Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

281–290 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#281
post #229

Earlier quoted context omitted.

I believe it was an insider. I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.

I believe not everyone always checks the checksums. "Never ascribe to malice that which is adequately explained by incompetence"

I'm sure malicious people are very grateful that this platitude is in circulation.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#282
post #241

Earlier quoted context omitted.

>It's time to admit that computers connected to the internet can not be secured. That ship sailed a long time ago. It was normal back in the 1990s for InfoSec folk to assume that "if it's connected to the Internet, eventually, it will be compromised." The goal (then, as now) is to implement layered (defense-in-depth) mechanisms to deter such activities -- at perimeters, network and systems infrastructure platforms an…

True. However, now that APT tools have been leaked to the world I think I can still argue that even layered defenses are no longer sufficient. I listened to security researchers say for years that there was no point in trying to address APT's because they were just impossible to stop. Now APT methods are public knowledge and being used in common attacks. Some types of APT attacks are still too costly to be widely use…

>True. However, now that APT tools have been leaked to the world I think I can still argue that even layered defenses are no longer sufficient. I listened to security researchers say for years that there was no point in trying to address APT's because they were just impossible to stop.

Perhaps I'm a little dense, but I'm not sure what you're arguing here.

Are you asserting that since sophisticated threat actors exist, security processes and procedures are useless, and as such, shouldn't be adhered to or implemented?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#283
post #229

Earlier quoted context omitted.

I believe it was an insider. I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.

I believe not everyone always checks the checksums. "Never ascribe to malice that which is adequately explained by incompetence"

Windows checks the signature.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#284
post #71

Earlier quoted context omitted.

Ya, I think I consume far beyond the average for political news and had never heard of that distinction until now. I just always equated nation-state to country.

Why do you think people said 'nation-state' if you thought it meant the same as the shorter and simpler word 'country'?

I always assumed it was a way to sidestep discussing whether certain contested territories were legitimately "countries" in their own right. By which I mean places like Palestine, Taiwan, and the way North and South Korea each kinda claim the other as part of their territory.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#285
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

Exacty. And we also know that the NSA/CIA have placed Russian language inside their exploits to frame other countries.

Source?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#286
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

>It's time to admit that computers connected to the internet can not be secured. That ship sailed a long time ago. It was normal back in the 1990s for InfoSec folk to assume that "if it's connected to the Internet, eventually, it will be compromised." The goal (then, as now) is to implement layered (defense-in-depth) mechanisms to deter such activities -- at perimeters, network and systems infrastructure platforms an…

How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#287

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

Interesting that they're called SolarWinds. They make netflow analysis tools... kinda like Stellar Wind.

I picked up on that too. I guess that means SolarWinds is a good target for nation-state level hacking

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#288

‘Nation state’ is such a stupid term for them to use as two of the usual suspects, Iran and Russia, are not nation states but rather multiethnic states. If they don’t have a clue who it is, it seems unlikely they would rule out these two states specifically and do so in this subtle way. For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).

> Iran and Russia Or Israel. Israel is the nation state that has subverted the US govt more than any other.

I seriously doubt that. But it’s cool to bash Israel online so you’ll probably get upvoted.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#289
post #137

Earlier quoted context omitted.

Yup. Jon Pollard, for one. He spied for Israel. Israel certainly has the chops to do something like this, but lots of other "friendly" countries with good geeks wouldn't mind having this kind of info.

I would bet on China, not Israel. Nation-states calculate risk/reward. With Jonathan Pollard, the reward was huge: getting your own nukes. Hacking the treasury ? Not sure what Israel would gain from that; the costs of being perceived to attack a friend would be relatively higher. Whereas China has obvious reasons to want to know what US economic policymakers are thinking, and has little to lose in terms of reputation…

> the costs of being perceived to attack a friend would be relatively higher.

Don't think israel is really concerned about attacking "friends".

https://en.wikipedia.org/wiki/USS_Liberty_incident

They live by different rules when it comes to the US due to their control/influence over our political parties, media, etc. But you already knew that.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#290

Earlier quoted context omitted.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

Looks like LinkedIn is a big security concern, I won't miss it. Imagine if companies require that you're ~not~ on it.

Not only linkedin but all job portals.
Post reply on HN