Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

231–240 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#231
post #229

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

I believe it was an insider. I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.

The said it involved a manual supply chain breach. Sounds like an insider with a USB drive.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#232
post #212

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention. Automatic updates are RCE vulnerabilities.

To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#233
post #223

I wonder why more attacks are not attributed to businesses. They have lots of resources and would benefit from attacking government agencies and competitors.

A salaried employee has absolutely zero incentive to take on that risk unless ordered, and the same would go for whoever ordered them, so it just doesn't really happen. Companies would love it, but at the end of the day people just don't take risks like that when they could simply choose not to and likely be just fine.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#234
With all of the outrage being expressed from those in media and government about the dangers of free speech because of the potential for "disinformation", it would be nice if everyone took a step back and examined how this report is being discussed.

We're under attack by the Russians(again), according to anonymous sources(again) that are purportedly government officials. Where is the skepticism? Are we simply to, yet again, blindly accept evidence-free assertions made by anonymous government officials? As technically literate people know, it can be very difficult, if not impossible to determine who exactly intruded into a network, even in the best of circumstances. As historically literate people know, evidence-free government assertions of attacks by our "enemies" are often baseless, deliberately misleading, or outright fabrications.

The Treasury may very well have been hacked, and the culprits may have been Russians, but its madness to believe any of this without evidence that be scrutinized. There's been a lot of recent outcry for "gatekeepers" that sift through disinformation and decide what people are allowed to see and hear. As illustrated with this article(and the reception it has received), the problem isn't the existence of evidence-free assertions, its the uncritical acceptance of these evidence-free assertions. We need to maintain our skepticism and maintain the same demands for evidence regardless of what assertions are offered or who they are offered by. Lies and unsubstantiated statements are just as bad (if not worse) whether they come stamped with the approval of officially designated gatekeepers or not.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#235

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

Yeah I had friends in college that did this kind of thing for fun.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#236
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

This stuff doesn't have to be complicated. Large organizations should have an internal CA to handle authentication and it should be a policy to use any other method.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#237

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

This is obvious not good, but just to note, when they say "the Office of the President of the United States", they're most likely referring to the Executive Office of the President (EOP), which consists of a few thousand employee, most of whom are non-partisan career civil servants. It's a much broader group than what it sounds like.

https://en.wikipedia.org/wiki/Executive_Office_of_the_Presid...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#238

Earlier quoted context omitted.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

I was the target of one of these during a recent internal pen test and got caught in it, despite being very technically savvy and aware of “normal” phishing techniques. The attack that was simulated in my case utilized convincing social engineering, spear phishing, domain spoofing, and malicious OAuth apps meant to look like an internal resource/service to gain access to sensitive material. It was very sophisticated…

Organizations that are serious about security should not allow random OAuth apps. Both G Suite and O365 admins can restrict what OAuth apps are allowed.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#239

Earlier quoted context omitted.

curios as to how Russian hackers slipped their software into solar winds. sounds like a major breach.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

Looks like LinkedIn is a big security concern, I won't miss it. Imagine if companies require that you're ~not~ on it.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#240

Earlier quoted context omitted.

Right. There are situations where we can see that the only apparent way to do something needed very considerable resources, which suggests a state actor. Equation Group is presumed to be (a front for) the NSA. It forged a (code signing) certificate that otherwise shouldn't exist, using an MD5 collision. But not the MD5 collision painfully created by researchers a little earlier to demonstrate that MD5 was vulnerable,…

Didn't Dan Kaminsky and others have tools to produce nearly arbitray collisions by the early 2000s?

Perhaps? I can't find any evidence easily that Dan did have such tool, but "by the early 2000s" it's not at all unthinkable certainly. If you have a link that'd be great.

However the trouble is MD5 collision isn't like that hilarious "Send all zeroes" Microsoft bug from a few weeks back where you just try it a few times then it works because someone was very stupid - the MD5 collision is pretty hard, the Merkle–Damgård construction actually works, your attack avenue is hammering on the compression function, everything else in MD5 (and any other Merkle–Damgård construction) works because of mathematics unless you can break that compression function - so having a program that when you run it spits out an MD5 collision with your preferred shape is great, it's a cryptographic breakthrough - but maybe it'll take 5000 years to run on a typical home PC. If you're a government or a big crime boss then money turns that into 5 days or (if you've enough of it) 5 hours instead, but if you're a bored teenager or small time crook not so much.

And like I said, Flame depends on a never before seen collision, so it isn't like they just re-used work somebody else had done.

Post reply on HN