Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

211–220 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#211
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

> the attackers where highly sophisticated and had the resources of a nation state

Also, the attack was carefully crafted. How could anyone expect or defend against a carefully crafted attack, by a nation state no less.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#212

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention.

Automatic updates are RCE vulnerabilities.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#213

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

Interesting that they're called SolarWinds. They make netflow analysis tools... kinda like Stellar Wind.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#214

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

curios as to how Russian hackers slipped their software into solar winds. sounds like a major breach.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#215
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

Maybe someone with more familiarity on the topic can chime in, but I don't think it's the effective PR move you think it is. Nobody, I think, actually cares who from a blame perspective.

The idea that there's face saving to be had by blaming it on someone sophisticated just doesn't ring true to me. It still happened, the details specifically about who and how don't make your board, your boss, or Wall St. care.

It's way more relevant how you react to the breach, than it is that the breach took place.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#216
It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted computers in the world have repeatedly been hacked. And even if you could make a secure computer, people can not be trusted because there is always some way to compromise them. Maybe the best we'll ever be able to do is assume a system will eventually be compromised and concentrate on minimizing damage and fast recovery. Removing the incentive to compromise computers could be a solution, but that seems even less likely given our million year history.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#217
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

It's easier to get congress to pump the relevant parts of the military industrial complex with $$$ when it's "cyber warfare" too.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#218
post #175

Earlier quoted context omitted.

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly.

There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does when it finds out it has published false information, and its track record of making sure what it publishes as news is accurate, or corrected when discovered to be false.

As a overly generic rule, trust (or don't) the Institution over the individuals.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#219
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured."

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#220
post #212

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention. Automatic updates are RCE vulnerabilities.

In this case, it doesn't appear to me that having the update be a manual process would have made it any easier to detect.
Post reply on HN