‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).
"Nation state" was a standard term in school going all the way back to fifth-grade Social Studies class.
U.S. Treasury breached by hackers backed by foreign government – sources
151–160 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#152Fortunately no classified information was compromised. All of the Treasury emails just said "brrrrrrr".
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#153Earlier quoted context omitted.
WaPo is reporting that this and the FireEye breach were via Solarwinds: > All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity. https://www.washingtonpost.com/national-security/russian-gov...
Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 >SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#154‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).
But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to not-necessarily-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".
Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#155‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).
I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…
This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation.
But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to non-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".
Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#156Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#157Earlier quoted context omitted.
I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.
semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#158> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…
> I bet it was someone on r/wallstreetbets
Both could be true? ;-)
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#159Re: U.S. Treasury breached by hackers backed by foreign government – sources
#160If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their password, no? And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected? Does Microsoft implement traffic monitoring for high-value clients? Or do sophisticated organizations embed tracking pixels in emails to see what clie…
Yes, I’m quite certain they can/do, as it is a requirement for FedRAMP. However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).