Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

251–260 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#251
post #158

Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…

> 1. You misconfigure the onprem software, making it more insecure than the alternatives. This does not occur with SaaS products.

Misconfigured, insecure AWS configurations are a dime a dozen. Not sure this point tracks.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#252

Russia's hacking/software capabilities have always fascinated me. I might be out of the loop, but it very much feels like this "online cold-war" is very one-sided towards Russia, which is ridiculous given US capabilities. Though, this could be attributed to the US simply not getting caught. Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told custo…

In US/western-centric media, you aren't likely to hear a lot of exploits of new malware that the US deployed in Russia or China. The targets of hacking by the US are not countries that publicize when they are infiltrated.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#254

Earlier quoted context omitted.

Neither of these hacks involved "back doors" as they are normally defined. One was an authentication bypass; the other was a supply chain attack. Neither involved any sort of deliberate covert access mechanism.

I don't think OP meant to imply that backdoors had anything to do with this. It's meant to underscore the argument against backdooring encryption by pointing out that when you trust some entity with a backdoor, you're potentially opening that backdoor to anyone who can break that entity's security, which may be very, very flawed.

That's unrelated to backdoors (deliberate covert access mechanisms). All parties with access to data, regardless of whether it is via a backdoor, can put that data at risk due to their own security.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#255

Earlier quoted context omitted.

And you posted this US military vulnerability on a publicly searchable internet site? head desk

TO be fair, it isn't really secret, if you look at any job posting for lackland, you'll see it mentioned over and over.. https://careers-salientcrgt.icims.com/jobs/11200/network-sys... ' https://i.imgur.com/d8KbSZp.png But, wow, imagine that's a job, just walk in, look at two programs and swap out parts as needed.

The qualifications reads 'Someone from HR came up with this'

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#256

Earlier quoted context omitted.

Doubt it - that bug has been known by Go/Mattermost since August.

How would SolarWinds know about it if it wasn't publicly disclosed until today? Also, I realize the SAML -> SolarWinds connection is a bit of speculation on my part, but SAML is mentioned in Microsoft's advisory: https://msrc-blog.microsoft.com/2020/12/13/customer-guidance... It sounds like a privilege escalation using the Go/SAML issue.

Also, this hack happened in March, so your timeline is irrelevant.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#257

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

That is Serv-U, not Orion. [0]

You might want to avoid The Epoch Times as a source of information in the future, they are unreliable. [1]

[0] https://krebsonsecurity.com/2020/12/u-s-treasury-commerce-de...

[1] https://mediabiasfactcheck.com/the-epoch-times/

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#258
post #189

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

I guess if you can be as successful as SolarWinds with that level of incompetence I should stop worrying so much about myself.

You'll be surprised at how technically illiterate most corporations are and how marketing and not engineering are responsible for the success for some of the software companies.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#259
post #58

Earlier quoted context omitted.

Incompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.

I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional

Professionally managed versus family managed. Not surprising, both are not quite related to the technical matter being discussed.

Muskets beat bows and arrows, but we're in the 21st century now.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#260
post #227

Earlier quoted context omitted.

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

This seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.

Is the proper response to tell a customer to install the package anyway because it's just a partial download or something similar? Regardless, it seems irresponsible.
Post reply on HN