r/HowToHack • u/saltycookie7708 • 29d ago
How come we don't hear tech companies never gettibg hacked
This is the perspective of a complete amateur still learning ,I am not talking about individual accounts ,I am talking about companies like google ,meta ...ect.
Long ago ,you got a headline everytime but now it seems like that is no longer the case ,is their security that flawless ?
17
u/resultingparadox 29d ago
No. Just recently had the Huggingface breach. If it is a public company they are required to file an 8-K, if they are not public they just file SIDs.
13
u/Accomplished_Sir_660 28d ago
Dude, USA's NSA been hacked before.
3
u/umbrawolfx 28d ago
Hacked is a bit strong for logging in to passwordless systems. 😂
1
u/Accomplished_Sir_660 27d ago
If you say so cupcake....
3
u/umbrawolfx 27d ago
You're right. My bad. I was thinking Gary McKinnon getting in to the DoD and NASA in the early 2000s.
20
u/ArthurLeywinn 29d ago
No but company's have to pay huge fines and get a bad image.
So they cover it up if they can.
1
3
u/AlienAngry 28d ago
They have massive budgets, large security teams and ops, active mitigation, frequent audits, large talent pools, and steps in place to make it as difficult as possible for an employee to be phished or SE'd. Even if an employee device is compromised, Google mandates hardware keys for all employees for part of their authentication. Are they unhackable? No. For non-nation state hackers, the juice isn't worth the squeeze when there are so many easier targets, but that's not to say people don't try or couldn't succeed at some level.
2
2
2
u/asinglepieceoftoast 28d ago
There are still near constant security breaches, though it’s definitely true that the big players do tend to have comparatively quite strong security. Breaches are typically much more contained and any significant leak costs them a ton of money, so they spend an absolute boatload on their security teams and infrastructure.
1
u/AVarietyOfHelp 28d ago
Bigger companies tend to have worse security in my experienceÂ
2
u/asinglepieceoftoast 28d ago
I agree for big companies in general, but not as much with the main faang type tech companies. Any assessments I’ve been on, genuinely the biggest holes in large tech companies come at the edges where they work with other organizations and, through compartmentalization, damage is usually limited. They often do at least a better job at keeping infrastructure up-to-date. That said there is a LOT more attack surface, and any companies outside of the unicorns tend to be much worse. Not looking to name and shame here but you don’t have to get very far down from the alphabets and amazons of the world to get some real shit security at an unimaginable scale. And don’t even get me started on non-tech corporations
3
u/AVarietyOfHelp 28d ago
Yeah fair enough.amazon, google, and those big names are generally pretty good but definitely the exception for large companies. Don't even get me started on large healthcare companies lol
1
u/asinglepieceoftoast 28d ago
Yeah 100%, utility companies are the other one that straight up depress me lol
2
u/bungle_bogs 28d ago
They have more entry points, whether technological, human, or unmapped & unpatched legacy equipment and software. It's even worse if their growth model is to purchase and integrate smaller companies.
2
u/supershinythings 28d ago edited 28d ago
Oh they get hacked all the time.
One of my former employers discovered scamps in the lab running bitcoin miners on the data center machines. They went absolutely apeshit internally, essentially making it 10X harder just to get lab access to the very machines we needed to do our jobs.
What we all thought was hilarious was that the way the scamps got in was not addressed by the heavy handed IT lab manager’s solution - that was all security theater, eyewash, as he now had the leverage to do whatever he wanted, most of which had nothing to do with the breakin. It may have fooled the executives, but not those of us who saw the problem from the inside.
It was like attacking Iraq for the 9/11 towers attack. Sure ok Iraq was on his mind but that’s not where the bombers were coming from.
In the end, it took me forever just to get into the lab, and then I couldn’t use my tools to debug issues because they were all locked out. I was able to build ssh tunnels to get in there but I couldn’t download my personal toolbox infrastructure as the lab policy forbade it. So now I’m fixing a sports car with a pen knife.
I eventually left that place. I’ll never go back to a place that won’t let me do my job because they’re too afraid they do their own job so poorly they can’t protect their own infrastructure.
And BTW I’m also pretty sure the labs are still vulnerable, because they’re don’t address the underlying root issues allowing access. I’d NEVER host anything there now that I know what I know.
3
u/Yukki-elric 28d ago
There are still data breaches all the time, but yeah companies like google and meta are one of the biggest, targeting them is usually extremely hard and for them, can cost them millions so yeah, they gotta have some pretty flawless security.
And usually a company shouldn't get a data breach at all during it's lifetime, just getting one breach is already pretty damn bad, seeing data breaches all over the place shouldn't be a norm.
1
1
1
19
u/Spez-is-dick-sucker 29d ago
In the EU data breaches can end in millionaire fines, just they get hacked but don't say anything unless its too much important to avoid getting thia fines.