So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
51–60 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#52A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…
For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
And still, very few have :(
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#53So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#54When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.
SolarWinds isn't another startup, its been around for over 20 years, I have used their software half a decade ago and it did the job just fine. Age doesn't imply its good either, but blaming startups isn't the problem here.
Russia agrees.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#55A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#56So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.
Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#57So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#58A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#59A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…
The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…
Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#60Earlier quoted context omitted.
So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.
We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.