Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

111–120 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#111
post #102

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

I like how when the downvoted messages start to fade away until they say [flagged] and vanish. The creators of the site were only looking for what’s popular because, you know, they’re VC.

I like when people complain about HN without understanding how it works.

Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#112

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

"Nation state" was a standard term in school going all the way back to fifth-grade Social Studies class.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#113

Earlier quoted context omitted.

'Foreign government.'

Also a problem with many places. Think about Pakistan, where the military is not the government per se, but has the resources. “Nation state adversary” says something without saying it.

> Pakistan, where the military is not the government per se,

A distinction without a difference? I don't know a whole lot about Pakistan, but that's the way it seems to me.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#114
post #109
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

Would MFA have prevented this from happening?

Unsure the user did not have it enabled.

Edit:: Another commenter in this thread indicated MFA did Not protect them.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#115

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

All nations do. It's become very normal. On the surface relations are nice and respectful. But we even spy on our allies behind closed doors. Take the case of Germany, that became public knowledge because of wikileaks. We had Angela Merkel's office wiretapped, among other things[1]. After it became known, they hardly responded past some internal investigations. I think their Senate switched to storing documents offli…

Some does, some don't, is not a new normal, is mostly for power players. But anyway, none is even near at the scale and reach of what the US does. And for most of it they don't even need to hack, just handle a request for the customers data to any US based service (ask Lavabit about that).

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#117
post #68

The "have been hacked by" scale seems to have two settings: 0. Forgot to secure access with password. 100. Nation state.

I’m so glad to see more immediate skepticism now.

I really dislike how deflection pretty much absolved the actual hacker of any scrutiny or liability.

Its like the old bugs bunny cartoons where the hacker - bugs bunny - puts on a disguise and says “he went that way”

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#118

Does the US conduct offensive cyber operations like this? I feel like we never hear about them in the news.

Trust me, you will not hear about them. Also, when the US government detects it's been infiltrated, it's also rare to hear about it. That's why whenever you see articles like this that make attribution, I recommend viewing them with skepticism, simply because the information is specifically selected.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#120
post #102

Earlier quoted context omitted.

I like how when the downvoted messages start to fade away until they say [flagged] and vanish. The creators of the site were only looking for what’s popular because, you know, they’re VC.

I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site
Post reply on HN