💾 Archived View for dioskouroi.xyz › thread › 24921201 captured on 2020-10-31 at 00:51:43. Gemini links have been rewritten to link to archived content

View Raw

More Information

-=-=-=-=-=-=-

Security Blueprints of Many Companies Leaked in Hack of Swedish Firm Gunnebo

Author: parsecs

Score: 66

Comments: 14

Date: 2020-10-28 17:01:49

Web Link

________________________________________________________________________________

gruez wrote at 2020-10-28 18:37:57:

the hacked material was uploaded to a public server during the second half of September

Is it still up?

tptacek wrote at 2020-10-28 18:34:45:

In a rare instance where I'm going to come out and criticize Krebs: he should have disclosed that he has a business relationship with Hold Security.

krebsonsecurity wrote at 2020-10-28 18:57:58:

I have no financial relationship to Hold Security. When Alex started his company, he asked if he could list me as an advisor. I said yes. I've never received any sort of remuneration for that role. If anything, he is more of an advisor to me, in terms of possible story tips.

tptacek wrote at 2020-10-28 19:03:52:

You're prominently on his web page. You should just disclose it! It's not like it's a bad thing.

If for no other reason than that most people who see that web page are (reasonably) going to assume the position is in fact compensated, because most advisor positions are.

unstatusthequo wrote at 2020-10-29 01:04:18:

Not sure you can say most advisor positions are. That’s a vague generalization. Krebs said he wasn’t paid. So that’s his story, who cares? That’s not what the crux of this story is about and at best is a sideshow.

tptacek wrote at 2020-10-29 02:07:06:

It's a total sideshow, and it's not that big of a deal. I'm not trying to take Krebs down a peg; I'm a fan. If he's an advisor to a company, he should disclose that relationship --- like any other relationship! --- in his stories. That he's not paid doesn't change much; personal relationships are also disclosable. I mentioned the payment thing only because the optics probably weren't the optics Krebs wanted, not because I dispute what he's saying.

totalZero wrote at 2020-10-28 21:54:54:

Boom. You just disclosed it.

tptacek wrote at 2020-10-29 02:13:36:

As a term of art, "disclose" means "in the story". His relationship with Hold isn't a secret; it's on Hold's web page.

INTPenis wrote at 2020-10-28 18:53:39:

Maybe but the very first sentence in my mind made it clear that him specifically had something to do with the reveal. Why else would KrebsOnSecurity inform Gunnebo and not Hold Security themselves?

JoeAltmaier wrote at 2020-10-28 19:51:28:

Is this a case of 'security through secrecy' shouldn't be relied upon? We all know that shouldn't be a thing, but I guess every little bit helps.

vorpalhex wrote at 2020-10-28 23:32:31:

Security _only_ by obscurity is the problem.

rootsudo wrote at 2020-10-29 01:01:52:

It depends, it very much is not a bad thing ---

Stierlitz wrote at 2020-10-29 04:25:01:

“the intruders stole and published online tens of thousands of sensitive documents — including schematics of client bank vaults and surveillance systems.”

Explain like I'm five what such information is even doing on a “computer” connected directly to the Internet.

nojokes wrote at 2020-10-28 23:23:18:

Now I know from where they get all these blueprint in movies.