Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[deleted]


[deleted]


Ha! ... quick turn around by Fortune, http://fortune.com/2016/06/18/palantir-hack-buzzfeed/

Bizarre to watch a company move like that ... a bit unnerving in an Enders-Game sort of way. Information manipulation, and suddenly you wonder who's wagging the dog.


Before I read the Fortune article, their remarks were pretty much my initial reaction to the article. Any company that hires sufficiently good pentesters is going to get breached, even an infosec company. I would bet NSA probably does pretty poorly, even to this day, on their annual pentests.

This isn't really news. A company that successfully fends off multiple independent pentests would be news. I've worked for a company that actually did quite well on one pentest, but the testers were pretty terrible.


You haven't actually commented on the actual content of the Buzzfeed article or the Fortune article, but instead have decided to go the route of putting forth FUD about sockpuppets and media manipulation.


[deleted]


How do you know Buzzfeed's source isn't a competitor with an axe to grind? You don't. So this almost-unfalsifiable FUD is useless.


[deleted]


How do you know Buzzfeed's source isn't a disgruntled employee with an axe to grind? So this almost-unfalsifiable FUD is useless.


Except that the Fortune article has the benefit of being 100% correct.


It's like a scene out of a Silicon Valley episode.


> Palantir does an incredibly comprehensive job with PR and damage control

Those are just two more aspects of controlling information.


> the assertion here is that Palantir being unable to defend its own networks against a fairly rudimentary and mundane attack throws its entire business offering around cybersecurity into question

I think you're right. I would imagine this will prompt some tough questions both within their existing customer franchise and in pitches for new business.

Here's how Palantir describe their company cybersecurity platform on their own website[0]:

> With Palantir, your enterprise can finally detect advanced threats that lie hidden within your data. All of it. Structured network logs from proxy to IDS, VPN, anti-virus, DLP, DNS queries, malware tools, and application logs. Contextual data like email, print logs, facility access logs, internal chat logs, and human resources data. Open source and third party data. Our technology integrates it all into a single environment, and separates actionable signal from the noise so you can protect your network.

So the obvious question if you're the CEO or CISO of a company that does or is considering doing business with Palantir is, "You guys have unfettered access to your own network -- you can deploy your own cyber solutions without any restraints whatsoever. And yet you couldn't detect these intruders on your own system?"

Importantly, I'm not sure this would be a fair criticism -- it sounds like the white hat hackers they hired were very very good at covering their tracks -- but there's no doubt this leak is going to result in some tough conversations.

[0]: https://www.palantir.com/solutions/cyber/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: