So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
The entire Trump administration's been an act of war. They got classified intel, private phone calls with the president, numerous concessions, everything they could have possibly wanted in terms of foreign policy, including an abrupt and chaotic withdrawal from Syria where Russian troops literally took over American bases, and a significant number of GOP congressional representatives visiting Moscow on July 4th toget…
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
121–130 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#122Earlier quoted context omitted.
Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.
I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#123Earlier quoted context omitted.
Citation? I couldn't find anything on the web or here: https://pages.nist.gov/800-63-3/sp800-63b.html edit: I wasn't calling OP a liar, I just couldn't find it.
It's right there in section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Without those other mitigations, pw rotation may still help more than it hinders, although I am definitely not a fan of it and recommend implementing all of the NIST’s recs instead.
For those looking to head that route, haveibeenpwned offers an API to check hashes against previous breaches. For a pw strength meter, have a look at zxcvbn.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#124Earlier quoted context omitted.
Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.
I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#125Is this the same SolarWinds that owns Pingdom? https://www.solarwinds.com/pingdom
The two sites I monitored w/ that tool, we used it to determine when a 3rd party account’s login info has expired.
So, I would expect my saved credentials to be invalid, but that is just my anecdote.
The rest is just simple uptime and response time monitoring of specific URLs, which we publicly expose anyway, so no threat there.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#126> Malicious code added to an Orion software update may have gone undetected by antivirus software and other security tools on host systems thanks in part to guidance from SolarWinds itself. In this support advisory, SolarWinds says its products may not work properly unless their file directories are exempted from antivirus scans and group policy object restrictions. Ouch!
Not uncommon for software that has to do very "shady" stuff, although their other advisories are quite bullcrap.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#127Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told customers to ignore inaccurate checksums but they also failed basic server security.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#128When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.
SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#129So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#130Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0]
The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems.
I have no idea who "did" this, I don't really care. The NSA has been loading this footgun for decades.
[0] https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital-eb...