TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

NATO Classified Cloud Platform Compromised

238 pointsby afrcncalmost 4 years ago

12 comments

spaniard89277almost 4 years ago
Everis is the typical meat grinder, and it is known for that in Spain.<p>Now, just as I&#x27;m writing this I&#x27;m sure someome from Everis will chime in to say he gets paid handsomely and works for amazing projects.<p>But everyone I&#x27;ve known working for Everis wants to die.<p>And if such project had to land in Spain for political reasons, there are plenty of companies capable on taking such project with way better prospects.
评论 #27684925 未加载
评论 #27684379 未加载
评论 #27685444 未加载
评论 #27709369 未加载
评论 #27686500 未加载
评论 #27687288 未加载
0xCMPalmost 4 years ago
&gt; &quot;which basically tricks organizations into spending a ton of money for installing Docker into a CentOS image without any cryptographic signature to verify the integrity of that image.&quot;<p>Ouch
评论 #27684405 未加载
nooberminalmost 4 years ago
Reading the start of this article reminded me of a somewhat unrelated thing I saw: I remember seeing in &quot;tech influencer&quot; youtube video on how &quot;Japan hasn&#x27;t kept up with the west&quot; when it comes to IT. Not to be super orientalist or whatever and assume Japan is doing better the US in IT, but what should they do instead, go the US route and put every thing on the cloud? Is that <i>better</i>?<p>I couldn&#x27;t help it, it&#x27;s literally in the article that this was part of the &quot;NATO modernization&quot; efforts. Perhaps whatever they had before would have failed too but it&#x27;s clear that these &quot;modernization&quot; efforts aren&#x27;t always better.
评论 #27686104 未加载
评论 #27686305 未加载
评论 #27685940 未加载
评论 #27686721 未加载
评论 #27686725 未加载
jll29almost 4 years ago
Favorite quote: &quot;(...) so that the information security community and the general public can judge the quality of your work, which basically tricks organizations into spending a ton of money for installing Docker into a CentOS image without any cryptographic signature to verify the integrity of that image.&quot;
neatzealmost 4 years ago
My only question is; why such project was connected to the internet at all ?
评论 #27686002 未加载
评论 #27685516 未加载
评论 #27685808 未加载
RcouF1uZ4gsCalmost 4 years ago
&gt; It will drive innovation and reduce operational costs by ensuring much greater reuse of capabilities.<p>I feel I have seen this vague promise on a lot of software projects that either failed or overran budget significantly.
评论 #27686092 未加载
edualmost 4 years ago
An interesting data point is that Everis is owned (2014 acquisition) by NTT Data Group [1], it provides consulting and outsourcing services and it doesn&#x27;t have the greatest reputation<p>1. <a href="https:&#x2F;&#x2F;www.everis.com&#x2F;global&#x2F;en&#x2F;about-us" rel="nofollow">https:&#x2F;&#x2F;www.everis.com&#x2F;global&#x2F;en&#x2F;about-us</a>
Aeolunalmost 4 years ago
Not that I think internal efforts are always success stories, but outsourcing your identity and access management to the lowest bidder sounds like a recipe for disaster.<p>Who thought this would be a good idea? And why was any of this on internet connected servers anyway?
评论 #27686218 未加载
cpachalmost 4 years ago
Does anyone know if there are other sources that can confirm the breach?
评论 #27685582 未加载
devetecalmost 4 years ago
Distributed Denial of Secrets, you&#x27;ve done it again!
评论 #27684330 未加载
alexfromapexalmost 4 years ago
How was it breached and what’s the fall out?
randombits0almost 4 years ago
How’s that Zero Trust working out for ya?
评论 #27683894 未加载
评论 #27683739 未加载
评论 #27684904 未加载
评论 #27686920 未加载
评论 #27685313 未加载