Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

211–220 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#211

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

I wonder if they use password managers. All the household-name corporations and small startups alike where I worked for the last decade used a password manager.

Selling a subscription to a government org should look like a tasty enough piece of revenue pie to attract multiple bidders, I assume.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#212

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

Neither of these hacks involved "back doors" as they are normally defined. One was an authentication bypass; the other was a supply chain attack. Neither involved any sort of deliberate covert access mechanism.

Let me be cystal clear. I've worked in domestic violence. Cops will use various tools to stalk their ex'es despite your claims that back door or priveleged access will not be abused.

Jump over to healthcare, the worker with full access to the govt it system for cases WILL lookup their friend / family members / neighbors / famous person if they see them on site or realize they are in system.

I have one experience with a private health HMO. A close relative, senior doctor, absolutely knew they would be immediately fired if they looked up family records. It was crazy, they would not do ANYTHING related to family stuff even by request of person involved. Obviously this place had some type of audit trail, some type of monitoring team for non-assigned patient record lookups etc.

My govt IT job, to do billing you had to be able to see case notes, and the system was integrated across of a ton of agencies, so everyone basically had access to everything and because you had to share logins and passwords (it took like 6 months to get a new account setup) there wasn't any accountability (not that I think they monitored anyway).

I came away very unimpressed. We had to use outdated IE / Java combos etc. as well and block all system updates. The default landing page was an unregistered domain name.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#214
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Digital war? Sure. We are probably hitting back right now. Traditional war? I hope not. 1) I don't have enough bottle caps saved up. and 2) in all seriousness, most humans would not survive WW3, not even those with bunkers.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#215

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

Punish won't do anything.

You can't punish lack of ability, just like you don't punish someone for scoring a B at school.

Everything happens after the fact, and no one knows what the next breach will be. And that will continue until the your average Joe's system no longer has 100 vendors each ordained by high management that basically acts as malware themselves.

Someone even started blaming the H1Bs, the mentality is amusing - fix nothing and find blame first and (often) blame it on the wrong thing - I'm glad I don't work for an organization that has the same mentality. Though I can certainly see many of the largest companies and a large percent of people have the exact MO. That also needs to change.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#216

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

And possibly related news? [0]

[0]: https://www.theepochtimes.com/crucial-logs-missing-from-antr...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#217

Russia's hacking/software capabilities have always fascinated me. I might be out of the loop, but it very much feels like this "online cold-war" is very one-sided towards Russia, which is ridiculous given US capabilities. Though, this could be attributed to the US simply not getting caught. Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told custo…

I'd highly recommend Sandworm by Andy Greenberg for more information about Russia's hacking capabilities.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#218

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

And possibly related news? [0] [0]: https://www.theepochtimes.com/crucial-logs-missing-from-antr...

Epoch Times. It's like Fox but turned up to 11.

Their origin story read like how we supported the original mujahideen in Afghanistan. We all knew how that turned out.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#219
post #59

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

None the less, until the pandemic hit the US in March, at least one large government agency still had silly password complexity requirements and expired passwords every 60 days. They seems to have suspended password rotation at some point since I haven't had to change my password since March, but it's not clear whether it's going to come back at some point or not.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#220
post #42

Earlier quoted context omitted.

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Because Russia has somewhat of an oil monopoly in Europe and the US doesn't like that. We've been being fed Russia war propaganda for at least a decade. If it even feels like a "Russia kind of thing" to the general public that is just the result of intentional conditioning by warmongers. It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the c…

You pretty much glossed over the whole Crimea thing in Europe. When has the US or the EU annexed part of a country in recent years?
Post reply on HN