So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
71–80 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#72So basically, Russians had the highest level of access to every large company and most government agencies in the US? (Including defense, DOD, pentagon) If so, this is on scale with the OPM hack in 2015. This is huge. Smart to use the election timing while authorities were focused elsewhere.
Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#73Earlier quoted context omitted.
That's what all the SolarWinds people are saying!
I suspect I'm being downvoted by foreign agents.
[EDIT:] although, with the more recent comment you have approached tantalizingly close to possible irony. So, I upvoted that.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#74> Malicious code added to an Orion software update may have gone undetected by antivirus software and other security tools on host systems thanks in part to guidance from SolarWinds itself. In this support advisory, SolarWinds says its products may not work properly unless their file directories are exempted from antivirus scans and group policy object restrictions. Ouch!
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#75Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#76So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Very simply because it's not an act anyone would initiate armed conflict over.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#77SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted
2. The checksum doesn't match because malware has been inserted into the package during build/delivery
3. SolarWinds tells customers to ignore this and install it manually
Did no one think to check why the checksum didn't match?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#78Earlier quoted context omitted.
NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
Citation? I couldn't find anything on the web or here: https://pages.nist.gov/800-63-3/sp800-63b.html edit: I wasn't calling OP a liar, I just couldn't find it.
"Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#79Earlier quoted context omitted.
For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(
Microsoft seems to be fairly forward thinking[1] on passwords, doing away with expiration requirements and focusing more on their risk based MFA stuff.
[1]https://www.microsoft.com/en-us/research/wp-content/uploads/...
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#80Earlier quoted context omitted.
So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.
US imposed individual sanctions and explicitly named hackers from the GRU after the DOD investigated 2016 election hacking, effectively authorizing their arrest if stepping on western soil. This will be handled diplomatically through the State Dept. first. There is little incentive to starting a war with Russia I don't think.