Hacker News new | past | comments | ask | show | jobs | submit login

From their official blog post:

> Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities.

I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?




Very few companies will publicly attribute attacks to a specific government - both because it is hard and because of potential political blowback.

I would confidently say that the top 50 countries by GDP have a solid offensive capability. Some, like Japan, have very specific interests that don't align with what makes the news.

At some point you start getting in to the territory of Hacking Team, NSO Group, Gamma, VASTech, etc. Effectively combining the resources of many smaller governments in to a for-hire enterprise that can provide near-nation-state capabilities.

Here is a list of well known attributions of groups to get you started: https://docs.google.com/spreadsheets/u/1/d/1H9_xaxQHpWaa4O_S...


Thanks. Any more info on the Japanese stuff you mention? I don't often hear about that (as you state)


IANASecurityExpert. Claiming that an adversary is a state actor seems as much about magnifying the threat as a genuine finding. A high school kid exploiting their weaknesses will obviously leave them red faced. Seems like an natural position to take for anyone hacked.

Not saying it didn't happen, but it looks like it has become the goto defense in recent times.


Bluffing would be very risky, if turned out the attacker really was a high school kid, or the exploit was trivial. I am inclined to believe them.


Probably anyone else in the Five Eyes, especially the UK.


Iran is pretty good, maybe North Korea too. Countries like Netherlands, Germany, France, UK and similar must have programs in place too.


Why would ant victim conclude anything else? You can't prove them wrong and this is what anyone trying to CYA would say.


I'd say that those listed here:

https://ctftime.org/

so usa, russia, china, poland, ukraine, japan.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: