Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

151–160 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#151

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

"Nation state" was a standard term in school going all the way back to fifth-grade Social Studies class.

[deleted]

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#153
post #150

Earlier quoted context omitted.

WaPo is reporting that this and the FireEye breach were via Solarwinds: > All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity. https://www.washingtonpost.com/national-security/russian-gov...

Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 >SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information

Not knowing anything about this, this could be a good guess. Folks likely jumping the gun blaming a MS vuln above, when the real breach was via SolarWinds and then they were able to spoof/takeover some Active Directory server inside the network or something such thus gaining access to MS 365 emails etc.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#154

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation.

But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to not-necessarily-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".

Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#155
post #47

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…

Copying my reply to GP:

This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation.

But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to non-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".

Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#156

Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.

That might also be a bias because very few companies or organizations use things like open office (or the google suite for that matter) so there would be fewer people interested in attacking those software suites. Also it’s more fun to report on bad stuff that happens to Microsoft then and stuff that happens to some relatively small and unknown software company.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#157
post #120

Earlier quoted context omitted.

I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site

True, and (in my opinion) improper. But users can vouch for comments that are improperly flagged. If you see it happening, don't gripe, fix it.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#158

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

>> “This is a nation state,”

> I bet it was someone on r/wallstreetbets

Both could be true? ;-)

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#160

If this is really an exploit of Microsoft's authentication services, then who knows what all got hacked. More likely, a Treasury IT admin got phished for their password, no? And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected? Does Microsoft implement traffic monitoring for high-value clients? Or do sophisticated organizations embed tracking pixels in emails to see what clie…

Yes, I’m quite certain they can/do, as it is a requirement for FedRAMP. However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).

Don't confuse the .gov DNS/email domain and network monitoring tools like Einstein. The brave new world of govt cloud computing use makes this not as straight forward as it might have been 10 years ago.
Post reply on HN