So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Lmao act of war. You going to fight? This is just what countries do to eachother. Welcome to the 21st century.
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
141–150 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#142Earlier quoted context omitted.
Not uncommon for software that has to do very "shady" stuff, although their other advisories are quite bullcrap.
It's not just shady stuff. Recently, on a customer's Windows server, antivirus software randomly decided to permanently delete some our DLLs (!). We weren't doing anything remotely shady; it was a normal ASP.NET Core app.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#143Earlier quoted context omitted.
No, not at all. It's political theatre the media is playing. Russia has been the big bad wolf since 2016. It's far more likely China than Russia, although it could be a variety of different states/parties.
> Russia has been the big bad wolf since 2016. For a very good reason.
Russia is in NO uncertain terms a hostile and aggressive nation that we all need to be wary of.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#144Earlier quoted context omitted.
What’s preventing more rapid uptake of integrating with the CAC system? I can use my CAC when going through TSA for ID (and verification is sub 10 seconds) but other agencies keep dragging their feet.
It seems to be laziness on the part of the IT system makers. There are (mostly) standardized ways to authenticate a CAC and associate it with a user for an information system. But people seem to prefer to roll their own. Either using traditional username/password combos, or a worse solution. The worse one is this (seen a few times): Username/password and then you register your CAC with it. They only check the CAC its…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#145Earlier quoted context omitted.
The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…
>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.
In an office? Absolutely not, never, not once. Offices are not private and not secure and in any kind of even vaguely sensitive setting allowing a colleague to have access to your password and impersonate you is a massive risk.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#146Earlier quoted context omitted.
> SolarWinds hasn't bothered to revoke their certs or remove the package Amazing. While I'm sure the attackers have already shut up shop and the threat no longer exists, this feels insanely tone-deaf from SolarWinds.
Maybe they were just bribed?
I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down all inbound/outbound traffic, snapshot all our running machines for later forensics, lock our AWS IAM access down to a single incident response account, and move DNS for our web properties to a "we've been hacked" page. (OK, it obviously doesn't say that, but something similar that has been heavily vetted by legal and marketing ;-)). We've drilled and timed it out and can stop the ship in ~5 minutes.
Either SolarWinds doesn't have a major security incident response plan, or they don't have the stomach to pull the trigger. Neither is promising.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#147SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#148Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#149Earlier quoted context omitted.
The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…
>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.
It is moronic to write passwords down and stick them underneath the keyboard.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#150Earlier quoted context omitted.
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?
One suspects they've given this advice for a long time... because their shit has been hacked for a long time.