Earlier quoted context omitted.
I believe it was an insider. I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.
I believe not everyone always checks the checksums. "Never ascribe to malice that which is adequately explained by incompetence"
U.S. Treasury breached by hackers backed by foreign government – sources
371–380 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#372Earlier quoted context omitted.
A very common source of information to reporters are people who aren't authorized to speak about an issue, or people who have informal relationships with the press and don't want their names revealed publicly. There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does w…
I'm perfectly willing to trust that the WaPo is reporting truthfully and that their sources are legit, but without concrete evidence it's hard to judge how serious the allegation really is. Is it "they forgot to switch their VPN on once and we got a direct connection from an IP that belongs to the Russian state" like that other time (still manipulable but fairly conclusive IMO) or is it "that really looks like the mo…
So in that spirit I agree with you. What this looks like, so far, is a sophisticated Russian attack. From here, we’re going to learn more, and that new info may change how we understand what’s happened substantially.
Though I will say I personally don’t care much that the source is anonymous, because I trust WaPo to vet what they’ve said with other sources. It’s not a perfect system, but it’s not like journalists are unaware of the groups trying to manipulate them.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#373Earlier quoted context omitted.
The difference is that it wasn't hard to work out the claims were nonsense. WMDs are hugely expensive, and the Iraqi economy was running on fumes at that point. That combined with US belligerence against Iraq made the claims improbable. But Russia actually does have a strong black hat culture, with links to the political establishment. Putin is a technologically savvy kind of despot who likes sneaky low-cost high-ret…
That's all well and good, but it fails to account for potential action by state actors other than Russia. Everything you have said applies just as much to China, if not more so.
At some point you have to trust others to be good at their jobs, and when an org like WaPo demonstrates their proficiency over and over again, their believability rises.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#374Earlier quoted context omitted.
Really? What's that problem called? As you stated it, it seems too vague to be considered "open" or "closed".
Provable Security: https://en.wikipedia.org/wiki/Provable_security If you read that article you'll see that current approaches don't even attempt some kinds of proofs such as proof of security against side channel attacks. It goes by other names as well such as proof of code correctness: https://www.schneier.com/blog/archives/2009/10/proving_a_com... A major problem with current attempts at proofs is you can at best…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#375>The breach presents a major challenge to the incoming administration of President-elect Joe Biden as officials investigate what information was stolen and try to ascertain what it will be used for. Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:…
If you're going to lecture others on correctness, you should probably make damn sure that you've got every little detail exactly right yourself (since, apparently, anything less than absolute perfection is completely unacceptable). (I believe you'll find that the "A" is for "Availability", not "Accessibility".)
https://www.doc.ic.ac.uk/~ajs300/security/CIA.htm
https://www.pearsonitcertification.com/articles/article.aspx...
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#376>The breach presents a major challenge to the incoming administration of President-elect Joe Biden as officials investigate what information was stolen and try to ascertain what it will be used for. Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:…
> First of all, don't end your sentence with a preposition There isn’t a real rule against that in English grammar. See https://www.merriam-webster.com/words-at-play/prepositions-e...
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#377Earlier quoted context omitted.
Show me a single project where the functional specs were complete when given to the developers and external concerns didn't dictate any implementation details. All of the projects I've been on have had changing specs, right up to and through release. I love the architecture weenie role. It's tons of fun. But eventually you need to build something and only with experience do you discover the first set of complications…
>So I agree I guess, but don't at the same time. I suppose I do too. While a lack of designed-in security is often the (sometimes disastrous) result, I posit that it's more about a lack of knowledge/education around good software security design/implementation than spec changes or scope creep. If good security design practices were stressed when teaching software development (and/or included in resources for autodida…
It probably depends on what your team is good at. I tend to work in fairly security conscious teams. They check the length of buffers, don't rely on anything from the user, etc. So most of our issues tend to be from our architecture being drastically changed to integrate our solution into something else, or vice versa. Stuff is dropped on us, opaque libraries and internal code, and entirely new goals created around the big stuff, data persistence, key management, and so on.
But when I had an actual stable product that could not get spec changes (it was custom hardware) we knew from the beginning how the project would go and how all of the pieces would fit and it went together cleanly. But, it turns out many embedded engineers don't (didn't maybe, it was a while ago) program as defensively because they're used to owning the entire scope. If they put a value somewhere they expect it to be there, unmolested, when they want it. That project was full of buffer overflows and bad crypto.
> If good security design practices were stressed when teaching software development (and/or included in resources for autodidacts)
Yeah. I'm not sure how but it does tend to be lacking. Everyone probably needs a different hook. For me it was quality. How could I say my software does X if you have a way to break it?
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#378Earlier quoted context omitted.
Hahaha our military can't even figure out boots for the troops, you think we can hack the US Government? As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence. We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.
You may not be aware, but Canada does have a sophisticated organization dedicated to electronic security: https://en.m.wikipedia.org/wiki/Communications_Security_Esta...
Do you think a Wiki article can capture the staggering incompetence that's endemic within the Canadian public sector?
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#379Earlier quoted context omitted.
Copying my reply to GP: This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation. But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translat…
This confusion is easily avoided by saying “country,” or if you still want your writing to be verbose you could say “government” or “government-backed actor.”
"Governmental actor" would be a better international-friendly term for use in computer security, outside of the parochial world of US national security discourse.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#380Earlier quoted context omitted.
I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…
Copying my reply to GP: This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation. But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translat…
US law actually uses "state" in a sense closer to the European and broader international sense. e.g. a "state actor" includes both the states and the federal government, and is used to describe any entity bound by the restrictions of the Bill of Rights. (e.g. state actors are bound by the First Amendment, whereas private actors can restrict speech all they want)