Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

51–60 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#51

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

All nations do. It's become very normal. On the surface relations are nice and respectful. But we even spy on our allies behind closed doors. Take the case of Germany, that became public knowledge because of wikileaks. We had Angela Merkel's office wiretapped, among other things[1]. After it became known, they hardly responded past some internal investigations. I think their Senate switched to storing documents offli…

All nations don't.

Some are too poor (take your pick). Others are rich, but small (the Vatican). Most just don't care enough to prioritise it over better things they could be doing.

And then, there are countries that simply consider the US an ally, and consider it morally dubious or practically unpromising to spy on them.

Add this up, and I'd be willing to give at least 10:1 odds it's one of a list of maybe ten suspects, even when adjusted for GDP or population.

As an aside, I'd really be curious why this "everyone does it" is used anytime something like this comes up? Is it just macho "I don't have friends but there are useful idiots that consider themselves my friend" talk? Is it nihilistic/cynical pretentiousness? International whataboutism to defend one's team?

Because it certainly isn't based on any actual data. If you add up offensive hacking by the USA, China, Russia, Israel, and maybe two or three others, you're pretty well done with the full list, but still close to nations short, where is the number of nations that exist.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#52

How do they know it was backed by a foreign government? I would immediately suspect China or North Korea but that seems too obvious and a bit of a setup?

I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.

Some of it is based on analysis of the actors motives - if you have 0-day works on fully patched Office 365, that took months/years to work, and throw it at a US government agency, you're clearly not in it for the money, _and_ you have no qualms about blowing your exploit.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#53
post #41

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

Nation-state prevents confusing with lower level states. State is the more appropriate term, but it would cause a lot of confusion in the US.

Could just use "country".

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#54
post #48

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

Depends on how they do things. Clicking “yes” on a phone wouldn’t be happening at higher trust levels.

If they offload auth to a on-prem or third party IdP (common in big hybrid O365 tenants), there are often different paths, implementation screwups or bugs that let you bypass MFA. Microsoft’s position is “buy Azure AD, Buy M365, Buy ATP” and other paths are poorly tested, or they explicitly tell you to F off.

Also remember that federal agencies are bigger than most fortune 50 companies, are usually global in scope and have lots of collaborations with other agencies and other third parties, and may have independent pockets within the agency. Those friction points are where problems tend to happen!

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#55
Good thing we have Christopher Krebs, director of the Homeland Security Department's Cybersecurity and Infrastructure Security Agency, on the job......Oh,wait,, Trump fired the guy responsible for defending against just such at attack? Brilliant.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#56

Good thing we have Christopher Krebs, director of the Homeland Security Department's Cybersecurity and Infrastructure Security Agency, on the job......Oh,wait,, Trump fired the guy responsible for defending against just such at attack? Brilliant.

yes this is trumps fault

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#57

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

Most large deals (e.g.: aerospace, defence contracts, infrastructure projects) are backed by diplomacy and/or various flavors of espionage.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#59
post #23

Earlier quoted context omitted.

I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…

don't underestimate Putin's greed the very friends who are known to be connected to "private" militias operating in Syria, also own companies making money from all sorts of activities of regular people, like 2% of all regular household transactions goes through their bank etc

the Americans are making billions from raytheon, the Saudi coalition. The Obama administration sold weapons to saudi to kill yemen people.

greed comes worse from the other side.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#60
post #31

Earlier quoted context omitted.

All nations do. It's become very normal. On the surface relations are nice and respectful. But we even spy on our allies behind closed doors. Take the case of Germany, that became public knowledge because of wikileaks. We had Angela Merkel's office wiretapped, among other things[1]. After it became known, they hardly responded past some internal investigations. I think their Senate switched to storing documents offli…

This is actually pretty fucked up

It seems like a fair game to me. You can always protect yourself by investing in cyber-security if you don't want to be spied on.

It's not like war where innocent people die and a there's a lot of human suffering. It's just a tech race where the nations doing a good job get a deserved advantage without doing direct damage to the population.

Post reply on HN