Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

41–50 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#41

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

Nation-state prevents confusing with lower level states. State is the more appropriate term, but it would cause a lot of confusion in the US.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#42
post #35

"monitoring internal email traffic at the U.S. Treasury Department _and_ an agency that decides internet and telecommunications policy" That's an interesting way of saying a U.S. organization. Does this mean the NSA? I would have assumed they were talking about the FCC, but why not name them?

The article mentions that the other organization is the National Telecommunications and Information Administration (NTIA).

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#43
post #35

"monitoring internal email traffic at the U.S. Treasury Department _and_ an agency that decides internet and telecommunications policy" That's an interesting way of saying a U.S. organization. Does this mean the NSA? I would have assumed they were talking about the FCC, but why not name them?

No, the NTIA. It was probably described that way because most people wouldn't recognize the agency or acronym.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#44

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

Comptia's Security+ exam refers to countries as "nation states" when it talks about government entities targeting businesses or other governments, and that nomenclature has become commonplace.

Sec+ is also a requirement for a lot of government related computer work, so it's not surprising that the guy they interviewed used the term.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#45
post #35

"monitoring internal email traffic at the U.S. Treasury Department _and_ an agency that decides internet and telecommunications policy" That's an interesting way of saying a U.S. organization. Does this mean the NSA? I would have assumed they were talking about the FCC, but why not name them?

It’s mentioned further down

> Treasury and the Commerce Department’s National Telecommunications and Information Administration

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#46
post #43
post #35

"monitoring internal email traffic at the U.S. Treasury Department _and_ an agency that decides internet and telecommunications policy" That's an interesting way of saying a U.S. organization. Does this mean the NSA? I would have assumed they were talking about the FCC, but why not name them?

No, the NTIA. It was probably described that way because most people wouldn't recognize the agency or acronym.

For anyone who's not familiar, the NTIA is basically the FCC for the federal government itself. They allocate spectrum, create policy, etc.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#47

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to those that are threats. In addition to your two examples, China certainly doesn't qualify either, which basically just leaves North Korea.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#48

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

>"able to trick the Microsoft platform’s authentication"

So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#49
post #31

Earlier quoted context omitted.

All nations do. It's become very normal. On the surface relations are nice and respectful. But we even spy on our allies behind closed doors. Take the case of Germany, that became public knowledge because of wikileaks. We had Angela Merkel's office wiretapped, among other things[1]. After it became known, they hardly responded past some internal investigations. I think their Senate switched to storing documents offli…

This is actually pretty fucked up

It's just business.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#50

It's always a nation state. A great way to increase defence budgets and not have to admit incompetence.

Key fact of government is that it NEVER fails, NEVER.

It always just a matter of spending a few more billions in tax payer money, you see the program/agency/task/what ever would have work perfectly if we just spend more money

Post reply on HN