Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

131–140 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#131

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all).

Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#132
post #42
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Because Russia has somewhat of an oil monopoly in Europe and the US doesn't like that. We've been being fed Russia war propaganda for at least a decade. If it even feels like a "Russia kind of thing" to the general public that is just the result of intentional conditioning by warmongers.

It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the culprit is.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#133

Seems like a good time to plug an excellent book: Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0] The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems. I have no idea who "did" this, I don't really care. The…

I really enjoyed The Hacker and the State by Ben Buchanan. It explores why various nations pursue cyber operations the way they do.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#134

Russia's hacking/software capabilities have always fascinated me. I might be out of the loop, but it very much feels like this "online cold-war" is very one-sided towards Russia, which is ridiculous given US capabilities. Though, this could be attributed to the US simply not getting caught. Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told custo…

I read Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon a few weeks ago, and really enjoyed it.

I'd recommend giving it a read. It gives an accurate-but-uncomfortable overview of how the US government handles cyber security issues.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#135
post #33

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

We can try sanctions, but we've pretty much maxed out that route after the Crimea annexation. If we do nothing, we're sending the message that these actions are okay.

The US Government does stuff like this to other countries all. the. time.

We don't hear about it much. But if this is an "act of war" the US has conducted dozens of these kinds of "attacks" on others over the last ten or fifteen years.

Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0]

[0]: https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital-eb...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#136
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

We (the public) have not been provided evidence that this was Russia. Let's not get ahead of ourselves. Some anonymous people claimed it's Russia. That is meaningless.

It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward.

https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#138

Earlier quoted context omitted.

Not uncommon for software that has to do very "shady" stuff, although their other advisories are quite bullcrap.

It's not just shady stuff. Recently, on a customer's Windows server, antivirus software randomly decided to permanently delete some our DLLs (!). We weren't doing anything remotely shady; it was a normal ASP.NET Core app.

Also, any task that involves reading or writing files will, in the presence of cutomer antivirus software, turn into a random number generator on whether the read/write goes through at all, how long it takes, etc. We are constantly having issues with customer AV because of this.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#139
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

If it were Iran, Turkey, etc the missiles would already be in the air

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#140

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

> SolarWinds hasn't bothered to revoke their certs or remove the package Amazing. While I'm sure the attackers have already shut up shop and the threat no longer exists, this feels insanely tone-deaf from SolarWinds.

Maybe they were just bribed?
Post reply on HN