Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

291–300 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#291
post #150

Earlier quoted context omitted.

WaPo is reporting that this and the FireEye breach were via Solarwinds: > All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity. https://www.washingtonpost.com/national-security/russian-gov...

Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 >SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information

More info on the attack here: https://www.fireeye.com/blog/threat-research/2020/12/evasive...

> They gained access to victims via trojanized updates to SolarWind’s Orion IT monitoring and management software. This campaign may have begun as early as Spring 2020 and is currently ongoing. Post compromise activity following this supply chain compromise has included lateral movement and data theft. The campaign is the work of a highly skilled actor and the operation was conducted with significant operational security.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#292

>The breach presents a major challenge to the incoming administration of President-elect Joe Biden as officials investigate what information was stolen and try to ascertain what it will be used for. Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:…

> First of all, don't end your sentence with a preposition

There isn’t a real rule against that in English grammar. See https://www.merriam-webster.com/words-at-play/prepositions-e...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#294

Earlier quoted context omitted.

If I had to guess, probably some kind of social engineering attack. Identify the supplier. Go on LinkedIn, look for employees of that supplier with a title that would imply sufficient privileges to enable the attack. Then get to know that person and target them personally.

Looks like LinkedIn is a big security concern, I won't miss it. Imagine if companies require that you're ~not~ on it.

The security heads of the previous companies I worked at all obfuscated their LinkedIn profiles.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#295

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

"I asked Putin if he hacked us and he said they didn't."

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#296
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

I totally agree with your point (and would trust a hazy dream more than anything coming from this government), but I'd add that even if they claim to identify these parties forensically, they're often using parallel construction through their own espionage. like in the mueller investigation, they had a lot of firsthand knowledge of the IRA's business from inside the building (and the names of everyone that worked the…

> bellingcat has also done a pretty remarkable job of identifying state-employed hackers and spies just through buying russian passport control information and other private information that's out there on the market

Wow, I just looked some stuff up on bellingcat. It appears that Russia is pretty bad at covering its tracks. This is a good example: https://www.bellingcat.com/news/uk-and-europe/2019/11/07/how...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#297

Earlier quoted context omitted.

True, and (in my opinion) improper. But users can vouch for comments that are improperly flagged. If you see it happening, don't gripe, fix it .

>If you see it happening, don't gripe, fix it. Sometimes flags/downvotes are warranted. In my experience, most dead/downvoted comments are dead/downvoted for good reason. But that doesn't mean I don't want to see them. Which is why I enabled "showdead." IMHO, that's often a better answer than vouching for a comment, but YMMV.

Sure. I meant vouch for it if the post warrants it, and not otherwise. If it deserves to be buried, leave it buried.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#298

Earlier quoted context omitted.

>It's time to admit that computers connected to the internet can not be secured. That ship sailed a long time ago. It was normal back in the 1990s for InfoSec folk to assume that "if it's connected to the Internet, eventually, it will be compromised." The goal (then, as now) is to implement layered (defense-in-depth) mechanisms to deter such activities -- at perimeters, network and systems infrastructure platforms an…

How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

Police are credited with making arrests, but are almost never credited with treating people with respect.

By your logic, police should be encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.

Doing the right thing for the right reasons is (or should be) a thing. That it isn't doesn't say much for those who ignore an important aspect of software design.

I've always striven to meet the ideal that "if it's worth doing, it's worth doing properly."

I suppose that I shouldn't hold others to the standards I set for myself, but sometimes I still do.

Feel free to be offended, but I stand by my original statement:

"4. But the most egregious offenders are software developers, who often just bolt on weak security measures or just ignore security altogether, rather than design with security as a primary consideration."

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#299

Earlier quoted context omitted.

How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…

> Police are credited with making arrests, but are almost never credited with treating people with respect.

> By your logic, police should be encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.

No, by their argument, to the extent your first quoted sentence is true, police are (not “should be”) encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.

Which seems pretty accurate.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#300
post #110

Earlier quoted context omitted.

Imagine if an automobile manufacturer allowed you to configure the safety features of your car and had the defaults set to unsafe but convenient values to help sell vehicles... do you think the manufacturers should evade liability?

I live in New York, where the speed limits on highways vary from 50 mph in NYC to 65 in the rural areas. My car is governed at 110 mph. Why? There is no reasonable scenario where that is smart to discover. Microsoft has billions of users. The security needs of the US Department of Justice are not the same as my mom’s real estate office. When you use 3rd party IdP, for example, how does Azure MFA know what the app is?…

> My car is governed at 110 mph. Why?

Most likely due to some physical (not legal) issue that would make it mechanically unsafe to operate the vehicle above that speed even in an otherwise appropriate location. (Or perhaps it's due to some obscure state law, or the manufacturer is just out to spoil your fun, or ... who knows?)

More generally, I agree with the point you make here about the responsibility to configure things correctly. However, it seems to me that Microsoft is also on the hook for failing to include the necessary context when an MFA request is sent. It's a bit like selling a car with seat belts that superficially appear to work but fail at the slightest provocation, no?

Post reply on HN