Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

311–320 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#311
post #302

Earlier quoted context omitted.

I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

I thought enough (5 or so?) downvotes resulted in an automatic [flagged][dead]? Did I misunderstand?

That's not how it works. Rather, there's a tug of war between upvotes and flags. If the flags get the upper hand, [flagged] appears, and if they dominate, then the post also gets killed. In the latter case users with 'showdead' turned on in their profile will see [flagged][dead].

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#312

Earlier quoted context omitted.

Exacty. And we also know that the NSA/CIA have placed Russian language inside their exploits to frame other countries.

Source?

I've heard this in the "right rooms" to know this to be likely true, but I'd like something to link to, too.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#313

Earlier quoted context omitted.

Sure. I meant vouch for it if the post warrants it , and not otherwise. If it deserves to be buried, leave it buried.

>Sure. I meant vouch for it if the post warrants it, and not otherwise. If it deserves to be buried, leave it buried. A fair point. And a correct one too. I took that as a given, but apparently folks are unable to read my mind. :) Thanks for clarifying. I should have been more explicit.

As should I have been...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#314
post #129

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

If your IT department cared, they could disable the app notification MFA method in AAD and force you to either use passwordless or a TOTP code, both of which prevent you from blindly approving a sign-in you aren't involved in.

I authenticate with 10 different Azure AD directories, of which I my company controls 1, and I personally control zero.

Notably, Microsoft's consumer MFA, the type used to protect Hotmail and XBox accounts shows more information in the exact same mobile app!

It's not that they don't have the capability, or don't know that it's important. Microsoft has explicitly chosen to never ever show additional information of any type for enterprise customers only.

They care about the security of their own things, not you stuff, in other words.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#316

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

There is no setting available to enable additional information for MFA when used for Azure AD. It's not an option.

It is is on by default however when using the same mobile app for Hotmail or XBox live accounts.

Microsoft thinks the data of Fortune 500 companies is less valuable than your Minecraft skins.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#317
post #227
post #219

Earlier quoted context omitted.

To be fair you have the burden of proof by asserting "computers connected to the internet can not be secured."

It's an open problem in science to prove security of a network connected computer. It's well known.

Really? What's that problem called? As you stated it, it seems too vague to be considered "open" or "closed".

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#318
post #105

Earlier quoted context omitted.

I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.

Hahaha our military can't even figure out boots for the troops, you think we can hack the US Government? As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence. We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.

You may not be aware, but Canada does have a sophisticated organization dedicated to electronic security:

https://en.m.wikipedia.org/wiki/Communications_Security_Esta...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#319

Earlier quoted context omitted.

How is it not Microsoft's fault if they don't provide the user with any information to decide whether the MFA request is legit?

There's literally no upside to hiding this information.

To be honest, though, if they did provide all the details, they'd criticized for "overwhelming" users with too much information -- most of which would probably be useless to the majority of users who either wouldn't (care|pay attention|understand) anyways.

That said, I'm sure there's a reasonable level somewhere in the middle. The current situation certainly doesn't sound like it, although I haven't used any form of Microsoft MFA, so I can't really say either way.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#320

Earlier quoted context omitted.

Didn't Dan Kaminsky and others have tools to produce nearly arbitray collisions by the early 2000s?

Perhaps? I can't find any evidence easily that Dan did have such tool, but "by the early 2000s" it's not at all unthinkable certainly. If you have a link that'd be great. However the trouble is MD5 collision isn't like that hilarious "Send all zeroes" Microsoft bug from a few weeks back where you just try it a few times then it works because someone was very stupid - the MD5 collision is pretty hard, the Merkle–Damgå…

Do you have any idea what time window they had to generate collisions in?

The MS article on the collision says the attack required knowledge of, among other things, the predictable serial numbers. They could have had as little as the usual inter-cert issuance time, or in the worst-case scenario with entirely predictable numbers could have had months or more.

Depending on the window the funds required would change dramatically.

Post reply on HN