Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

271–280 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#271

Earlier quoted context omitted.

I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS a…

>...obsolete tech like SCADA... ...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...

>>...obsolete tech like SCADA...

>...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...

Wow! 2010 called. They want their ideas about what makes the world go back.[0]

That's just crazy talk. Everyone knows that hardware has been completely deprecated. It's all clouds. Mostly cumulo-nimbus, in fact.

Power plants, chip fabs, heavy machinery, machine tools, factory automation and logistics systems are completely obsolete and never, ever used anymore.

Because there's cloudiness, hardware is just a waste of money and space, which is why we can stack 600MB of js libraries on top of each other so we can have the browser render an opaque 40x40px box.

[0] https://en.wikipedia.org/wiki/Poe%27s_law

(Please refer to the above link reference to resolve any confusion.)

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#272
post #212

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention. Automatic updates are RCE vulnerabilities.

If Windows didn't autoupdate without user intervention, the number of hacks and breaches would be thousands of times higher than it is today. Ordinary people do not update if they're not forced to; it's unpleasant but true.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#273
post #219

Earlier quoted context omitted.

To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured."

>To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured." How so? In fact, competent InfoSec folks will tell you that you should assume that "if you connect a device to the Internet, eventually it will be compromised." That's not to say a device will be compromised, but making such an assumption, given the history of Internet connected devices is an eminently reas…

Extraordinary claims require extraordinary evidence.

But even ordinary claims require ordinary evidence.

The burden of proof is on the claimant, not the defendant. I believe that's the point parent was addressing.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#274

It seems like this incident has impacted not only the U.S. Treasury, but other U.S. government agencies. The Washington Post also stipulates that the group behind it also hacked FireEye [1]. Makes me wonder if the TTP used for this attack is similar to the FireEye breach (if of course it really was APT29 behind both attacks). Edit: Reuters reporter Chris Bing says he is hearing the way FireEye got hacked is similar t…

Here’s the FireEye write up: https://www.fireeye.com/blog/threat-research/2020/12/evasive...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#277
post #222

Earlier quoted context omitted.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

Or become employed there and go for the long con. How many companies check in go vendor code or pip install from CI? Ripe targets for abuse

Where I work we forbid this kind of behavior but you would not believe the kind of pushback we get for "making things too difficult".

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#278

Earlier quoted context omitted.

>To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured." How so? In fact, competent InfoSec folks will tell you that you should assume that "if you connect a device to the Internet, eventually it will be compromised." That's not to say a device will be compromised, but making such an assumption, given the history of Internet connected devices is an eminently reas…

Extraordinary claims require extraordinary evidence. But even ordinary claims require ordinary evidence. The burden of proof is on the claimant, not the defendant. I believe that's the point parent was addressing.

>The burden of proof is on the claimant, not the defendant. I believe that's the point parent was addressing.

Absolutely. I was pointing out that in this specific case (whether or not devices connected to the internet can be secured), the converse is also true.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#279
FireEye describes:

> "Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website, including hxxps://downloads.solarwinds[.]com/...

So does this mean that the attacker masqueraded as SolarWinds and somehow (brute force?) forged the signature? Or that the attacker had agents working at SolarWinds?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#280

To quote a Heavy Metal Icon: "Peace sells, but who is buying?" Let's start a war, based on this "hack"!

"Ramstein Air Base in Germany Experiences Potential Incoming Missile Scare"

https://news.ycombinator.com/item?id=25409459

Seems some are interested in keeping the populace scared. Wonder what scare tomorrow will bring.

Post reply on HN