Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

111–120 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#111

RELEVANT XKCD: https://xkcd.com/936/

Though it should be noted those “4 random word” passwords are strong only if the words are truly random (and the string is less likely to be memorable in this case).

A password generator that allows retries means people will hit that button until the string is memorable, reducing the entropy.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#112

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

What’s preventing more rapid uptake of integrating with the CAC system? I can use my CAC when going through TSA for ID (and verification is sub 10 seconds) but other agencies keep dragging their feet.

It seems to be laziness on the part of the IT system makers. There are (mostly) standardized ways to authenticate a CAC and associate it with a user for an information system. But people seem to prefer to roll their own. Either using traditional username/password combos, or a worse solution.

The worse one is this (seen a few times): Username/password and then you register your CAC with it. They only check the CAC itself for the cert expiration date. When it does finally expire (or gets revoked, say you need a new one early like happened to me a couple times, not to loss just became unreliable in the CAC reader), then you have to use the username/password combo (the password has been getting updated every 60-90 days during all this time) and register your new CAC.

But, since they aren't checking revocation data a stolen CAC + PIN (say it's weak, beaten out of you, or they observe you using it) even revoked would still be able to authenticate against that system until the cert expires or the admin (usually) manually removes the revoked CAC.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#113
post #4

Earlier quoted context omitted.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". Today it is. If we knew when SolarWinds was added to the government systems, his comment might stand.

Startup or not, government contracts require certain certifications.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#114
post #11

Ouch. Via a security provider. Thats ugly no matter how you look at it

Adding snake oil usually adds more attack vectors rather than removing them. Look at all the "endpoint protection" and AV exploits surfacing almost every week.

Yes. Security vendors have to add a bunch of snake oil products.

If they just did "consulting" and trained the staff against social security attacks, and improved a company's policies, how could managers that authorized the expense justify it? Where's the shiny "product" that "keep us safe"?"Do you mean we have to periodically expend money to keep ourselves safe? I'll go with Vendor B, they have a blockchain-based Machine Learning tool that's going to safeguard us against current and future threats!"

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#115

Earlier quoted context omitted.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

No, not at all. It's political theatre the media is playing. Russia has been the big bad wolf since 2016. It's far more likely China than Russia, although it could be a variety of different states/parties.

> Russia has been the big bad wolf since 2016.

For a very good reason.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#117
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Tense is wrong, they have this ability RIGHT NOW to a very high degree of certainty.

Just because the tip of the iceberg has been discovered doesn't mean its mitigated. Even Fireeye is probably still compromised. It will take a while to understand the actual scope of this.

And in the meantime new attacks are likely happening also.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#118
post #59

Earlier quoted context omitted.

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

However I'm pretty sure PCIDSS does still say 90 days

all the more reason to prioritize minimization of scope for PCI ;)

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#119
So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh.

Saying "APT29" or "CozyBear" doesn't make the accusation any more credible.

If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?"

It's pretty amusing, in a depressing way, to see how quickly so many otherwise intelligent people can be made to snap to attention and fight the Russian Menace with a few anonymous government claims.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#120
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Are you personally willing to go to war? Are you willing to be a foot soldier? Do you wish to kill? Do you wish to be killed?

I do not want to go to war over this, and generally I have friends from a number of countries in the east but make no mistake: if my country asks me to defend its borders or even NATO borders I'll be there[1], even if it is many years since I finished draft and I know have a family. The alternative will probably be worse.

Anyways, no sane, decent person should wish a war.

[1]: I am a whole lot less interested in defending us around the middle East and in Afghanistan though.

Post reply on HN