Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

241–250 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#241

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

And until we end the H1B visa and only allow Americans or American allies to run the IT systems of companies in America.

Solarwinds doesn’t have h1bs according to public database probably because they work on government contracts. So how does ending h1b stop this attack?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#242

Earlier quoted context omitted.

And possibly related news? [0] [0]: https://www.theepochtimes.com/crucial-logs-missing-from-antr...

Epoch Times. It's like Fox but turned up to 11. Their origin story read like how we supported the original mujahideen in Afghanistan. We all knew how that turned out.

Is the story actually false or is this just an ad hominem attack?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#243

Earlier quoted context omitted.

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

I'm curious, are people saying that "Russia doesn't do any hacking" or that "there isn't yet enough evidence that this specific attack is by Russia". Those are two very different claims. I don't think there's any doubt about the former claim, personally. The latter though, I think it's too early to tell, especially since we've seen recently how certain hackers have explicitly started putting bait signs from other nat…

> The latter though, I think it's too early to tell, especially since we've seen recently how certain hackers have explicitly started putting bait signs from other nation-states to misdirect.

Has there been any indication at all that it was Russia in particular? A lot of people believe it was a state-level attacker based on the sophistication of the attack, but even conceding that doesn't make Russia the only alternative.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#244

Earlier quoted context omitted.

>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.

It depends entirely on your security and threat model. Me, working from home? I'll write down the password for my netflix account and wifi - sure. In an office? Absolutely not, never, not once. Offices are not private and not secure and in any kind of even vaguely sensitive setting allowing a colleague to have access to your password and impersonate you is a massive risk.

Yeah, it really depends - in many cases an attacker gaining local access is game over anyway & less technical users will at least have harder to guess passwords. In other cases it's indeed a bad idea.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#245
post #52
post #41

Earlier quoted context omitted.

For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(

PCI/DSS hasn't yet, so that's holding up a lot of them.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#246
So was the election hacked too? I'm a little confused how Biden can get 80 million votes, and almost no one watched his acceptance speech today. 40k views on youtube.

The 6k vote flipping in Michigan was claimed to be some sort of computer error. But why were the logs deleted? that seems like a hacker thing to do to delete the logs. A judge just released the audit report.

https://www.freep.com/story/news/politics/elections/2020/12/...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#247

Seems like a good time to plug an excellent book: Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0] The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems. I have no idea who "did" this, I don't really care. The…

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#248

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

US gov guidance from NIST no longer suggests regular password resets, but that guidance hasn't gotten out yet.

> Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.

Source: https://pages.nist.gov/800-63-3/sp800-63b.html

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#249

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

What punishment do you want? How would you calculate damages?
Post reply on HN