So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
> the Russian government You sure about that? "They" have been claiming Russia is the boogie man for years, but it's never been proven. In this case, it does appear like a complex hack. Wouldn't be surprised if it's China, Iran, North Korea, Russia, U.S. Government (yes, hacking itself), etc.
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
151–160 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#152So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#153Earlier quoted context omitted.
Maybe they were just bribed?
An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…
The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics.
I wish business continuity planning (which would include infosec procedures but has a much wider overall scope) was paid more attention and more widely scrutinized.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#154Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#155Earlier quoted context omitted.
Yeah, I know it's not actually recommended anymore, but the policy makers don't care. They're doing CYA policy. They do whatever seems to be the strongest possible thing, users and reality be damned. I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-…
> They do whatever seems to be the strongest possible thing It's not that, it's inertia and poor incentive structures. In a large organization, if a policy was set in place by someone else, then, even when you know it's a sub-par policy, it's still in your interest to leave it alone. Doing so gives you a way to deflect blame in the event of a breach related to that decision. You can just blame the policy itself. If,…
This is the psychological/economics point of view, and I think it's the correct one for this problem. The other tricky issue, besides the CYA prioritization, is that being a dynamic entity requires other entities to do the same. If you start changing procedures in your section, other sections that rely on you need to adapt to these, and they may have the CYA attitude and resist that change.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#156https://mattermost.com/blog/coordinated-disclosure-go-xml-vu...
It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#157So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…
See: moon landing. Of course we went to the moon otherwise, what, 50,000 people are keeping a perfect and scandalous secret for half a century?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#1581. You misconfigure the onprem software, making it more insecure than the alternatives. This does not occur with SaaS products.
2. The software delivery system is tampered with, and you download and run malicious code on your systems with high privileges. If you don't run it, this can't happen.
Cloud deployments aren't obviously safer, but they have clear advantages unless you are willing to pay top people to work on and secure each onprem deployment full-time.
NB: I don't actually believe "the cloud" is fundamentally more or less secure than onprem deployments. Rather, I frequently hear people argue that a website being hacked - or the potential for it - justifies a movement to onprem, and I think this is (usually) false.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#159Earlier quoted context omitted.
Maybe they were just bribed?
An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…
2. My own knowledge of folk rock and subsequent visits to Google and Wikipedia have not helped me interpret this reference, in this context:
"Electric Dylan/Pete Seeger with the axe"
Help, please :-D
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#160Earlier quoted context omitted.
Adding snake oil usually adds more attack vectors rather than removing them. Look at all the "endpoint protection" and AV exploits surfacing almost every week.
Yes. Security vendors have to add a bunch of snake oil products. If they just did "consulting" and trained the staff against social security attacks, and improved a company's policies, how could managers that authorized the expense justify it? Where's the shiny "product" that "keep us safe"?"Do you mean we have to periodically expend money to keep ourselves safe? I'll go with Vendor B, they have a blockchain-based Ma…
Salesmen (external or even worse internal) convincing inexperienced CTOs or VPs that they need regardless of any real world factors...
These are the people I would throw out with their own bathwater.