Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

21–30 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#21
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Having the capacity isn’t an act of war, in the same way that having the much more significant capacity to obliterate major population centers isn’t. How the capacity is applied may be another story.

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#22
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Well, that is very similar to asking how it is that conventional spying is not an act of war. It isn't, because everyone is going to be doing it anyway, so if you make that an act of war we have war all the time, rather than nations not doing it.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#23
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

The US executive branch is favourable to Russian interference. They're invited

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#24
post #11

Ouch. Via a security provider. Thats ugly no matter how you look at it

Adding snake oil usually adds more attack vectors rather than removing them. Look at all the "endpoint protection" and AV exploits surfacing almost every week.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#25
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

> How is this NOT an act of war?

Because spying is not an act of war.

If it was, the entire world would be at war with the entire world.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#26
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Lmao act of war. You going to fight?

This is just what countries do to eachother. Welcome to the 21st century.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#28
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

So it's an act of war. Now what?

Does the US escalate to a shooting war with the second biggest nuclear power in the world?

So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#29
SolarWinds hasn't bothered to revoke their certs or remove the package

https://twitter.com/KyleHanslovan/status/1338360093767823362

Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed

https://twitter.com/vinodsparrow/status/1338431183588188160/...

Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and installing it manually, LOL

https://twitter.com/KyleHanslovan/status/1338419999665508354...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#30

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). They also used a shared account for admin stuffs, even though we were all given an admin token (like the smart card or CAC for regular login, but with admin credentials and issued separately).

In theory, the DOD CAC system (they've gotten better over the years) eliminates the need for passwords entirely, but somehow most teams never tie their system to it properly.

Post reply on HN