Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

101–110 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#102
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

I like how when the downvoted messages start to fade away until they say [flagged] and vanish. The creators of the site were only looking for what’s popular because, you know, they’re VC.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#103

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

Maybe they suspect Californians?

https://www.bnnbloomberg.ca/gavin-newsom-declares-california...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#104
post #68

The "have been hacked by" scale seems to have two settings: 0. Forgot to secure access with password. 100. Nation state.

Or G. Social Engineering.

"Ah yes we are from IT and found suspicious behavior, we need to reset your password, can you provide it immediately? No? Okay well we will be contacting your manager immediately for insubordination. You may want to gather your belongings.

Ok, any capital letters?"

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#105
post #47

Earlier quoted context omitted.

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…

I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.

Hahaha our military can't even figure out boots for the troops, you think we can hack the US Government?

As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence.

We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#106

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

How is it not Microsoft's fault if they don't provide the user with any information to decide whether the MFA request is legit?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#107
post #52

Earlier quoted context omitted.

I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.

Some of it is based on analysis of the actors motives - if you have 0-day works on fully patched Office 365, that took months/years to work, and throw it at a US government agency, you're clearly not in it for the money, _and_ you have no qualms about blowing your exploit.

Well if you are targeting Treasury it could be to act on information not yet made public in the stock market.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#108
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

[deleted]

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#109
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

Would MFA have prevented this from happening?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#110

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

Imagine if an automobile manufacturer allowed you to configure the safety features of your car and had the defaults set to unsafe but convenient values to help sell vehicles... do you think the manufacturers should evade liability?
Post reply on HN