Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

351–360 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#351

Earlier quoted context omitted.

> the most egregious offenders are software developers Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it.

>Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it. I get that a variety of pressures are put on developers to add features and ship quickly. But whether it's corporate development done internally (e.g., LOB applicatio…

Show me a single project where the functional specs were complete when given to the developers and external concerns didn't dictate any implementation details. All of the projects I've been on have had changing specs, right up to and through release.

I love the architecture weenie role. It's tons of fun. But eventually you need to build something and only with experience do you discover the first set of complications, then marketing starts promising features and you've got the next, and management refuses to allocate more time.

Did you do something wrong at step 1 by building a prototype before knowing it would be perfect? And if so, how could you know that and what would you do to get there?

I write the code, and tag releases, but I don't determine what ships. I, and 95% of us, are not engineers and even those who are have abrogated their responsibility to make the bridge stand - we're all just building individual struts because someone told management that things done in a vacuum will all fit together properly in the end.

So I agree I guess, but don't at the same time.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#352
post #211
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

> the attackers where highly sophisticated and had the resources of a nation state Also, the attack was carefully crafted. How could anyone expect or defend against a carefully crafted attack, by a nation state no less.

Well, one would presume our own nation state could, for starters.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#353
post #342

Earlier quoted context omitted.

>True. However, now that APT tools have been leaked to the world I think I can still argue that even layered defenses are no longer sufficient. I listened to security researchers say for years that there was no point in trying to address APT's because they were just impossible to stop. Perhaps I'm a little dense, but I'm not sure what you're arguing here. Are you asserting that since sophisticated threat actors exist…

No, I'm saying researchers ignored APT's for decades and now that they are available to everyone many current security processes and procedures are less effective, and yes possibly useless, _regardless_ of whether sophisticated threat actors exist (because their tools have been exposed). Current processes and procedures should still be used because they are all we have, but something new is also needed. Part of that…

>No, I'm saying researchers ignored APT's for decades

That isn't even close to being true. In fact, that statement is ridiculous on its face.

Research into detecting, mitigating and countering such attacks go back at least 30 years.

That APT actors have often been successful is more a function of effective execution and poor security practices than lack of knowledge/research around such attacks.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#354

Earlier quoted context omitted.

>Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it. I get that a variety of pressures are put on developers to add features and ship quickly. But whether it's corporate development done internally (e.g., LOB applicatio…

Show me a single project where the functional specs were complete when given to the developers and external concerns didn't dictate any implementation details. All of the projects I've been on have had changing specs, right up to and through release. I love the architecture weenie role. It's tons of fun. But eventually you need to build something and only with experience do you discover the first set of complications…

>So I agree I guess, but don't at the same time.

I suppose I do too.

While a lack of designed-in security is often the (sometimes disastrous) result, I posit that it's more about a lack of knowledge/education around good software security design/implementation than spec changes or scope creep.

If good security design practices were stressed when teaching software development (and/or included in resources for autodidacts) and given the same value as other development concepts, developers would incorporate those concepts from the start, rather than having to bolt them on (or not) later on.

As such, it's more about lack of knowledge/focus/value placed on security in software design/development.

Given the value of data that being secured with software, good security practices should be, if not just as integral, to software development as performance or UX design, it should at least be a consideration before prototyping.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#355

Earlier quoted context omitted.

Right. There are situations where we can see that the only apparent way to do something needed very considerable resources, which suggests a state actor. Equation Group is presumed to be (a front for) the NSA. It forged a (code signing) certificate that otherwise shouldn't exist, using an MD5 collision. But not the MD5 collision painfully created by researchers a little earlier to demonstrate that MD5 was vulnerable,…

Didn't Dan Kaminsky and others have tools to produce nearly arbitray collisions by the early 2000s?

The HashClash tool [1] was written back in 2006 and can construct chosen-prefix md5 collisions. Don't know if it has anything to do with Dan Kaminsky though.

[1]: https://www.win.tue.nl/hashclash/

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#356
post #175

Earlier quoted context omitted.

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…

But you should also keep in mind that organizations (or factions within organizations) will use these channels for their own purposes, to test public opinion before an official announcement, as propaganda channel or to undermine elected officials who are politically in charge.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#357

Earlier quoted context omitted.

A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…

> As a overly generic rule, trust (or don't) the Institution over the individuals. That is precisely the same line of reasoning that started the Iraq War based on lies. The New York Times claimed to have intel from anonymous sources showing that Saddam Hussein had nuclear weapons, and their false reporting is what led the US to declare war. That snafu didn't happen all that long ago, and yet most people in 2020 seem…

The difference is that it wasn't hard to work out the claims were nonsense. WMDs are hugely expensive, and the Iraqi economy was running on fumes at that point. That combined with US belligerence against Iraq made the claims improbable.

But Russia actually does have a strong black hat culture, with links to the political establishment. Putin is a technologically savvy kind of despot who likes sneaky low-cost high-return actions. So this fits the profile - both as a workable hack and also as a proof of concept for future attacks.

Consider the cost/benefit. Instead of physically blowing up infrastructure and security systems you can cripple them, possibly permanently, for the cost of - what? - 20 or 30 specialists, some PCs, and maybe some supercomputer time. Although even that may be optional.

It's unlikely conclusive evidence will be released, because that might reveal too much information about defence strategies. So circumstantial evidence will be as good as it gets.

But whatever the cause, clearly - clearly - all countries and larger orgs need to work much harder on security. Some decorative pen-testing isn't going to be nearly enough in the 2020s.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#358
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

This attack is a supply chain attack on enterprise software used by huge government organizations. Where can teenagers with wget pull that off?

When a leading security group (FireEye) says it's a state-level actor, I don't think they are doing PR.

It's fine to be skeptical, but why are you being skeptical? Perhaps it's lost on me but I don't think the claim that PR would look bad _if it were teenagers_ is a good reason to promote widespread distrust of ???.

I see the compromise of SolarWinds Orion software as far more likely to be carried out by state level actors than by script-kiddies. What would script-kiddies stand to gain?

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#359

Earlier quoted context omitted.

Perhaps? I can't find any evidence easily that Dan did have such tool, but "by the early 2000s" it's not at all unthinkable certainly. If you have a link that'd be great. However the trouble is MD5 collision isn't like that hilarious "Send all zeroes" Microsoft bug from a few weeks back where you just try it a few times then it works because someone was very stupid - the MD5 collision is pretty hard, the Merkle–Damgå…

Do you have any idea what time window they had to generate collisions in? The MS article on the collision says the attack required knowledge of, among other things, the predictable serial numbers. They could have had as little as the usual inter-cert issuance time, or in the worst-case scenario with entirely predictable numbers could have had months or more. Depending on the window the funds required would change dra…

I agree that there is a wide range of costs for the attack, however for the sake of the discussion I would point out that the lower bound of that cost is likely to still be prohibitive for a teenager.
Post reply on HN