[HN Gopher] Hackers claim vast access to Western Digital systems
       ___________________________________________________________________
        
       Hackers claim vast access to Western Digital systems
        
       Author : NKosmatos
       Score  : 143 points
       Date   : 2023-04-13 17:33 UTC (5 hours ago)
        
 (HTM) web link (techcrunch.com)
 (TXT) w3m dump (techcrunch.com)
        
       | Apocryphon wrote:
       | I'm curious if Western Digital's cloud was built upon their
       | acquisition of Bertrand Serlet's startup UpThere at all.
        
       | anigbrowl wrote:
       | I bought an external drive of theirs a few years ago and they
       | were _so_ into selling me the cloud storage on the back of it. I
       | 'm glad that I'm old-fashioned enough to have most stuff stored
       | locally on my mediocre home-build systems rather than the super-
       | duper high performance cloud servers in a data center somewhere.
       | 
       | What mystifies me about ransomware attacks is how many targets
       | don't notice that vast quantities of data are being
       | systematically exfiltrated. I can see how it might be
       | particularly difficult for a cloud provider (assuming the hackers
       | didn't pull it all through a single set of credentials), but for
       | many targets, any sort of unfamiliar outgoing data stream larger
       | than a gigabyte ought to be suspicious.
        
         | outworlder wrote:
         | > I can see how it might be particularly difficult for a cloud
         | provider
         | 
         | It is really not, though. Unless they take it very slowly and
         | to locations that are not suspicious. Even something like
         | GuardDuty on AWS will flag 'interesting' traffic to new
         | locations.
        
       | andrejguran wrote:
       | seems like their cloud is back online after 5 days:
       | https://status.mycloud.com/os4 Wonder if they paid the ransom
        
         | xyst wrote:
         | Or restored to a backup?
        
           | thricegreat wrote:
           | the article states they have not run any ransomware on the
           | systems as of yet and they have maintained access. a backup
           | wouldn't do much in this situation. it's not confirmed if the
           | attackers are the cause of the service going offline and it
           | should be presumed if they were they can take it down again.
        
       | JohnMakin wrote:
       | article mentions them "spidering into an azure tenant." Wonder if
       | that's related to the azure multi tenancy misconfiguration that
       | resulted in the Bing CMS being accessed that was brought up a few
       | times here recently:
       | 
       | https://news.ycombinator.com/item?id=35363205
        
         | steffanA wrote:
         | Very common to get access to the Azure/Local AD in ransomware
         | attacks.
         | 
         | That Bing CMS bug was only exploited by the researchers who
         | disclosed it to MS.
        
           | JohnMakin wrote:
           | I'm not saying it's literally the same attack, but the author
           | of that Bing CMS bug identified the cause (misconfigured
           | multi tenancy) and said up to 25% of Azure apps they scanned
           | had this same vulnerability.
        
         | readyplayernull wrote:
         | Is OpenAI at risk with MS deal?
        
           | flangola7 wrote:
           | if someone hasn't stolen GPT-4's weights yet, they're
           | definitely trying
        
             | jacquesm wrote:
             | I wonder what their personnel vetting processes are like.
             | That would be my first worry.
        
       | anonsec123 wrote:
       | Western Digital has likely been compromised for years. I would be
       | real concerned about their windows drivers and device firmware.
        
       | qwertox wrote:
       | What do they mean by "customer data"? Payment information and
       | other PII, or real backup data from this cloud backup thing they
       | have?
       | 
       | I only know of this "My Cloud" service which appears to be
       | somehow linked to some NAS-like HDD offerings they have. I never
       | really read about it because it is irrelevant to me, so I don't
       | know if they also mirror the data in the cloud, or if the cloud
       | gives the attacker remote access to these NAS disks and that they
       | exfiltrated data this way, or something else.
        
         | bot999top wrote:
         | Let's speculate!
         | 
         | Probably a lot based on the 10 terabyte number... and the SAP
         | Backoffice... and that it took 5 days for them to come back up
         | 
         | Ah, the SAP Backoffice, the magical land where businesses store
         | their most treasured data, and where hackers drool over the
         | potential loot. The SAP Backoffice system is a complex beast,
         | made up of several components, such as:
         | 
         | ERP (Enterprise Resource Planning) - The backbone of the
         | operation, keeping track of everything from finances to supply
         | chain management. CRM (Customer Relationship Management) - The
         | digital black book of customer interactions, preferences, and
         | sales opportunities. SRM (Supplier Relationship Management) -
         | The hub that orchestrates the delicate dance between a business
         | and its suppliers. HCM (Human Capital Management) - The
         | watchful eye over the company's most valuable asset: its
         | people. PLM (Product Lifecycle Management) - The puppet master
         | pulling the strings of a product's journey from inception to
         | obsolescence. SCM (Supply Chain Management) - The maestro
         | conducting the symphony of goods flowing from supplier to
         | customer. BI (Business Intelligence) - The all-knowing oracle
         | that uncovers hidden insights from the vast sea of data.
        
         | dabluecaboose wrote:
         | The MyCloud hardware line allows you to setup a NAS and
         | optionally expose it to the internet through their online
         | credential service so that you can access the files from
         | anywhere.
         | 
         | The data is not "in the cloud" per se, but the credentials and
         | login portal are.
        
       | tpmx wrote:
       | Assuming the self-proclaimed vermin is operating from
       | $mostly_defunct_state without risk of recourse, what would the
       | arguments be against removing all internet routes to/from
       | $mostly_defunct_state? (Yes, it's obvious that criminals can find
       | ways out of that, please go deeper than that.)
       | 
       | Edit: Seems like the downvotes made me hit my rate limit of HN
       | comments. Can't reply to any more comments; sorry. :(
        
         | csydas wrote:
         | it's a bad idea that is only punishing persons who have nothing
         | to do with what you're trying to stop. as you said, it won't
         | even bother the actual criminals, so why punish people for
         | actions that are not their own and not under their control? so
         | they rise up and...get killed by an overbearing government? it
         | would even strengthen the governments position likely as well
         | as the will of the hackers and force the nation(s) in question
         | to be even more dependent on their government and fearful of
         | any disruption or protest.
         | 
         | information is and must continue to be a fundamental human
         | right, and the internet is information. you basically doom an
         | entire nation (or nations) to try to stop a small group of
         | actors. this is the same thought process that has gotten the US
         | into pointless wars and allowed awful law to be created all in
         | the name of good.
         | 
         | making efforts to block the payment systems they use arguably
         | is a more effective approach (which i am not recommending by
         | any means, but if we want to be serious about this and lowering
         | the reward for ransomware, crypto would be a far better target)
        
         | tromp wrote:
         | The argument would be that we want the Russian people to have
         | access to Western news (and former independent Russian news
         | sites that were forced to setup shop abroad e.g. [1]), to
         | counter all the state fed propaganda.
         | 
         | [1] https://dutchreview.com/news/tindependent-russian-news-
         | chann...
        
         | f6v wrote:
         | That's like saying you should build a wall around ghettos.
         | Would make for an interesting movie, though.
        
         | neoromantique wrote:
         | Internet being global and free brings peace and understanding
         | to the world, using it as a weapon is to accept defeat to the
         | totalitarian regimes of yesteryear.
         | 
         | Let the $mostly_defunct_state die off with the rest of them
         | without succumbing to their playbook.
        
           | tpmx wrote:
           | > Internet being global and free brings peace and
           | understanding to the world
           | 
           | Do you think that worked with China?
        
             | neoromantique wrote:
             | Internet censorship being self-inflicted by China hints at
             | who benefits from censorship, and it isn't democracies.
        
             | pc86 wrote:
             | China's internet is neither global nor free (and on the
             | flip side, the global and free (mostly-free?) internet of
             | the world is not generally accessible in China. That's not
             | a particularly strong argument against the GP's point.
        
         | sennight wrote:
         | Like how the US impotently tried to destroy the Russian economy
         | by fully weaponizing the USD, how did that work out? Not so
         | great - all that served to do is begin the process of
         | displacing the dollar as the world reserve. There is a point
         | when your attempts to isolate a target only serve to further
         | isolate yourself - and we are well past it.
        
           | tomcar288 wrote:
           | i don't see why this was downvoted. It's entirely correct
           | that the impact on the russian economy was far less than
           | hoped for. One youtube documentary I saw stated -2% GDP,
           | whereas the expected amount people wanted and expected was on
           | the order of 20 to 30%. they go into quite a bit of detail on
           | why this is the case. And USD, is well on track to be
           | displaced in a few decades: central banks across the world
           | are dumping dollars on average 6% of US dollar reserves per
           | year (although this was already started abeit more slowly in
           | 2008).
        
         | DoItToMe81 wrote:
         | No, we shouldn't arbitrarily cut off millions of people from
         | communication because some westerners have bought into a new
         | red scare. That's ridiculous and childish.
        
           | last_responder wrote:
           | I suppose you think the invasion of Ukraine is either fake or
           | justified as well.
        
             | filoleg wrote:
             | Not the person you are replying to, but you are making an
             | absolutely bad faith assumption here.
             | 
             | Is it that impossible for you to imagine that someone could
             | be extremely apalled by the invasion of Ukraine and be
             | fully in support of their side (i.e., being fully opposed
             | to the Russian side), while at the same time standing for
             | the principles of open internet and not believing in
             | wholesale disconnecting entire countries?
             | 
             | Because that's my personal stance. I am fully on the side
             | of Ukraine here, with no "ifs" or "buts", and I
             | simultaneously don't believe in blackholing tens of
             | millions of people like that being a good idea.
        
           | pelorat wrote:
           | Why not? I netblock everything from .ru and .cn from my own
           | servers. It's the way to go.
        
             | panki27 wrote:
             | And what benefit do you gain from that? Still enough
             | proxies and other ways around.
        
               | consumer451 wrote:
               | I did that as well. One benefit I got was learning that
               | GeForce Now will store your PII on CCP controlled servers
               | at nvidia.cn by default. This happened from the USA. I
               | have never been able to come up with a non-conspiratorial
               | reason as to why this choice was made.
               | 
               | I was able to get around this is by changing the login
               | POST to use nvidia.com and everything worked just fine,
               | and the ping to .com was obviously faster.
               | 
               | It is lightyears beyond dumb that this is even legal in
               | the USA.
               | 
               | Would love to be talked down from this with a rational
               | explanation.
               | 
               | NOTE: This happened in 2021
        
               | rm_-rf_slash wrote:
               | How did you catch the traffic? Wireshark?
        
               | jacquesm wrote:
               | That's the wrong question. The right question is what did
               | he lose because of that. And the answer is likely
               | 'nothing'. So it's a free gain with zero downside, makes
               | good sense to me.
        
           | hackinthebochs wrote:
           | When that country is fomenting unrest in the west through
           | various means utilizing the internet, why should the west
           | allow themselves to remain at the mercy of these operations?
           | Liberal principles should not be a suicide pact.
        
             | pphysch wrote:
             | The idea that this or that Big Bad state is fomenting
             | _significant_ unrest in the West is a false narrative
             | manufactured to scapegoat from domestic mismanagement and
             | distract from the fact that Washington hosts a massive
             | global industry dedicated to destabilizing states,
             | especially those Big Bad ones, via organizations like GEC,
             | NED, USAGM, USAID, etc.
        
               | hackinthebochs wrote:
               | Putin's disinformation tactics are well known and
               | documented. There is certainly a question of how much of
               | a causal factor they are as opposed to the pre-existing
               | fissures in society. But it's not reasonable to act like
               | this is all a false narrative manufactured by whomever.
        
               | pphysch wrote:
               | This just isn't true. There is a well known and
               | documented _narrative_ that Trump is a Russian asset and
               | Putin is puppeteering US politics and so on and so forth,
               | but it doesn 't match the evidence when you _actually dig
               | into it_ and abandon preconceived conclusions.
               | 
               | Russia doesn't have anything remotely like the global
               | propaganda apparatus based in Washington. They do a lot
               | of propaganda, sure, but they are small fries in
               | comparison. They are investing in changing that, however.
        
               | jltsiren wrote:
               | The Russian propaganda machine is more about useful
               | idiots than actual puppets. If you are doing something
               | that creates divisions among their enemies, they try to
               | encourage that, regardless of your ideological positions.
               | In Soviet times, the useful idiots tended to be
               | communists and environmentalists. These days, right-wing
               | populists and conservative nationalists form a better
               | target audience.
               | 
               | And when it comes to propaganda, it's good to remember
               | that the US didn't win the cold war because it had a
               | better propaganda machine. It won, because it had more
               | substance behind the propaganda. As a kid in the 80s, I
               | was exposed to blatant propaganda from both sides. The
               | USSR fell, and I was left with an instinctive dislike to
               | anything that suggests that America is somehow special.
               | But I've never had any doubt of which side I would choose
               | if I had to, because substance is ultimately more
               | important than propaganda.
        
               | hackinthebochs wrote:
               | Putin's disinformation tactics in the west go far beyond
               | anything specifically related to Trump. Putin's facebook
               | ad buy and relationship to Cambridge Analytica is well
               | known. So is Putin's playbook for fomenting unrest in
               | Eastern Europe. It's some serious myopia to think Putin's
               | relevance is entirely related to Trump.
        
               | pphysch wrote:
               | Please show me an example of an ad that Putin used on
               | Facebook (or anywhere).
        
               | filoleg wrote:
               | I don't think it is some big "Washington and the buddies"
               | conspiracy theory, but something much simpler.
               | 
               | Fearmongering and doomer attitudes drive clicks for news
               | publishers. Clicks drive money. Money drives their growth
               | and influence. Which, in turn, drives more clicks.
               | 
               | And guess who is thrashing around in their desperate
               | attempts to stop bleeding influence and money in the
               | internet age? Traditional news media.
               | 
               | Not that difficult to see some clear examples of that
               | either, like the recent bills in some countries trying to
               | extort FB and Google to pay money for every news article
               | shared on their platforms (for google it was in the form
               | of the preview snippets, for fb it was in the form of
               | users sharing links iirc).
        
               | pphysch wrote:
               | There is a component of click-baiting, but there are also
               | clear mechanisms by which Washington promotes these
               | misleading narratives.
        
         | phailhaus wrote:
         | What would this even accomplish? How would that solution
         | generalize to other sources of hackers? It's the equivalent of
         | going "hmm, they all seem to love using Aquafresh toothpaste,
         | what if we banned it?"
        
         | jms703 wrote:
         | Cyber hackers are not limited to particular geographies or ip
         | address blocks. The network approach doesn't work.
        
           | jws wrote:
           | Ultimately, maybe not, but I finally dabbled in geolocation
           | on a property that was receiving comment spam. I ended up
           | eliminated 100%, not nearly 100%, actually 100% of the spam
           | by blocking anonymous content from one country.
           | 
           | In another application I got rid of 90% of the flash wear on
           | an IoT device by blocking a single country from a port.
           | 
           | A determined, targeted attack will go around a geoblock, but
           | I have to reluctantly admit that it can be useful for the
           | high volume attacks.
        
             | neoromantique wrote:
             | Perhaps the takeaway is that you shouldn't leave ports wide
             | open rather than go for xenophobia?
        
               | jacquesm wrote:
               | Blocking an IP range isn't xenophobia.
        
               | neoromantique wrote:
               | Extending the line of thought of OP sure is.
               | 
               | It's not $country's fault that you don't use vpn or port
               | knocking.
        
               | jacquesm wrote:
               | It is $country's fault that there is a free reign for
               | criminals, either state sponsored or acting on their own.
        
         | BeepBipBoop wrote:
         | [dead]
        
         | justeleblanc wrote:
         | So what, fuck the people living there? And who are you to
         | decide that some state is "mostly defunct"?
        
           | hackinthebochs wrote:
           | They have their own internal internet. Accessing Google and
           | Youtube aren't critical to modern life.
        
             | justeleblanc wrote:
             | Neither are western digital services.
        
         | popcalc wrote:
         | North Korea doesn't use their own IPs to execute heists. They
         | go on work trips to HK or Eastern China and set up a proxy
         | chain that culminates with the iot lightbulb in your grandpa's
         | garage as the exit node.
         | 
         | I'm going to take this opportunity to shill gost, an amazing
         | tool (https://github.com/go-gost/gost). Can someone tell me why
         | Go is so popular in Chinese dev circles?
        
           | thakoppno wrote:
           | > iot lightbulb in your grandpa's garage as the exit node
           | 
           | Obvious hyperbole and all, but just how much data is
           | transmitted to accomplish a sophisticated nation-state level
           | attack?
           | 
           | I'd believe a regular laptop is sufficient but not a
           | lightbulb. Then again, if it's only a matter of 100KB, then
           | maybe a lightbulb makes sense.
        
             | pseudo0 wrote:
             | Consumer routers are a shitshow when it comes to CVEs and
             | updates. Someone who gets on an IoT device can often pivot
             | to the router or something else vulnerable on the network.
             | Also command and control and data theft can happen through
             | different channels. Command and control typically has very
             | low bandwidth requirements.
        
             | jacquesm wrote:
             | The effect is similar to 'FTP', your control channel is
             | only sending a couple of bytes but the resulting data
             | transfers can be massive.
        
           | rsync wrote:
           | "I'm going to take this opportunity to shill gost, an amazing
           | tool ..."
           | 
           | Here is the english readme:
           | 
           | https://github.com/go-gost/gost/blob/master/README_en.md
           | 
           | ... and here is a better page:
           | 
           | https://gost.run/en/
           | 
           | It seems to have a rich feature set ... can you elaborate on
           | why you like this tool so much ?
        
       | voytec wrote:
       | related thread from few days ago: Western Digital cloud services
       | down for 4 days[1]
       | 
       | [1] https://news.ycombinator.com/item?id=35478007
        
       | stan_kirdey wrote:
       | Do hackers ask for ransom as a single payment, or there is more
       | of a scalable repeatable business model with recurring revenue? A
       | subscription service seems convenient.
        
         | c7DJTLrn wrote:
         | 20% off for the yearly plan, or buy one get one free on Black
         | Friday.
        
           | waboremo wrote:
           | Is there a student discounted plan?
        
             | jacquesm wrote:
             | Only if you first send them only copy of your thesis.
        
         | henriquez wrote:
         | The hackers offer a lifetime licensing model for their
         | ExtortionPro SaaS service. With a single convenient payment you
         | can be guaranteed that your enterprise security and
         | confidential information is in good hands. At least until the
         | hacking group is acquired and they reposition their offering as
         | a two year subscription.
        
           | WakoMan12 wrote:
           | [dead]
        
         | boredumb wrote:
         | If they can incorporate an LLM somewhere - they may even show
         | up on the front page as a (YC 2024) project.
        
         | stan_kirdey wrote:
         | lack of analytics offering over stolen data seemed like a
         | missed opportunity too :(
        
         | eastbound wrote:
         | I like that you're discussing revenue streams. They also add
         | social proof on the pricing page ("We blackmailed hospital xyz
         | with success") and play dopamine effects ("Play PasswordGuessr
         | to unlock a file, or pay to unlock all files"). The infinite
         | scroll is coming to show what your API keys have access to
         | (highly addictive, look at all those bank transactions and,
         | mmh, revenge pics with your ex).
        
         | outworlder wrote:
         | > Do hackers ask for ransom as a single payment, or there is
         | more of a scalable repeatable business model with recurring
         | revenue? A subscription service seems convenient.
         | 
         | Given that in many cases they are more skilled than the actual
         | cybersec folks in those companies, they should charge a fee to
         | monitor their systems.
         | 
         | There's prior art for that business model. I'm told it was
         | popular in Italy many years ago.
        
       ___________________________________________________________________
       (page generated 2023-04-13 23:01 UTC)