Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

121–130 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#121
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

The entire Trump administration's been an act of war. They got classified intel, private phone calls with the president, numerous concessions, everything they could have possibly wanted in terms of foreign policy, including an abrupt and chaotic withdrawal from Syria where Russian troops literally took over American bases, and a significant number of GOP congressional representatives visiting Moscow on July 4th toget…

On the plus side, no actual wars were started or joined. Like Jimmy Carter.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#122
post #58

Earlier quoted context omitted.

Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.

I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional

Although I do not disagree with your comment, I would do a double take befpre accepting the source you cite because they are very much incentived to proclaim the result they proclaim.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#123
post #68

Earlier quoted context omitted.

Citation? I couldn't find anything on the web or here: https://pages.nist.gov/800-63-3/sp800-63b.html edit: I wasn't calling OP a liar, I just couldn't find it.

It's right there in section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

Should be noted that NIST’s current recommendations are meant to be part of a number of mitigation’s including checking passwords against known-breach databases, rate-limiting, etc.

Without those other mitigations, pw rotation may still help more than it hinders, although I am definitely not a fan of it and recommend implementing all of the NIST’s recs instead.

For those looking to head that route, haveibeenpwned offers an API to check hashes against previous breaches. For a pw strength meter, have a look at zxcvbn.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#124
post #58

Earlier quoted context omitted.

Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.

I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional

you mean professionally run corporations like Equifax, Target or SolarWinds (published ftp password to github)?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#125
post #84

Is this the same SolarWinds that owns Pingdom? https://www.solarwinds.com/pingdom

Yes. Luckily that is an external monitoring tool, but they do allow ‘transactional’ monitoring, so some folks could have login info saved.

The two sites I monitored w/ that tool, we used it to determine when a 3rd party account’s login info has expired.

So, I would expect my saved credentials to be invalid, but that is just my anecdote.

The rest is just simple uptime and response time monitoring of specific URLs, which we publicly expose anyway, so no threat there.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#126

> Malicious code added to an Orion software update may have gone undetected by antivirus software and other security tools on host systems thanks in part to guidance from SolarWinds itself. In this support advisory, SolarWinds says its products may not work properly unless their file directories are exempted from antivirus scans and group policy object restrictions. Ouch!

Not uncommon for software that has to do very "shady" stuff, although their other advisories are quite bullcrap.

It's not just shady stuff. Recently, on a customer's Windows server, antivirus software randomly decided to permanently delete some our DLLs (!). We weren't doing anything remotely shady; it was a normal ASP.NET Core app.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#127
Russia's hacking/software capabilities have always fascinated me. I might be out of the loop, but it very much feels like this "online cold-war" is very one-sided towards Russia, which is ridiculous given US capabilities. Though, this could be attributed to the US simply not getting caught.

Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told customers to ignore inaccurate checksums but they also failed basic server security.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#128
post #4
post #2

When will people realize that slapping yet another startup's tech stack onto yours isn't going to magically fix anything and in fact just adds complexity and points of failure. I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

No longer publicly traded: https://www.solarwinds.com/company/press-releases/solarwinds...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#129
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

We (the public) have not been provided evidence that this was Russia. Let's not get ahead of ourselves. Some anonymous people claimed it's Russia. That is meaningless.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#130
Seems like a good time to plug an excellent book:

Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0]

The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems.

I have no idea who "did" this, I don't really care. The NSA has been loading this footgun for decades.

[0] https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital-eb...

Post reply on HN