Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

11–20 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#13
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

And how many such tools have been employed by CIA? So are all the other countries supposed to wage war against US? Govt's all over the world do shady shit, constantly. Sometimes they get caught, sometimes they dont. Men in power use tensions to stay in power, waging wars against more powerful/equal, wont help men in power neither of the sides.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#14
A couple of quick notes:

1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc.

2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's the only way to actually get work done. And then such glaring weaknesses that no one cares to fix. With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure).

Govt you are forced to write down these insanely long passwords with super complexity that cannot be cut and pasted that change very 30 or 60 days.

Because lost passwords are so common in these settings, the password reset process is usually a MASSIVE weakspot. I've seen it just be a phone call to a third party, you give them your username, they give you a new temp password - that's literally it. And the passwords end up everywhere. In lots of documents that float around, emailed around etc etc. And lots of password sharing when you get locked out of a tool and it will take a long time to get a new account setup (months). Pretty soon the procedures manual also gets you root access to everything.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#16
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

The entire Trump administration's been an act of war. They got classified intel, private phone calls with the president, numerous concessions, everything they could have possibly wanted in terms of foreign policy, including an abrupt and chaotic withdrawal from Syria where Russian troops literally took over American bases, and a significant number of GOP congressional representatives visiting Moscow on July 4th together, with no American press there to cover the event or tell us who they met with, what they discussed, or why they went.

There's also evidence that Russia infiltrated the Treasury in 2015, unrelated to the election interference afterwards.

It's been war for a long time, and we have not been winning.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#17
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

It is an act of war. Be suspect of anyone downplaying.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#20
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

I agree with the point, but that's not what happened here. SolarWinds Orion isn't some VC-backed panacea sold by SV hucksters to cure all your infrastructure's ills, it's a monitoring stack like Zenoss or Zabbix or (...) and is correctly marketed as such.
Post reply on HN