With no skill in software exploitation or encryption busting, Lapsus$ wins anyway.
See full article...
See full article...
Typo?Another recommendation is for the Federal Communications Commission and the Federal Communications Commission to beef up regulations concerning the porting of phone numbers from one SIM to another to curb SIM swapping.
A ragtag bunch of amateur hackers, many of them teenagers
Hack the planet!I saw that movie.
And that other one.
And that one, too.
The FBI? All the reporting I've managed to dig up says that it was the City of London Police that made the arrests. Do you have a link to the indictment or Krebs' writeup? I couldn't find it during a quick trawl through the archives.Krebs did a write up on Lapsus going through the indictments when the fbi arrested a bunch of the kids. IIRC, they played tons of people pretty hilariously(disclamer:Hacking is NOT COOL!) in a way security professionals with masters degrees and decades of experience couldn't prevent, and one tried to bluff the FBI agents interviewing them several times. It really debunks the "(un)motivated attacker" view of security through obscurity preventing script kiddies.
"These aren't script kiddies, they're script teenagers" [suspense noise]
A ragtag bunch of amateur hackers
Hacking into Brazil’s Ministry of Health and deleting more than 50 terabytes of data stored on the ministry’s servers
https://krebsonsecurity.com/2022/04/the-original-apt-advanced-persistent-teenagers/https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/This was several months ago, there was a link to the actual sworn FBI affidavit linked somewhere on one of these pages.The FBI? All the reporting I've managed to dig up says that it was the City of London Police that made the arrests. Do you have a link to the indictment or Krebs' writeup? I couldn't find it during a quick trawl through the archives.
Right, I saw and skimmed those articles, but as far as I can see none makes mention of LAPSUS$ members interacting with FBI agents beyond the FBI seizing one of their AWS data dumps. It's entirely possible I'm missing something.https://krebsonsecurity.com/2022/04/the-original-apt-advanced-persistent-teenagers/https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/This was several months ago, there was a link to the actual sworn FBI affidavit linked somewhere on one of these pages.
I tried searching on google and DDG and the results are being diluted by irrelevant "Trump indictment/affadavit" pages.
To be fair, an immutable law of the universe is that absolutely nothing will stand between a bored teenager and what they want at any particular moment. Things like parental filters and such are overwhelmingly useless and always have been.Reading daily the number of companies who admit to being hacked is worrying. When it is so easy for teenagers to gain access, how much easier for the nation states who have so much more resources?
Sadly, the recommendations are rarely implemented and if they are implemented take way too long.
I looked as well, and couldn't find it. It was the FBI special agent affadavit to extradite "white" from the UK to US. It might have been a different site too. I think the fact they are a minor when they commited the crimes is also possibly preventing an easy search by defendant name.Right, I saw and skimmed those articles, but as far as I can see none makes mention of LAPSUS$ members interacting with FBI agents beyond the FBI seizing one of their AWS data dumps. It's entirely possible I'm missing something.
The people that downvote this don't get it. The phonecalls are the wrench. You can create all the sophisticated security system in the world but you break down the person controlling the machine it becomes meaningless.
It's not being downvoted because people don't understand it, it's being downvoted because so many of us already read xkcd and posting a link to one is a bit of a tired cliché. If you're going to do it, at least add some sort of commentary or additional information to make it worthwhile (and no, stating "obligatory xkcd" doesn't count...)The people that downvote this don't get it. The phonecalls are the wrench. You can create all the sophisticated security system in the world but you break down the person controlling the machine it becomes meaningless.
Don't suppose you have a link to that, do you?These guys were really good at social engineering. Had a chance to listen to a recording of them in action. Really good.
We did, only we hacked the environmental control systems and permanently set them to "bake".Hack the planet!
I'd feel slightly less gross if the information on new standards had been distributed effectively and not been bogged down in Google PR peppering "death of the password" in every headline to the point it could have been a drinking game.Remember the breathless brouhaha about FIDO2 and passkeys?
This this is what FIDO2 was designed to fight. Specifically making sure the authentication device is within a few feet of the point of access being authenticated.
It’s for the people who haven’t read it…It's not being downvoted because people don't understand it, it's being downvoted because so many of us already read xkcd and posting a link to one is a bit of a tired cliché. If you're going to do it, at least add some sort of commentary or additional information to make it worthwhile (and no, stating "obligatory xkcd" doesn't count...)
It's all fun and games until a real threat from some totalitarian government hacks these teenagers..Krebs did a write up on Lapsus going through the indictments when the fbi arrested a bunch of the kids. IIRC, they played tons of people pretty hilariously(disclamer:Hacking is NOT COOL!) in a way security professionals with masters degrees and decades of experience couldn't prevent, and one tried to bluff the FBI agents interviewing them several times. It really debunks the "(un)motivated attacker" view of security through obscurity preventing script kiddies.
"These aren't script kiddies, they're script teenagers" [suspense noise]
It helps against that particular attack because it keys the device, which not all MFA systems do.No amount of 2FA is going to stop this kind of social engineering. The people accessing the system in this case are the people who are allowed to access the system, so they hae the FIDA2 keys already. You would need a system where changes requires review of multiple people to stop that kind of stuff.
Time limits on network access is a pain in the ass. I am fortunate enough to be able to stay mostly ahead of my teen so far. One is frustrated when the "internet doesn't work" when actually TikTok is blocked.To be fair, an immutable law of the universe is that absolutely nothing will stand between a bored teenager and what they want at any particular moment. Things like parental filters and such are overwhelmingly useless and always have been.