Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

171–180 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#171

The hack involved the creation of counterfeit tokens, essentially electronic indicators that provide an assurance to Microsoft or Google about the identity of the computer system its email systems are talking to. By using a flaw that is extraordinarily difficult to detect, the hackers were able to trick the system and gain access. Source: https://www.nytimes.com/2020/12/13/us/politics/russian-hacke...

That could refer to anything from an OAuth consent attack (not much more sophisticated and arguably easier than phishing a password but much less likely to be detected because most companies don't know they should be looking for it) to actual exploits against Azure AD or a third-party authentication provider. If the latter, I hope that Microsoft/FireEye decide at some point decide to be transparent about what was possible and how they're going to prevent it from happening again. I have enough doubts about AAD's ability to generate enough forensically useful logs as it is.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#172
post #149
post #96

Earlier quoted context omitted.

Russian state media taking a victory lap, I see

Please leave your Redditor mentality at the door. Nothing good is gained by this kind of commenting.

dang already does an excellent job.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#174
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

Who would be trusted to design and procure the hardware for such a device?

Good question :).

Maybe layers? For government agencies, the government could manage procurement.

For non-government organizations, realistically, maybe some sort of public-private/foundation partnership, if the NSA is willing to bend a little. Which at this point might be in their best interest.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#175
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group?

I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and how solid these claims are.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#176
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

This isn't going to help if the discussed is essentially tunneled through the Nat using legit protocols and traffic to the vulnerable service, where most of the attacks actually happen on the software side. How do you architect a firewall to accurately know if the application layer traffic is legit or not? It might not even be possible to fully implement something like this. Sounds complicated already. There is a reason firewalls are complex because the application landscape is extremely complex.

Source: Am Sr. Systems Engineer.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#177
This is a tangential aside, but the school system our kids are in get "Your credentials have been leaked and should be changed immediately" warning from iOS devices when logging into their Microsoft 365 accounts.

Seems like a commonality between the two that happened recently (2 weeks ago for us).

This is just an observation, nothing more. I'm sure MSFT spends a fortune on securing that platform (among other things).

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#178
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

I agree with the concerns over complexity. That said, I see nothing in the article that indicates that a firewall appliance is the correct countermeasure. Defense in depth is likely what you need (and may ultimately get) here.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#179
post #175

Earlier quoted context omitted.

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

Exacty. And we also know that the NSA/CIA have placed Russian language inside their exploits to frame other countries.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#180

Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.

That might also be a bias because very few companies or organizations use things like open office (or the google suite for that matter) so there would be fewer people interested in attacking those software suites. Also it’s more fun to report on bad stuff that happens to Microsoft then and stuff that happens to some relatively small and unknown software company.

Growth for Google Workspace (previously G Suite) and Office 365 is insane. Office 365 has >258 million paid seats[0], while Google claims they have 2 billion paid seats (or "users")[1]. Soon enough more businesses will be using one of these than those that aren't (as in, those that are using Exchange or another email server).

0: https://office365itpros.com/2020/10/28/teams-115-million-use....

1: https://www.axios.com/google-g-suite-total-users-9a6d3df6-c9...

Post reply on HN