Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

41–50 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#41

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change.

>“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#42
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#43
post #33

Earlier quoted context omitted.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

Maybe we should "send the message" that we won't install insecure shit on our networks?

no... nuclear war before free software.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#44

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

LOL that last one. Why bother having the checksum at all in this case....

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#45
So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon)

If so, this is on scale with the OPM hack in 2015. This is huge.

Smart to use the election timing while authorities were focused elsewhere.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#46
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

We aren’t even close to maxing out what could be accomplished with economic sanctions! The US and Russia still have a direct trading relationship!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#47

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

Indeed. Sports Team + Year, Season + Year, Company + Year or some other such combination should get you a good 10% or more of your users with only a few dozen permutations.

They wrote 60 days into FEDRAMP I believe, something I jaw-droppingly realized last year sometime. Whoever is writing these policy frames don't know what they're doing. NIST did away with those periodic password change recommendations for a very good reason but IMO they need to now recommend the opposite, directly, because the constant password changes are doing real harm.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#48

So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#49
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

> How is this NOT an act of war?

So you want bombing to start over this? I don't.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#50
> Malicious code added to an Orion software update may have gone undetected by antivirus software and other security tools on host systems thanks in part to guidance from SolarWinds itself. In this support advisory, SolarWinds says its products may not work properly unless their file directories are exempted from antivirus scans and group policy object restrictions.

Ouch!

Post reply on HN