Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

91–100 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#91
Sigh.

"Engineers are expensive, so don't build, buy!"

How about... the middle way? Let your own engineers deploy open source, something you can verify, even audit, if you ever have to.

Ah, I forgot. Those usually don't come with fat envelopes from the provider to the people making the decisions.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#92
post #4

Earlier quoted context omitted.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". Today it is. If we knew when SolarWinds was added to the government systems, his comment might stand.

And yesterday's startup is tomorrow's billion dollar company, often with nothing changed except the number of customers.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#94
post #47

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

Indeed. Sports Team + Year, Season + Year, Company + Year or some other such combination should get you a good 10% or more of your users with only a few dozen permutations. They wrote 60 days into FEDRAMP I believe, something I jaw-droppingly realized last year sometime. Whoever is writing these policy frames don't know what they're doing. NIST did away with those periodic password change recommendations for a very g…

According to another comment, they do:

> It's right there in section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

https://news.ycombinator.com/item?id=25421584

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#95
post #42
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Because it definitely couldn’t be China or any other country.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#96

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

What’s preventing more rapid uptake of integrating with the CAC system? I can use my CAC when going through TSA for ID (and verification is sub 10 seconds) but other agencies keep dragging their feet.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#97

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

> SolarWinds hasn't bothered to revoke their certs or remove the package

Amazing. While I'm sure the attackers have already shut up shop and the threat no longer exists, this feels insanely tone-deaf from SolarWinds.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#98
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

There are ways for US to retaliate through espionage, such as doing a mass round up of minor russian spy assets that usually aren't worth the effort to go after, going after russian operations in places in which neither country have jurisdiction in, exposing blackmail of some random oligarch, stirring up unrest with plausible deniability, etc.

Essentially make life difficult for the people who actually run Russia.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#99
post #40
post #4

Earlier quoted context omitted.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

Willy-nilly dropping tools into core infrastructure is largely how government IT works. Corporate IT, too, from what I've seen.

That's very true, In my limited experience, they are tools sold to non-technical leadership that are either thrown to technical staff to deal with and implement or require letting yet another vendor have network access to manage. It adds up to a hot mess.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#100
This is why all this bullshit about "let's add a backdoor to all encryption just for the government" is just that: bullshit. A year or so after it is added, it will be available to every government on earth this way, and a year after, on your favourite warez site...
Post reply on HN