Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

31–40 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#31
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

As I'm forced to speculate, because it is inconvenient for us to call it an act of war. We routinely conduct cyber espionage missions on other countries and "probe" their cyber defenses. If we were to call this an all out act of war, then we would also be found guilty of unprovoked acts of war on many other countries, including allied countries. So, too, would many other countries. This is the new spywork.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#32
More details: https://www.fireeye.com/blog/threat-research/2020/12/evasive...

“SolarWinds.Orion.Core.BusinessLayer.dll is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. We are tracking the trojanized version of this SolarWinds Orion plug-in as SUNBURST.”

“ Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website. The trojanized update file is a standard Windows Installer Patch file that includes compressed resources associated with the update, including the trojanized SolarWinds.Orion.Core.BusinessLayer.dll component. Once the update is installed, the malicious DLL will be loaded by the legitimate SolarWinds.BusinessLayerHost.exe or SolarWinds.BusinessLayerHostx64.exe. After a dormant period of up to two weeks, the malware will attempt to resolve a subdomain of avsvmcloud[.]com.”

“This actor prefers to maintain a light malware footprint, instead preferring legitimate credentials and remote access for access into a victim’s environment.”

“In observed [trojan] traffic these HTTP response bodies attempt to appear like benign XML related to .NET assemblies” “Command data is spread across multiple strings that are disguised as GUID and HEX strings.”

Edit: Silly me, that was the first article on hn, see thread: https://news.ycombinator.com/item?id=25413053

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#33
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation.

If we do nothing, we're sending the message that these actions are okay.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#34

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

Aside from anything else, your second point is exactly spot-on. That's not just your impression.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#35
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

> the Russian government

You sure about that? "They" have been claiming Russia is the boogie man for years, but it's never been proven. In this case, it does appear like a complex hack. Wouldn't be surprised if it's China, Iran, North Korea, Russia, U.S. Government (yes, hacking itself), etc.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#36
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

>If we do nothing, we're sending the message that these actions are okay.

I think it sends the message that these actions won’t trigger nuclear war. How would you even get public support for war with Russia?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#37

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#38
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

Maybe we should "send the message" that we won't install insecure shit on our networks?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#39

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

Spot on, humans are always the weakest link. You must assume your users will invoke every worst practice imaginable and make your system secure anyway.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#40
post #4
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

Willy-nilly dropping tools into core infrastructure is largely how government IT works.

Corporate IT, too, from what I've seen.

Post reply on HN