The hack involved the creation of counterfeit tokens, essentially electronic indicators that provide an assurance to Microsoft or Google about the identity of the computer system its email systems are talking to. By using a flaw that is extraordinarily difficult to detect, the hackers were able to trick the system and gain access. Source: https://www.nytimes.com/2020/12/13/us/politics/russian-hacke...
U.S. Treasury breached by hackers backed by foreign government – sources
171–180 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#172Re: U.S. Treasury breached by hackers backed by foreign government – sources
#173Has anyone ever said they were hacked by a group of unsophisticated group of script kiddies?
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#174All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…
Who would be trusted to design and procure the hardware for such a device?
Maybe layers? For government agencies, the government could manage procurement.
For non-government organizations, realistically, maybe some sort of public-private/foundation partnership, if the NSA is willing to bend a little. Which at this point might be in their best interest.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#175I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…
WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...
I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and how solid these claims are.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#176All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…
Source: Am Sr. Systems Engineer.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#177Seems like a commonality between the two that happened recently (2 weeks ago for us).
This is just an observation, nothing more. I'm sure MSFT spends a fortune on securing that platform (among other things).
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#178All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#179Earlier quoted context omitted.
WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...
I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#180Everytime I hear about Office 365, it's always with respect to some vulnerability or downtime.
That might also be a bias because very few companies or organizations use things like open office (or the google suite for that matter) so there would be fewer people interested in attacking those software suites. Also it’s more fun to report on bad stuff that happens to Microsoft then and stuff that happens to some relatively small and unknown software company.
0: https://office365itpros.com/2020/10/28/teams-115-million-use....
1: https://www.axios.com/google-g-suite-total-users-9a6d3df6-c9...