Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

341–350 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#341
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…

> As a overly generic rule, trust (or don't) the Institution over the individuals.

That is precisely the same line of reasoning that started the Iraq War based on lies. The New York Times claimed to have intel from anonymous sources showing that Saddam Hussein had nuclear weapons, and their false reporting is what led the US to declare war. That snafu didn't happen all that long ago, and yet most people in 2020 seem to have blocked it out of their minds.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#342
post #241

Earlier quoted context omitted.

True. However, now that APT tools have been leaked to the world I think I can still argue that even layered defenses are no longer sufficient. I listened to security researchers say for years that there was no point in trying to address APT's because they were just impossible to stop. Now APT methods are public knowledge and being used in common attacks. Some types of APT attacks are still too costly to be widely use…

>True. However, now that APT tools have been leaked to the world I think I can still argue that even layered defenses are no longer sufficient. I listened to security researchers say for years that there was no point in trying to address APT's because they were just impossible to stop. Perhaps I'm a little dense, but I'm not sure what you're arguing here. Are you asserting that since sophisticated threat actors exist…

No, I'm saying researchers ignored APT's for decades and now that they are available to everyone many current security processes and procedures are less effective, and yes possibly useless, _regardless_ of whether sophisticated threat actors exist (because their tools have been exposed). Current processes and procedures should still be used because they are all we have, but something new is also needed. Part of that something new should be an acknowledgement that systems are unprotectable, so instead of just security procedures we need, for example, faster recovery procedures (not just restore from backup). Another example might be dual implementations of systems, built with different technologies, so that when one is compromised the other is less likely to be susceptible to the same compromise. Expensive, but that may be what it takes to keep the world running. Splitting the internet into layers of VPN's with everything having it's own VPN might be useful too. The internet is fragmenting anyway, might as well fragment it in a useful way. Maybe everyone should have multiple physical computers as well, one for each work project, one for play, one for home finances, etc., each with tailored protections and no connections between them. I'm not sure what the answers are but it's obvious what is being done now is not good enough. I do fully expect to see the IRS hacked, chemical plants destroyed, factories stopped, etc. the way things are going now. Simple ransomware is already causing major problems and there seems to be no way to stop it and it's going to spread to all sectors and it seems likely there will be ransomware without the ransom too, just pure destruction. Already happened in Saudi Arabia.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#343
post #227

Earlier quoted context omitted.

It's an open problem in science to prove security of a network connected computer. It's well known.

Really? What's that problem called? As you stated it, it seems too vague to be considered "open" or "closed".

Provable Security:

https://en.wikipedia.org/wiki/Provable_security

If you read that article you'll see that current approaches don't even attempt some kinds of proofs such as proof of security against side channel attacks. It goes by other names as well such as proof of code correctness:

https://www.schneier.com/blog/archives/2009/10/proving_a_com...

A major problem with current attempts at proofs is you can at best create a proof based on a system specification and what you want it to be secure against, which basically means you have to already know all possible attacks including zero day attacks. So far the field has resulted in nothing practically useful as far as I know. Homomorphic encryption might be close to being practical for a limited set of problems and could be provably secure for a limited set of attacks, though I don't know if anyone has attempted such a proof yet.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#344
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

> "I'm just wondering why this response has become so popular recently."

There is a huge divergence in understanding of the purport of recent events, starting with the Wikileaks release of DNC emails in 2016, and continuing through to Hunter Biden's laptop

One camp believes or suspects that Russia is more of a useful bugbear and scapegoat for certain political factions in the US, used cynically as FUD to manipulate public perceptions, than something to be so worried about

The other believes in good faith that Russia is a dangerous and sophisticated adversary with assets in the highest levels of the US government, and finds the first camp to be incomprehensibly obtuse at best

It's difficult for these 2 camps to communicate effectively for some reason

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#345
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…

Often, people who "aren't authorized" are used to plant an idea in the press, without the agency in question having to make an official statement. Whether that information is reliable depends on whether you trust the agenda of whoever decided to leak the information.

The Washington Post's record on verifying the claims of the US national security apparatus is poor. The newspaper uncritically reported false claims by the Bush administration about Iraqi WMD. Many people people at the time found those claims extremely dubious, but critical voices were belittled or shut out of most mainstream reporting. More recently, the Washington Post has been all-in on Russia paranoia. That doesn't mean that everything they publish about Russian hackers is wrong, but it very well may be misinformation leaked by US intelligence officials, or something insignificant blown out of proportion and presented without any context. In December 2016, for example, the Washington Post reported that the Russians had hacked a Vermont utility. That story turned out to be complete nonsense, but the Washington Post never fully retracted it. If you look at the story today, you'll still get the impression that the Russians attempted to hack the utility, even though that aspect of the story completely fell apart. The Washington Post on Russia is a bit like Bloomberg on Chinese hackers (e.g., Supermicro).

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#346
By the way, is there a report on how many foreign governments are being hacked per year by the US (or Russia/China/etc.)?

This report reads like 'Russia attacked the US in cyberspace' when there is no transparency about the quantities of cyber attacks by governments in the world.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#347
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

I think it is just a problem between theory and practice. In theory it is possible, but in practice it has proven to be so hard, that I am not sure if there ever was or will be a secure computer that is connected to the internet.

Another problem is that the complexity in modern systems is increasing and designing secure systems on top of complexity is next to impossible. I think Unikernels have a good chance of delivering secure systems from a software perspective, but it seems even modern hardware has enough vulnerabilities to thwart those plans.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#348

>The breach presents a major challenge to the incoming administration of President-elect Joe Biden as officials investigate what information was stolen and try to ascertain what it will be used for. Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:…

If you're going to lecture others on correctness, you should probably make damn sure that you've got every little detail exactly right yourself (since, apparently, anything less than absolute perfection is completely unacceptable).

(I believe you'll find that the "A" is for "Availability", not "Accessibility".)

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#349

Earlier quoted context omitted.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…

> the most egregious offenders are software developers Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it.

>Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it.

I get that a variety of pressures are put on developers to add features and ship quickly.

But whether it's corporate development done internally (e.g., LOB applications), a web app or a SaaS offering, not designing security into the software is a disaster waiting to happen.

So many times I've seen businesses have their crown jewels ripped off due to poorly implemented/weak or non-existent security practices in application design/development.

Even when the infrastructure is reasonably well secured, with defense-in-depth, including strong authn/authz, separation of duties, as well as strong security processes and policies in place, software that lacks designed-in security can render all of it useless.

Whether that's because the software doesn't/can't integrate with the security tools in use (often requiring applications to run with much higher privilege than they should) or because little or no thought was given to secure coding mechanisms or access controls.

I absolutely understand that there are always security trade-offs, regardless of where in a multi-layered infrastructure/management/application environment.

And it's always important not to expend resources beyond what's appropriate for the assets being secured.

That said, application software is the most frequent culprit in enabling compromises (followed closely by poor security implementation in the infrastructure and a lack of policy/process in securing it -- usually through ignorance/incompetence).

My argument is not that developers are stupid or ignorant, but that security isn't baked-in to their design decisions as a guiding principle.

And that often leads to insecure software and/or sloppy/insecure integration of security after the fact.

If more developers thought about security as a feature rather than an inconvenience to be given little thought or just lip service, that would make a big difference.

Edit: Clarified verbiage and fixed typos.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#350
post #289
post #137

Earlier quoted context omitted.

I would bet on China, not Israel. Nation-states calculate risk/reward. With Jonathan Pollard, the reward was huge: getting your own nukes. Hacking the treasury ? Not sure what Israel would gain from that; the costs of being perceived to attack a friend would be relatively higher. Whereas China has obvious reasons to want to know what US economic policymakers are thinking, and has little to lose in terms of reputation…

> the costs of being perceived to attack a friend would be relatively higher. Don't think israel is really concerned about attacking "friends". https://en.wikipedia.org/wiki/USS_Liberty_incident They live by different rules when it comes to the US due to their control/influence over our political parties, media, etc. But you already knew that.

I said they were concerned about the possible reputational loss. I am also skeptical of overblown arguments that Israel "controls the US media". These tend to shade into antisemitic conspiracy theories. The incident you link seems to be a good example: I see little to persuade me that the USS Liberty wasn't sunk by accident.
Post reply on HN