TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tesla and FBI prevented $1M ransomware hack

20 pointsby noahmbarrover 4 years ago

6 comments

elliekellyover 4 years ago
Buried in the footnotes of the criminal complaint:<p>&gt; CHS1 [Confidential Human Source] is cooperating with the FBI because of patriotism to the United States and a perceived obligation to Victim Company A. CHS1 has not asked for and has not been offered any form of payment, including consideration regarding immigration or citizenship.<p>Does that mean this person is a foreign national? Would it be risky for this person to return home (perhaps to Russia?) after assisting the US government in this way?
评论 #24294805 未加载
ahale13over 4 years ago
I love reading stories about good people who step up and do what’s right. It seems most of today’s media is slanted to highlight those people who make the immoral, self-serving choice. Thank you, Tesla employee. Thank you for doing the right thing.
评论 #24294483 未加载
toomuchtodoover 4 years ago
Additional context:<p><a href="https:&#x2F;&#x2F;news.clearancejobs.com&#x2F;2020&#x2F;08&#x2F;26&#x2F;tesla-insider-works-with-fbi-to-turn-the-tables-on-russias-million-dollar-attempt-to-hijack-the-network&#x2F;" rel="nofollow">https:&#x2F;&#x2F;news.clearancejobs.com&#x2F;2020&#x2F;08&#x2F;26&#x2F;tesla-insider-work...</a><p><a href="https:&#x2F;&#x2F;www.justice.gov&#x2F;opa&#x2F;pr&#x2F;russian-national-arrested-conspiracy-introduce-malware-nevada-companys-computer-network" rel="nofollow">https:&#x2F;&#x2F;www.justice.gov&#x2F;opa&#x2F;pr&#x2F;russian-national-arrested-con...</a>
techslaveover 4 years ago
muy interensante.<p>we <i>often</i> theorize about &#x2F; present a threat model of an insider becoming malicious in exactly this way. rare that we hear of it actually occurring.<p>the number used in such threat modeling scenarios is typically $1MM. maybe we need to up that to $4.5MM. (per TFA)<p>note the simplification in the headline: the $1MM was merely the insider’s share, not the proposed ransomware amount.
评论 #24294704 未加载
ericalexander0over 4 years ago
Sign of a new trend? Most ransomware teams use traditional tactics: phishing to establish beach head, pivot to hunt down admin creds, game over. Some teams make opportunistic use of perimeter vulnerabilities (ie pulse VPN).<p>Most companies struggle with basic security controls like patching. Very few would survive insider threats with admin creds.
Ansil849over 4 years ago
I really wish sites would stop using scribd to host primary documents, which requires an account to be able to download them. Use something like DocumentCloud instead - which is both leaner, and does not require account to download files.