This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Hacks spied on Nasdaq ...

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Hacks spied on Nasdaq company boards
- http://www.reuters.com/article/2011/10/20/…E79J84T20111020
Oct 20, 2011 - "Hackers who infiltrated the Nasdaq's computer systems last year installed malicious software that allowed them to spy on the directors of publicly held companies, according to two people familiar with an investigation into the matter. The new details showed the cyber attack was more serious than previously thought, as Nasdaq OMX Group had said in February that there was no evidence the hackers accessed customer information. It was not known what information the hackers might have stolen. The investigation into the attack, involving the FBI and National Security Agency, is ongoing… The case is an example of a "blended attack," where elite hackers infiltrate one target to facilitate access to another… Nasdaq had previously said that its trading platforms were not compromised by the hackers, but they attacked a Web-based software program called Directors Desk, used by corporate boards to share documents and communicate with executives, among other things. By infecting Directors Desk, the hackers were able to access confidential documents and the communications of board directors… Investigators have learned that hackers were able to spy on "scores" of directors who logged onto directorsdesk .com before the malicious software was removed… It was still unclear how long Nasdaq's system was breached before the attack was discovered last October. A Nasdaq spokesman confirmed the investigation into the attack continues, but declined to give further details… Nasdaq CEO Robert Greifeld said in July that the exchange is under constant attack, requiring it to spend nearly a billion dollars a year on information security…"

:ph34r: <_< :ph34r:

… A Billion Dollars per Year ?


That's what is says. I'd be glad to take a paltry sum/part of that in the way of a salary of some sort, but they're exactly not beating down my doors in this economy, I'll tell ya'.

:(
Yes, I'd like to see that happen, It would be nice for you, and possibly more effective for them. I read the same article elsewhere and had similar thoughts. In my opinion, it is utterly scandalous, the extent to which major service providers (banks, medical records, government agencies, cloud providers, etc.) have IT in place that simply "ignores" serious breach risks that could otherwise be protected with relatively simple procedures which are not terribly different from what we individual owner/users provide on our local machines and networks. Their "bean-counters" and "lawyers" seem to be in charge of "risk management" and thereby trivialize and minimize risks to a few tens of thousands of users, simply because they believe they can get away with it. End of rant. :)

… have IT in place that simply ignore serious breach risks

I wouldn't be too harsh in assessing the IT techs, though. Most are working in a "skeleton crew" environment now, due to "budget cuts" and the like. Mgmt… well, that's a whole 'nother issue.

:(

… have IT in place that simply ignore serious breach risks

I wouldn't be too harsh in assessing the IT techs, though. Most are working in a "skeleton crew" environment now, due to "budget cuts" and the like. Mgmt… well, that's a whole 'nother issue.

:(



Yes, my rant is directed at CEO/Management, attorneys, and risk-management folks who gaze into their crystal balls to determine what risks they are willing to tolerate financially, while willingly placing their users at risk.

IT folks should not necessarily be "running-the-show" but they should have a voice and vote in executive decisions.

… to determine what risks they are willing to tolerate financially, while willingly placing their users at risk.

To them, it's just a "write-off". To you and me, it's probably a lot more than that.

:(
FYI…

Nasdaq lax security helped hacks…
- http://www.reuters.com/article/2011/11/17/…E7AG2NU20111117
Nov 17, 2011 - "A federal investigation into last year's cyber attack on Nasdaq OMX Group found surprisingly lax security practices that made the exchange operator an easy target for hackers… The ongoing probe by the Federal Bureau of Investigation is focused on Nasdaq's Directors Desk collaboration software… used by directors to share confidential information and to collaborate on projects. The investigators found that Nasdaq's basic computer architecture was sound, which kept its trading systems safe from the hackers… the investigators were surprised to find some computers with out-of-date software, misconfigured firewalls and uninstalled security patches that could have fixed known "bugs" that hackers could exploit…"

Budget cuts in an IT "skeleton crew" (already pared to the bone) have anything to do with it?
You have to wonder…


:blink: