U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
11–20 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#12The widespread use of unvalidated automatic updates will go down as one of the biggest security blunders of the last decade.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#13So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#141) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc.
2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's the only way to actually get work done. And then such glaring weaknesses that no one cares to fix. With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure).
Govt you are forced to write down these insanely long passwords with super complexity that cannot be cut and pasted that change very 30 or 60 days.
Because lost passwords are so common in these settings, the password reset process is usually a MASSIVE weakspot. I've seen it just be a phone call to a third party, you give them your username, they give you a new temp password - that's literally it. And the passwords end up everywhere. In lots of documents that float around, emailed around etc etc. And lots of password sharing when you get locked out of a tool and it will take a long time to get a new account setup (months). Pretty soon the procedures manual also gets you root access to everything.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#15Ouch. Via a security provider. Thats ugly no matter how you look at it
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#16So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
There's also evidence that Russia infiltrated the Treasury in 2015, unrelated to the election interference afterwards.
It's been war for a long time, and we have not been winning.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#17So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#18The widespread use of unvalidated automatic updates will go down as one of the biggest security blunders of the last decade.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#19The widespread use of unvalidated automatic updates will go down as one of the biggest security blunders of the last decade.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#20When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.