Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

81–90 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#82
It seems like this incident has impacted not only the U.S. Treasury, but other U.S. government agencies.

The Washington Post also stipulates that the group behind it also hacked FireEye [1].

Makes me wonder if the TTP used for this attack is similar to the FireEye breach (if of course it really was APT29 behind both attacks).

Edit: Reuters reporter Chris Bing says he is hearing the way FireEye got hacked is similar to these government agencies [2].

[1]: https://www.washingtonpost.com/national-security/russian-gov...

[2]: https://twitter.com/Bing_Chris/status/1338233592347045892

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#83
post #53
post #41

Earlier quoted context omitted.

Nation-state prevents confusing with lower level states. State is the more appropriate term, but it would cause a lot of confusion in the US.

Could just use "country".

Nation State suggests the nations government. If you just say country it might suggest organized crime or other randos from that country.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#84

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

Yes. Stuxnet being the most famous which brought this to more daylight -'cat out of the bag.' Trump admin also did a press push after changing policy to ramp up digital offense [1]. Notably these stories were obviously is coordinated and on purpose. e.g. not just someone leaker talking to reporter it was strategy. [1] https://www.nbcnews.com/politics/national-security/under-tru...

That push was actually interesting, since they were intentionally being open about their cyber capabilities. They also had a "press tour" about how they hacked ISIS [0]. There's clearly some mind games going on by showing your hand like that.

[0] https://www.npr.org/2019/09/26/763545811/how-the-u-s-hacked-...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#85

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

> Iran and Russia Or Israel. Israel is the nation state that has subverted the US govt more than any other.

Yeah but Israel isn’t in the intersection of usual subjects and countries that aren’t nation states.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#86

Earlier quoted context omitted.

Comptia's Security+ exam refers to countries as "nation states" when it talks about government entities targeting businesses or other governments, and that nomenclature has become commonplace. Sec+ is also a requirement for a lot of government related computer work, so it's not surprising that the guy they interviewed used the term.

Just because an attack originated in a certain place does not mean it was supported by a nation state. For some reason it seems like a large number of security folks don’t understand this. I know lots of intelligent Russian engineers who could easily break into US corporate or government systems or orchestrate a DDoS attack. And if they chose to do so there would be zero legal consequences since they live in Russia a…

Yes, I don't understand why you would assume government backing, but you don't know which government. If you don't know who it is, it could be anybody.

I think people use Nation-State to suggest that they are not so incompetent that some random hacker could get access.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#87

If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their password, no? And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected? Does Microsoft implement traffic monitoring for high-value clients? Or do sophisticated organizations embed tracking pixels in emails to see what clie…

Yes, I’m quite certain they can/do, as it is a requirement for FedRAMP.

However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#88
post #47

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…

Nation-state: a sovereign state whose citizens or subjects are relatively homogeneous in factors such as language or common descent.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#90
post #47

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…

I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.
Post reply on HN