Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

161–170 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#161

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking.

It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on.

I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#162
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

If the U.S. didn’t go to war over Crimea why would they go to war over this?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#163
Wow the hackers had free rein over basically any company that they wanted.

SolarWinds says it has over 300,000 customers including:

-more than 425 of the U.S. Fortune 500

-all ten of the top ten US telecommunications companies

-all five branches of the U.S. military

-all five of the top five U.S. accounting firms

-the Pentagon

-the State Department

-the National Security Agency

-the Department of Justice

-The White House

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#164
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Everyone country does this to every other country that they can. Not like the US doesn't (or at least try to) pull off stuff like this too. So if it's an act of war then every major power has pretty much at some point declared war on every other major power, even allies.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#165

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

This is the same congress that moved to largely indemnify Equifax?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#166

Earlier quoted context omitted.

We (the public) have not been provided evidence that this was Russia. Let's not get ahead of ourselves. Some anonymous people claimed it's Russia. That is meaningless.

It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward. https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...

Right, so anonymous sources who provided no evidence to the public. It's meaningless.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#167
The "Russia" allegation sounds like an extremely weak & repetitive claim made by people on a certain political side to divert attention away from their bad press for criminal behavior (to include all of the Chinese compromises that were recently revealed).

They're playing a VERY dangerous game, as if they would rather the entire world be destroyed before facing the possibilities of justice (Gitmo, military court tribunals, and everything else that the EO from 9/18 outlined).

The bottom line: the MSM has been full of $&@T for quite some time, and this claim in Reuters is most likely more of the same.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#168
post #167

The "Russia" allegation sounds like an extremely weak & repetitive claim made by people on a certain political side to divert attention away from their bad press for criminal behavior (to include all of the Chinese compromises that were recently revealed). They're playing a VERY dangerous game, as if they would rather the entire world be destroyed before facing the possibilities of justice (Gitmo, military court trib…

Microsoft and Fireeye have both made similar claims and released substantial technical details.

Attribution is hard, but those two companies have a solid reputation and do not make BS claims.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#169
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

If the U.S. didn’t go to war over Crimea why would they go to war over this?

Because Crimea is another country/outside of usa jurisdiction? Whereas this is a direct attack to USA institutions/government.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#170
post #158

Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…

Whilst not being a "cloud is someone else's computer" adherent, the notion SaaS products can't be misconfigured into opening up security holes not present / so serious in some on-prem environments doesn't hold water - see the last decade's stories of accidentally open S3 buckets, plaintext secrets pushed to public GitHub repos, and all manner of other "minor misconfigurations"
Post reply on HN