Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

71–80 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#71
post #42
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Psychological conditioning is my theory. If you think about it, has this not been a rather popular news item for many years? If people should not get their perception of world affairs from the news, then from where should they get it?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#72

So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

It’s not fully confirmed yet but its probable it’s the same 'Cozy Bear' Russian hack group that hacked the State Department and White House email servers during Obama administration.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#73

Earlier quoted context omitted.

That's what all the SolarWinds people are saying!

I suspect I'm being downvoted by foreign agents.

We can't rule out that possibility, but I also downvoted that comment. HN needs less paranoia.

[EDIT:] although, with the more recent comment you have approached tantalizingly close to possible irony. So, I upvoted that.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#74

> Malicious code added to an Orion software update may have gone undetected by antivirus software and other security tools on host systems thanks in part to guidance from SolarWinds itself. In this support advisory, SolarWinds says its products may not work properly unless their file directories are exempted from antivirus scans and group policy object restrictions. Ouch!

Not uncommon for software that has to do very "shady" stuff, although their other advisories are quite bullcrap.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#76
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

How is this NOT an act of war?

Very simply because it's not an act anyone would initiate armed conflict over.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#77

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

Am I understanding the last one correctly?

1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted

2. The checksum doesn't match because malware has been inserted into the package during build/delivery

3. SolarWinds tells customers to ignore this and install it manually

Did no one think to check why the checksum didn't match?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#78
post #68
post #59

Earlier quoted context omitted.

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

Citation? I couldn't find anything on the web or here: https://pages.nist.gov/800-63-3/sp800-63b.html edit: I wasn't calling OP a liar, I just couldn't find it.

It's right there in section 5.1.1.2:

"Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#79
post #52
post #41

Earlier quoted context omitted.

For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(

I think it's new as of the 2019 revision, though it wouldn't surprise me if it's been ignored for a while. I don't think CMMC requirements specifically call out expiration periods, so hopefully a good sign.

Microsoft seems to be fairly forward thinking[1] on passwords, doing away with expiration requirements and focusing more on their risk based MFA stuff.

[1]https://www.microsoft.com/en-us/research/wp-content/uploads/...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#80
post #51

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

US imposed individual sanctions and explicitly named hackers from the GRU after the DOD investigated 2016 election hacking, effectively authorizing their arrest if stepping on western soil. This will be handled diplomatically through the State Dept. first. There is little incentive to starting a war with Russia I don't think.

I may be wrong, but I thought members of the security apparatus weren't allowed to leave the country in Russia? I may be horrendously wrong, but I thought someone mentioned that when these sanctions came out about Guccifer 2 and such.
Post reply on HN