Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

331–340 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#331
post #212

Earlier quoted context omitted.

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention. Automatic updates are RCE vulnerabilities.

No one is arguing a compromise of the update server doesn't allow compromising all customers. They're arguing that the benefits out auto-updating software (especially consumer software) outweigh the risk of a compromised update server, which is generally true.

What about users who don't consent to that, who would prefer to manually update in a safe manner?

Making the decision for a user is the issue. Consent to run software A on Monday is not consent to run unknown/unexamined software B on Tuesday.

In the vast majority of cases, receiving userspace updates in a timely fashion is not worth this real-time remote access vulnerability.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#332

Earlier quoted context omitted.

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

What it means is that MS is no IBM, in the sense that you may very well get fired for buying MS.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#333

Earlier quoted context omitted.

To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.

Depends how you weigh timing. If attacker doesn't know when you update, they have to hang out and risk detection at the supplier. (Who added this update?) If they can push updates, they can move quickly and compromise the target.

This is the key. Additionally, updates can be verified to be the same thing that everyone else got, by checking them from multiple different clients/IPs/countries. Targeted attacks are much harder, and if the compromised update is untargeted, detection risk increases drastically.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#334

Earlier quoted context omitted.

Right. There are situations where we can see that the only apparent way to do something needed very considerable resources, which suggests a state actor. Equation Group is presumed to be (a front for) the NSA. It forged a (code signing) certificate that otherwise shouldn't exist, using an MD5 collision. But not the MD5 collision painfully created by researchers a little earlier to demonstrate that MD5 was vulnerable,…

Didn't Dan Kaminsky and others have tools to produce nearly arbitray collisions by the early 2000s?

As far as I know you can reliably change a few bits and get a collision, not create arbitrary data with padded info whose hash collides with the original data.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#335

Earlier quoted context omitted.

>...obsolete tech like SCADA... ...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...

>>...obsolete tech like SCADA... >...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps... Wow! 2010 called. They want their ideas about what makes the world go back.[0] That's just crazy talk. Everyone knows that hardware has been completely deprecated. It's all clouds. Mostly cumulo-nimbus, in fact. Power plants, chip fabs, heavy…

It's the hardware that's the problem so we should have an fpga cloud so you can run whatever hardware you want.

What would make that 600MB of javascript secure would be to auto-generate a random CPU architecture and recompile your server to run on it!

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#336
post #23

Earlier quoted context omitted.

I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…

Yeah if I were a blackhat I would launch all my attacks from a cheap VPS in Tehran and sprinkle random Russian gibberish throughout my binaries. Guaranteed nobody will come looking for me. Sincerely yours, Evil mastermind

Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them.

The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep information on many system that would likely require badges or intensive social engineering to access, both of which leave traces. Do you really think you could hide?

I'm an expert (of sorts) and I'm not sure that I could buy drugs on the dark web 100% securely if those resources were hunting me.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#337
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…

I'm perfectly willing to trust that the WaPo is reporting truthfully and that their sources are legit, but without concrete evidence it's hard to judge how serious the allegation really is.

Is it "they forgot to switch their VPN on once and we got a direct connection from an IP that belongs to the Russian state" like that other time (still manipulable but fairly conclusive IMO) or is it "that really looks like the modus operandi of those damn russians and we really need somebody to pin it on right now"?

To be clear I'm not making one of those "fake news" pro-russian rants, I can totally believe that Russia would very much do the things being reproached here if given the opportunity, I just have a really hard time taking the word of an anonymous source without concrete elements in these matters because the potential for manipulation is so absolutely tremendous.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#338
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

I'm not usually very distrustful of mainstream news (at least, by internet standards) but I am very distrustful of the news' capacity to vet very technical issues correctly. Remember that Bloomberg "the Chinese put spy microchips on our motherboards" story?

I'm not accusing the WaPo of being distrustful here, I just think that in these cases the potential for manipulation, half-truths and technical mistakes from their sources is very high, and without either knowing who these sources are or what are the concrete element they're using to make their conclusions I find it very hard to blindly trust these sources.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#339

Earlier quoted context omitted.

>>...obsolete tech like SCADA... >...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps... Wow! 2010 called. They want their ideas about what makes the world go back.[0] That's just crazy talk. Everyone knows that hardware has been completely deprecated. It's all clouds. Mostly cumulo-nimbus, in fact. Power plants, chip fabs, heavy…

It's the hardware that's the problem so we should have an fpga cloud so you can run whatever hardware you want. What would make that 600MB of javascript secure would be to auto-generate a random CPU architecture and recompile your server to run on it!

Stop it, you're giving Amazon ideas.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#340

Earlier quoted context omitted.

Yeah if I were a blackhat I would launch all my attacks from a cheap VPS in Tehran and sprinkle random Russian gibberish throughout my binaries. Guaranteed nobody will come looking for me. Sincerely yours, Evil mastermind

Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them. The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep informati…

You can try to blame somebody else (or even multiple people) by leaving deliberate traces. Cyberwarfare is the most assymetric warfare that we have.
Post reply on HN