U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
191–200 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#192So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Ultimately, the hack is the practical responsibility of the victim.
Don't fall for the Kissinger style war mongering.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#193SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#194A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…
Neither of these hacks involved "back doors" as they are normally defined. One was an authentication bypass; the other was a supply chain attack. Neither involved any sort of deliberate covert access mechanism.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#195SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#196Earlier quoted context omitted.
Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.
> Why are there so many people who absolutely deny Russia does any hacking. Because there are many people paid to do so. (and soon if not already automated bots).
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#197SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#198SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Is it possible that there could be SolarWinds customers who are not vulnerable because, for whatever reason, they did not enable/install updates. Were updates to the Orion software necessary for the original software to continue to function or were they optional.
https://www.zdnet.com/article/sec-filings-solarwinds-says-18...
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#199SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
I guess if you can be as successful as SolarWinds with that level of incompetence I should stop worrying so much about myself.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#200So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?
Tense is wrong, they have this ability RIGHT NOW to a very high degree of certainty. Just because the tip of the iceberg has been discovered doesn't mean its mitigated. Even Fireeye is probably still compromised. It will take a while to understand the actual scope of this. And in the meantime new attacks are likely happening also.