Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

51–60 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#51
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

US imposed individual sanctions and explicitly named hackers from the GRU after the DOD investigated 2016 election hacking, effectively authorizing their arrest if stepping on western soil. This will be handled diplomatically through the State Dept. first. There is little incentive to starting a war with Russia I don't think.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#52
post #41

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...".

And still, very few have :(

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#53
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Anyone calling for war between the the largest nuclear power and second-largest nuclear power is insane or ignorant. To even suggest something like that is obscene given the incomprehensible loss of life it would entail. I think most people who can remember it would agree that it's a good thing the Cold War stayed cold.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#54
post #6
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds isn't another startup, its been around for over 20 years, I have used their software half a decade ago and it did the job just fine. Age doesn't imply its good either, but blaming startups isn't the problem here.

>>I have used their software half a decade ago and it did the job just fine.

Russia agrees.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#55

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

Neither of these hacks involved "back doors" as they are normally defined. One was an authentication bypass; the other was a supply chain attack. Neither involved any sort of deliberate covert access mechanism.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#56

So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

Attribution is very difficult in this space. According to most articles I've read, senior officials believe it's Russia (and it makes sense given the scope/scale) but smoking guns are hard to find.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#57
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Are you personally willing to go to war? Are you willing to be a foot soldier? Do you wish to kill? Do you wish to be killed?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#58

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#59

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security.

Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#60
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

Does anyone believe the US isn’t doing similar shit themselves ? In that light it seems pretty disingenuous to call out others for the same act.
Post reply on HN