Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

151–160 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#151
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

> the Russian government You sure about that? "They" have been claiming Russia is the boogie man for years, but it's never been proven. In this case, it does appear like a complex hack. Wouldn't be surprised if it's China, Iran, North Korea, Russia, U.S. Government (yes, hacking itself), etc.

Who is "they"? And what hasn't been proven, are you referring to Russian interference in 2016?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#152
post #42
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Don't you know? Liberals automatically blame Russia. Conservatives automatically blame China. Me, I Blame Canada. Damn you, Gordon Lightfoot!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#153

Earlier quoted context omitted.

Maybe they were just bribed?

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

Sounds like a solid information security incident response mechanism!

The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics.

I wish business continuity planning (which would include infosec procedures but has a much wider overall scope) was paid more attention and more widely scrutinized.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#155

Earlier quoted context omitted.

Yeah, I know it's not actually recommended anymore, but the policy makers don't care. They're doing CYA policy. They do whatever seems to be the strongest possible thing, users and reality be damned. I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-…

> They do whatever seems to be the strongest possible thing It's not that, it's inertia and poor incentive structures. In a large organization, if a policy was set in place by someone else, then, even when you know it's a sub-par policy, it's still in your interest to leave it alone. Doing so gives you a way to deflect blame in the event of a breach related to that decision. You can just blame the policy itself. If,…

> It's not that, it's inertia and poor incentive structures.

This is the psychological/economics point of view, and I think it's the correct one for this problem. The other tricky issue, besides the CYA prioritization, is that being a dynamic entity requires other entities to do the same. If you start changing procedures in your section, other sections that rely on you need to adapt to these, and they may have the CYA attitude and resist that change.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#156
This also came out today:

https://mattermost.com/blog/coordinated-disclosure-go-xml-vu...

It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#157

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Given the scope of this product — basically everyone runs it — any chance that this is some sort of hoax will be mitigated by the “too large to be a hoax” thing. Probably some sort of fallacy whose name I don’t know.

See: moon landing. Of course we went to the moon otherwise, what, 50,000 people are keeping a perfect and scandalous secret for half a century?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#158
Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments:

1. You misconfigure the onprem software, making it more insecure than the alternatives. This does not occur with SaaS products.

2. The software delivery system is tampered with, and you download and run malicious code on your systems with high privileges. If you don't run it, this can't happen.

Cloud deployments aren't obviously safer, but they have clear advantages unless you are willing to pay top people to work on and secure each onprem deployment full-time.

NB: I don't actually believe "the cloud" is fundamentally more or less secure than onprem deployments. Rather, I frequently hear people argue that a website being hacked - or the potential for it - justifies a movement to onprem, and I think this is (usually) false.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#159

Earlier quoted context omitted.

Maybe they were just bribed?

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

1. That's impressive

2. My own knowledge of folk rock and subsequent visits to Google and Wikipedia have not helped me interpret this reference, in this context:

"Electric Dylan/Pete Seeger with the axe"

Help, please :-D

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#160

Earlier quoted context omitted.

Adding snake oil usually adds more attack vectors rather than removing them. Look at all the "endpoint protection" and AV exploits surfacing almost every week.

Yes. Security vendors have to add a bunch of snake oil products. If they just did "consulting" and trained the staff against social security attacks, and improved a company's policies, how could managers that authorized the expense justify it? Where's the shiny "product" that "keep us safe"?"Do you mean we have to periodically expend money to keep ourselves safe? I'll go with Vendor B, they have a blockchain-based Ma…

Thanks now my skin's crawling again from the all too familiar cesspool feeling.

Salesmen (external or even worse internal) convincing inexperienced CTOs or VPs that they need regardless of any real world factors...

These are the people I would throw out with their own bathwater.

Post reply on HN