Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

61–70 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#61
post #33

Earlier quoted context omitted.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

> If we do nothing, we're sending the message that these actions are okay. I think it sends the message that these actions won’t trigger nuclear war. How would you even get public support for war with Russia?

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#62
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

It is an act of war. Be suspect of anyone downplaying.

That's what all the SolarWinds people are saying!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#63
post #4
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup".

Today it is. If we knew when SolarWinds was added to the government systems, his comment might stand.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#64
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

If you had an experince of an actual war, you would NOT have asked this question.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#65

So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

No, not at all. It's political theatre the media is playing. Russia has been the big bad wolf since 2016. It's far more likely China than Russia, although it could be a variety of different states/parties.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#67
post #59

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

Yeah, I know it's not actually recommended anymore, but the policy makers don't care. They're doing CYA policy. They do whatever seems to be the strongest possible thing, users and reality be damned.

I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-network. Security didn't care, it took the realization of the cost (delays, people too busy moving data to do their actual jobs) for management to step in and end the nonsense.

The same will be required for things like password policies. Until the issue becomes realized (weak/written passwords lead to a compromise), these policies will stay in place within organizations and teams. It doesn't help that the majority of the policy setters are not IT professionals (or only in the loosest sense, they can install software but have no real understanding of IT systems). In DoD, most come from a physical security background (retired/separated security forces).

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#68
post #59

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

Citation? I couldn't find anything on the web or here: https://pages.nist.gov/800-63-3/sp800-63b.html

edit: I wasn't calling OP a liar, I just couldn't find it.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#69
Just to add, 15 mins ago Chris Bing from Reuters and other journalists confirmed the U.S. Department of Homeland Security to be the 3rd agency to be impacted [1].

I suspect there will likely be further agencies and of course private companies to come forward in the upcoming weeks/months.

[1] https://twitter.com/Bing_Chris/status/1338552048342753288

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#70
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

One of the shortcoming of maximalist position, you lost your leverage.
Post reply on HN