Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

301–310 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#301

Earlier quoted context omitted.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…

> Police are credited with making arrests, but are almost never credited with treating people with respect. > By your logic, police should be encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community. No, by their argument, to the extent your first quoted sentence is true, police are (not “s…

>Which seems pretty accurate.

Exactly. Which is why it was a good analogy WRT the lack of security baked into the design of most software.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#302
post #102

Earlier quoted context omitted.

I like how when the downvoted messages start to fade away until they say [flagged] and vanish. The creators of the site were only looking for what’s popular because, you know, they’re VC.

I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

I thought enough (5 or so?) downvotes resulted in an automatic [flagged][dead]? Did I misunderstand?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#303
It's common to downvote questions/statements such as-"Has the United States government released evidence to back the claim that the hack was committed by Russia?" and "The word of the United States is not trustworthy to take on face value alone." on Hacker News?

Because that's what I believe.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#304

Earlier quoted context omitted.

>If you see it happening, don't gripe, fix it. Sometimes flags/downvotes are warranted. In my experience, most dead/downvoted comments are dead/downvoted for good reason. But that doesn't mean I don't want to see them. Which is why I enabled "showdead." IMHO, that's often a better answer than vouching for a comment, but YMMV.

Sure. I meant vouch for it if the post warrants it , and not otherwise. If it deserves to be buried, leave it buried.

>Sure. I meant vouch for it if the post warrants it, and not otherwise. If it deserves to be buried, leave it buried.

A fair point. And a correct one too. I took that as a given, but apparently folks are unable to read my mind. :)

Thanks for clarifying. I should have been more explicit.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#305
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

MITM is getting harder due to TLS improvements. Most traffic is TLS encrypted over a handful of destination ports.

I don't want to oversimplify, because there is of course an uncountable number of software packages and a lot of noise on any network. However, "super simple FPGA network firewall" is not going to save us. Trustworthy logging, least-privilege account credentials and a competent SOC, among a number of other things, are critical.

Many orgs know how to be secure, they just can't or won't be due to some financial or usability constraint.

https://www.cm-alliance.com/consultancy/compliance-gap-analy...

https://blog.cipher.com/hs-fs/hubfs/NIST%20Cybersecurity%20F...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#306

Earlier quoted context omitted.

I believe not everyone always checks the checksums. "Never ascribe to malice that which is adequately explained by incompetence"

I'm sure malicious people are very grateful that this platitude is in circulation.

Calling it a platitude is selling it short. Yes, it's a little strained in the context of people trying to deceive you, but the malicious are still vastly outnumbered by the incompetent.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#307
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

there is a saying in infosec, "not if, but when". no one is under the dissolution that we can keep a network perfectly safe, we just implement layers to mitigate damage

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#308

Earlier quoted context omitted.

Looks like LinkedIn is a big security concern, I won't miss it. Imagine if companies require that you're ~not~ on it.

The security heads of the previous companies I worked at all obfuscated their LinkedIn profiles.

don’t post current work place until it’s over.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#309

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

"I asked Putin if he hacked us and he said they didn't."

Could you please stop posting unsubstantive comments to Hacker News? You've been doing it a lot lately and we're trying for something different here.

https://news.ycombinator.com/newsguidelines.html

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#310
post #102

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

I like how when the downvoted messages start to fade away until they say [flagged] and vanish. The creators of the site were only looking for what’s popular because, you know, they’re VC.

Actually it's an attempt to prevent the overwhelming forces of the internet from filling the site immediately with dreck.

Would you please review the site guidelines? Your comment breaks more than one of them: https://news.ycombinator.com/newsguidelines.html

Also, as bigyikes pointed out, downvotes don't flag things. Flag flag things.

Post reply on HN