Earlier quoted context omitted.
I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.
semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site
U.S. Treasury breached by hackers backed by foreign government – sources
131–140 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#132Earlier quoted context omitted.
I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…
I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS a…
...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#133> “This is a nation state,” said a different person briefed on the matter. “We just don’t know which one yet.” So, how do they know then?
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#134Earlier quoted context omitted.
Also a problem with many places. Think about Pakistan, where the military is not the government per se, but has the resources. “Nation state adversary” says something without saying it.
> Pakistan, where the military is not the government per se, A distinction without a difference? I don't know a whole lot about Pakistan, but that's the way it seems to me.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#135"No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out".
I suppose "we think it could be done by a group of two or three teenagers with decent knowledge of wget" doesn't have the same ring to it.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#136Earlier quoted context omitted.
That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.
Imagine if an automobile manufacturer allowed you to configure the safety features of your car and had the defaults set to unsafe but convenient values to help sell vehicles... do you think the manufacturers should evade liability?
Microsoft has billions of users. The security needs of the US Department of Justice are not the same as my mom’s real estate office.
When you use 3rd party IdP, for example, how does Azure MFA know what the app is?
The configuration described was not out of the can. Somebody decided to make it the way it was.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#137Earlier quoted context omitted.
Could be just about anyone. Knowing what USA has done, it seems that even this type activity is standard even between "friendly" governments....
Yup. Jon Pollard, for one. He spied for Israel. Israel certainly has the chops to do something like this, but lots of other "friendly" countries with good geeks wouldn't mind having this kind of info.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#138My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…
Would MFA have prevented this from happening?
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#139Earlier quoted context omitted.
This is actually pretty fucked up
Is it really? Theoretically with perfect information you don't need to go to war, you can just compute the result and start with treaty negotiations.
My dad (a journalist, RIP) was once at a UN conference in the 70s, and made the remark to a Chinese official in a light-hearted spirit: "of course you spy on us, we spy on you, and what's wrong with that?" This caused a major row and he was forced to apologize.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#140Earlier quoted context omitted.
How did you determine that the attacker hijacked the existing O365 session rather than logging in with the phished username and password? For an app like O365, usually that kind of cookie-stealing doesn't happen without malware on a user's computer.
This was about 6-9 months ago and I didn’t lead the postmortem, so to be honest I don’t recall how we determined that. However anecdotal, the user who was compromised is aware enough not to re-enter their credentials outside URL schemes that match our password manager database, and they wouldnt have entered anything. “Oh but how can you trust the user, they clicked a bad link?!”... again this email came from a very r…
Notion.so is popular for phishing pages because it's a "reputable" "enterprise" application that doesn't raise the spam score when it's linked to in an email, can require signing in to view the page which further deters spam filters that actually check the links, and has less robust anti-phishing systems than Google Docs and Sharepoint (which are still used for the same purpose but require more tweaking of the template to avoid being auto-flagged).