing around in their desperate
| attempts to stop bleeding influence and money in the
| internet age? Traditional news media.
|
| Not that difficult to see some clear examples of that
| either, like the recent bills in some countries trying to
| extort FB and Google to pay money for every news article
| shared on their platforms (for google it was in the form
| of the preview snippets, for fb it was in the form of
| users sharing links iirc).
| pphysch wrote:
| There is a component of click-baiting, but there are also
| clear mechanisms by which Washington promotes these
| misleading narratives.
| phailhaus wrote:
| What would this even accomplish? How would that solution
| generalize to other sources of hackers? It's the equivalent of
| going "hmm, they all seem to love using Aquafresh toothpaste,
| what if we banned it?"
| jms703 wrote:
| Cyber hackers are not limited to particular geographies or ip
| address blocks. The network approach doesn't work.
| jws wrote:
| Ultimately, maybe not, but I finally dabbled in geolocation
| on a property that was receiving comment spam. I ended up
| eliminated 100%, not nearly 100%, actually 100% of the spam
| by blocking anonymous content from one country.
|
| In another application I got rid of 90% of the flash wear on
| an IoT device by blocking a single country from a port.
|
| A determined, targeted attack will go around a geoblock, but
| I have to reluctantly admit that it can be useful for the
| high volume attacks.
| neoromantique wrote:
| Perhaps the takeaway is that you shouldn't leave ports wide
| open rather than go for xenophobia?
| jacquesm wrote:
| Blocking an IP range isn't xenophobia.
| neoromantique wrote:
| Extending the line of thought of OP sure is.
|
| It's not $country's fault that you don't use vpn or port
| knocking.
| jacquesm wrote:
| It is $country's fault that there is a free reign for
| criminals, either state sponsored or acting on their own.
| BeepBipBoop wrote:
| [dead]
| justeleblanc wrote:
| So what, fuck the people living there? And who are you to
| decide that some state is "mostly defunct"?
| hackinthebochs wrote:
| They have their own internal internet. Accessing Google and
| Youtube aren't critical to modern life.
| justeleblanc wrote:
| Neither are western digital services.
| popcalc wrote:
| North Korea doesn't use their own IPs to execute heists. They
| go on work trips to HK or Eastern China and set up a proxy
| chain that culminates with the iot lightbulb in your grandpa's
| garage as the exit node.
|
| I'm going to take this opportunity to shill gost, an amazing
| tool (https://github.com/go-gost/gost). Can someone tell me why
| Go is so popular in Chinese dev circles?
| thakoppno wrote:
| > iot lightbulb in your grandpa's garage as the exit node
|
| Obvious hyperbole and all, but just how much data is
| transmitted to accomplish a sophisticated nation-state level
| attack?
|
| I'd believe a regular laptop is sufficient but not a
| lightbulb. Then again, if it's only a matter of 100KB, then
| maybe a lightbulb makes sense.
| pseudo0 wrote:
| Consumer routers are a shitshow when it comes to CVEs and
| updates. Someone who gets on an IoT device can often pivot
| to the router or something else vulnerable on the network.
| Also command and control and data theft can happen through
| different channels. Command and control typically has very
| low bandwidth requirements.
| jacquesm wrote:
| The effect is similar to 'FTP', your control channel is
| only sending a couple of bytes but the resulting data
| transfers can be massive.
| rsync wrote:
| "I'm going to take this opportunity to shill gost, an amazing
| tool ..."
|
| Here is the english readme:
|
| https://github.com/go-gost/gost/blob/master/README_en.md
|
| ... and here is a better page:
|
| https://gost.run/en/
|
| It seems to have a rich feature set ... can you elaborate on
| why you like this tool so much ?
| voytec wrote:
| related thread from few days ago: Western Digital cloud services
| down for 4 days[1]
|
| [1] https://news.ycombinator.com/item?id=35478007
| stan_kirdey wrote:
| Do hackers ask for ransom as a single payment, or there is more
| of a scalable repeatable business model with recurring revenue? A
| subscription service seems convenient.
| c7DJTLrn wrote:
| 20% off for the yearly plan, or buy one get one free on Black
| Friday.
| waboremo wrote:
| Is there a student discounted plan?
| jacquesm wrote:
| Only if you first send them only copy of your thesis.
| henriquez wrote:
| The hackers offer a lifetime licensing model for their
| ExtortionPro SaaS service. With a single convenient payment you
| can be guaranteed that your enterprise security and
| confidential information is in good hands. At least until the
| hacking group is acquired and they reposition their offering as
| a two year subscription.
| WakoMan12 wrote:
| [dead]
| boredumb wrote:
| If they can incorporate an LLM somewhere - they may even show
| up on the front page as a (YC 2024) project.
| stan_kirdey wrote:
| lack of analytics offering over stolen data seemed like a
| missed opportunity too :(
| eastbound wrote:
| I like that you're discussing revenue streams. They also add
| social proof on the pricing page ("We blackmailed hospital xyz
| with success") and play dopamine effects ("Play PasswordGuessr
| to unlock a file, or pay to unlock all files"). The infinite
| scroll is coming to show what your API keys have access to
| (highly addictive, look at all those bank transactions and,
| mmh, revenge pics with your ex).
| outworlder wrote:
| > Do hackers ask for ransom as a single payment, or there is
| more of a scalable repeatable business model with recurring
| revenue? A subscription service seems convenient.
|
| Given that in many cases they are more skilled than the actual
| cybersec folks in those companies, they should charge a fee to
| monitor their systems.
|
| There's prior art for that business model. I'm told it was
| popular in Italy many years ago.
___________________________________________________________________
(page generated 2023-04-13 23:01 UTC)