Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

81–90 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#81
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Did you also consider this[0] an act of war?

[0] (U.S. Escalates Online Attacks on Russia’s Power Grid) [ https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-r... ]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#82

The widespread use of unvalidated automatic updates will go down as one of the biggest security blunders of the last decade.

There was a fun one a few years ago when someone realized that Maven Central didn't require https so anyone could MITM arbitrary amounts of open source Java code. But I think this problem could be even more pervasive. Think about that giant green lock icon you see on secured sites. And then think about all the apps and devices making requests with no UI and we have no idea what they're all talking to until you have the patience and knowhow to operate wireshark.

Off the top of my head, the only real solution is to feed a lot of this arbitrary traffic through trusted brokers which is going to make us even more dependent on Google, Microsoft or whoever else takes up that mantle.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#83

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

One suspects they've given this advice for a long time... because their shit has been hacked for a long time.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#85
post #59

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

However I'm pretty sure PCIDSS does still say 90 days

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#90
post #4
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

I believe that you have mis-read their comment - they aren't saying Solar Winds is "yet another startup", they're saying that SolarWinds is incorporating 3rd party technology (the so-called supply chain attack on their build) without vetting it.

And, if we're being honest, those technologies probably are based off startup tech; SolarWinds purchases and incorporates startup companies (such as Vivid Cortex recently).

Post reply on HN