Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

161–170 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#161
post #149
post #96

Earlier quoted context omitted.

Russian state media taking a victory lap, I see

Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.

So the person posting Russian State propaganda isn't the problem, I am for pointing out the uselessness of citing their work.

Gotcha.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#162
All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems.

Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simple firewall appliance. The absolute minimum set of configuration options, the simplest possible hardware architecture; something you could actually trust with your life. Right now I have zero confidence that any of the commercially available security appliances are actually secure against nation-states.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#163
The hack involved the creation of counterfeit tokens, essentially electronic indicators that provide an assurance to Microsoft or Google about the identity of the computer system its email systems are talking to. By using a flaw that is extraordinarily difficult to detect, the hackers were able to trick the system and gain access.

Source: https://www.nytimes.com/2020/12/13/us/politics/russian-hacke...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#164
post #144

Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.

For me it’s usually complaining about what the fuck shit they have done to outlook. It’s like a train in Mumbai at rush hour these days.

Could you expand on that?

We're moving to 365 and I'd like to know what f*ckery to expect. =(

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#165
post #144

Earlier quoted context omitted.

For me it’s usually complaining about what the fuck shit they have done to outlook. It’s like a train in Mumbai at rush hour these days.

Could you expand on that? We're moving to 365 and I'd like to know what f*ckery to expect. =(

Just generally they spent the last 10 years cramming so much crap into the outlook desktop client that it’s horrible to use. The web client is better than the desktop one now.

Rest of office is pretty good. Do not worry about this. It works well.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#168
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

Who would be trusted to design and procure the hardware for such a device?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#169
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

> I'm paranoid enough that I'll always reject these MFA prompts and then start the login cycle manually, but most people would just peck the button like a trained bird. Similarly, I've run scripts before that needed 6 MFA prompts to complete (don't ask). I ran the script once and it asked 7 times... uh-oh. Is this an Azure bug, or a hacker from China? How could I possibly know?! The information is not provided to me!

I'm just glad I'm not the only one who sees this as a problem.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#170
post #160

Earlier quoted context omitted.

Yes, I’m quite certain they can/do, as it is a requirement for FedRAMP. However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).

Don't confuse the .gov DNS/email domain and network monitoring tools like Einstein. The brave new world of govt cloud computing use makes this not as straight forward as it might have been 10 years ago.

That’s a good point and one I had thought of afterwards. That being said, I have to imagine there is some kind of perimeter established, which cloud providers would exist within (at least the FedRAMP accredited segments).

Then again, I have seen crazier things and sometimes government takes quite a while to catch up with technology implementations.

Post reply on HN