Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

201–210 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#201
post #129

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

If your IT department cared, they could disable the app notification MFA method in AAD and force you to either use passwordless or a TOTP code, both of which prevent you from blindly approving a sign-in you aren't involved in.

I ha e to fight tooth and nail to get Toto where I work. The inertia of "but push is eaaasy" is strong.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#202
post #147

Earlier quoted context omitted.

Curious how this is connected at all to my question? I know "America Bad" is trendy now, but I don't see the connection.

Please, this isn't Reddit. The US just happens to be part of the list of bad guys together with Russia, North Korea, Israel, PRC, etc. The difference is that on sites with a lot of US users pointing the finger at the US is more often than not seen as someone being Edgy or whatever while pointing it at Russia is cool/patriotic/stating the facts/etc.

This. Over the past few months I've noticed HN slowly slipping into the reddit-esque, us-centric groupthink in the comments section.

The bias is apparent and I fear the trend is accelerating.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#203
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#205
I find the timing of these reports interesting. They tell a story of a nation state adversary who has been behind our lines for months. If true, I assume we have known, but reporting up the chain and especially to the public has been...prevented. Now is the first calendar time- at the cusp of the electoral college vote- when these reports reaching the public may lead to positive action in response.

If these reports and this surmise bear some resemblence to reality, I look forward also to seeing more reporting about steps and countersteps taken in response to these breaches. The timing for this reporting is too neat to not be intended to spur some stronger response.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#206
So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies.

They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer.

And get this: "SolarWinds says on its website that its customers include most of America’s Fortune 500 companies, all top ten U.S. telecommunications providers, all five branches of the U.S. military, the State Department, the National Security Agency, and the Office of President of the United States". Yikes.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#207

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

curios as to how Russian hackers slipped their software into solar winds. sounds like a major breach.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#208

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

Shit, SolarWinds is how MS does a lot of its electronic software distribution. I've received multiple things from MS SolarWinds download links.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#209

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

My first thought on this was that it was an EvilginX hack, ala https://www.thecloudtechnologist.com/office-365s-mfa-is-vuln...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#210
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

Lack of trust.
Post reply on HN