Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

141–150 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#141

Earlier quoted context omitted.

Curious how this is connected at all to my question? I know "America Bad" is trendy now, but I don't see the connection.

Espionage is less aggressive and overt than perpetrating coups in democratic societies.

His question was "does the US conduct cyber espionage", not "does the USA do bad things?"

Let's not let every post about international politics degenerate into a contest about which state is the wickedest.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#142
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

WaPo reporting it is APT29.

https://www.washingtonpost.com/national-security/russian-gov...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#143
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

WaPo is reporting that this and the FireEye breach were via Solarwinds:

> All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity.

https://www.washingtonpost.com/national-security/russian-gov...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#144

Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.

For me it’s usually complaining about what the fuck shit they have done to outlook. It’s like a train in Mumbai at rush hour these days.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#145

Earlier quoted context omitted.

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

How is it not Microsoft's fault if they don't provide the user with any information to decide whether the MFA request is legit?

There's literally no upside to hiding this information.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#146
post #31

Earlier quoted context omitted.

This is actually pretty fucked up

It seems like a fair game to me. You can always protect yourself by investing in cyber-security if you don't want to be spied on. It's not like war where innocent people die and a there's a lot of human suffering. It's just a tech race where the nations doing a good job get a deserved advantage without doing direct damage to the population.

There are hacks that can cause extensive destruction. But it isn't good to talk about them lest we give people ideas.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#147

Earlier quoted context omitted.

The United States has admitted to perpetrating coups to get a us-friendly dictator in otherwise democratic societies: https://www.youtube.com/watch?v=_2khAmMTAjI

Curious how this is connected at all to my question? I know "America Bad" is trendy now, but I don't see the connection.

Please, this isn't Reddit. The US just happens to be part of the list of bad guys together with Russia, North Korea, Israel, PRC, etc. The difference is that on sites with a lot of US users pointing the finger at the US is more often than not seen as someone being Edgy or whatever while pointing it at Russia is cool/patriotic/stating the facts/etc.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#148
post #68

The "have been hacked by" scale seems to have two settings: 0. Forgot to secure access with password. 100. Nation state.

Seems about right, maybe add in 0.1 didn't patch 14-month-old RCE.

Excuse me, sir, all of our IT systems are always patched up to the most recent approved version. It says so right here on this contract.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#149
post #96
post #9

https://sputniknews.com/us/202012131081447209-us-treasury-ha...

Russian state media taking a victory lap, I see

Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#150

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

WaPo is reporting that this and the FireEye breach were via Solarwinds: > All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity. https://www.washingtonpost.com/national-security/russian-gov...

Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984

>SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information

Post reply on HN