Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

1–10 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#2
When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure.

I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#3
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

When the financial costs of exposing yourself to such risks outweigh the time saved.

So, never. At least, not in our current software development industry.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#4
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds is a 21-year-old publicly-traded company.

They're not really "yet another startup".

I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure.

While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#5
So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while.

How is this NOT an act of war?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#6
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds isn't another startup, its been around for over 20 years, I have used their software half a decade ago and it did the job just fine.

Age doesn't imply its good either, but blaming startups isn't the problem here.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#7
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Russia has a policy where they allow "patriotic hackers" to operate freely while turning a blind eye to their actions. The Kremlin even mentioned this in their disavowal.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#8
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Having the capacity isn’t an act of war, in the same way that having the much more significant capacity to obliterate major population centers isn’t.

How the capacity is applied may be another story.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#10
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Russia has a policy where they allow "patriotic hackers" to operate freely while turning a blind eye to their actions. The Kremlin even mentioned this in their disavowal.

While I disagree with the claim that merely having the capacity is an act of war, doing something that would be an act of war through privateers rather than official state forces doesn’t make it any less an act of war than it otherwise would be.
Post reply on HN