Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

61–70 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#61
post #48

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in:

Encryption: Yes.

Multi-factor authentication: Yes.

Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No.

There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "do not approve". You don't get any input information for making this decision.

Hacking this is trivial. If you know someone's password, you just have to occasionally try logging in. Eventually the user will accidentally click approve even though they didn't trigger the authentication.

You'd assume that nobody would ever fall for something like this, because surely nobody would be so stupid as to approve an MFA prompt they didn't trigger.

Meanwhile, my Microsoft Authenticator app triggers randomly about 5-10 times per day because every single MS app insists on "reauthenticating" me every 24 hours. So I'll be sitting at my desk and my phone will pop it up randomly. I'll look up, and sure enough, Teams wants me to re-MFA for some stupid reason.

I'm paranoid enough that I'll always reject these MFA prompts and then start the login cycle manually, but most people would just peck the button like a trained bird.

Similarly, I've run scripts before that needed 6 MFA prompts to complete (don't ask). I ran the script once and it asked 7 times... uh-oh. Is this an Azure bug, or a hacker from China? How could I possibly know?! The information is not provided to me!

This is Microsoft's fault, 110%, and I dare anyone here to argue otherwise.

So instead of reaching for the downvote button, make your case on how "yes, yes, yes, yes" is not a security disaster below in the comments please.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#63
post #48

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

Your assuming they had mfa enabled!

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#65

Earlier quoted context omitted.

I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.

Don’t they usually have “styles” of intrusion? I’m certain I’ve read in the past where intelligence agencies could differentiate between Russian backed styles of hacking and Chinese backed styles of hacking. I’m sure Americans have their own style of hacking as well. I would say it’s also quite likely that the US knows who did this or has known who has been doing it for a while. It’s highly unlikely that this press r…

If there are such styles of exploit, which means it’s public knowledge, sounds like a great way to cover your tracks then. Just make it look like the other person.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#66

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

There was a guy called "Edward Snowden" who revealed a bunch of offensive cyber operations a while back. You may have heard of him.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#67
If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their password, no?

And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected?

Does Microsoft implement traffic monitoring for high-value clients?

Or do sophisticated organizations embed tracking pixels in emails to see what clients load them, and then check that those are authorized clients?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#69
post #23

It's always a nation state. A great way to increase defence budgets and not have to admit incompetence.

I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…

I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS and the public domain. The Snowden NSA leaks, although ancient history at this point, confirmed a lot of this for me. The only exception would be where the government can flex muscle in low tech applications they can throw money or legal resources at (MiTM/interception, obsolete tech like SCADA) but otherwise I’ve never been been impressed.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#70

Good thing we have Christopher Krebs, director of the Homeland Security Department's Cybersecurity and Infrastructure Security Agency, on the job......Oh,wait,, Trump fired the guy responsible for defending against just such at attack? Brilliant.

yes this is trumps fault

"The buck stops elsewhere".
Post reply on HN