Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

261–270 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#261

Earlier quoted context omitted.

Epoch Times. It's like Fox but turned up to 11. Their origin story read like how we supported the original mujahideen in Afghanistan. We all knew how that turned out.

Is the story actually false or is this just an ad hominem attack?

It is not an ad hominem attack when accurately describing the well known attribute of the source.

The story also turned out to be not necessarily true, from another comment.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#262
post #91

Sigh. "Engineers are expensive, so don't build, buy!" How about... the middle way? Let your own engineers deploy open source, something you can verify, even audit, if you ever have to. Ah, I forgot. Those usually don't come with fat envelopes from the provider to the people making the decisions.

Finally, the post I was looking for, sadly voted below calls for Biden to invade Russia.

Literally how is this not the take away from this story? It's time to stop putting stock in one big company to do all the work for you.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#263

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

We are in WW3. It's information warfare. People don't know who the enemy is. They don't even know we are at war.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#264

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

Is it possible that there could be SolarWinds customers who are not vulnerable because, for whatever reason, they did not enable/install updates. Were updates to the Orion software necessary for the original software to continue to function or were they optional.

They were optional. I know a company still using a version from 2015/2016.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#265

Earlier quoted context omitted.

Given the scope of this product — basically everyone runs it — any chance that this is some sort of hoax will be mitigated by the “too large to be a hoax” thing. Probably some sort of fallacy whose name I don’t know. See: moon landing. Of course we went to the moon otherwise, what, 50,000 people are keeping a perfect and scandalous secret for half a century?

The best proof that the United States went to the Moon is that there was extensive Russian spying going on at the time, but Russia never claimed that the US was lying about the Apollo program.

The best proof that we went to the moon is that we left mirrors there that we use to bounce lasers off of to detect the distance to the moon.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#266

Russia's hacking/software capabilities have always fascinated me. I might be out of the loop, but it very much feels like this "online cold-war" is very one-sided towards Russia, which is ridiculous given US capabilities. Though, this could be attributed to the US simply not getting caught. Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told custo…

We are now in the Code War.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#267

Earlier quoted context omitted.

It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward. https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...

Right, so anonymous sources who provided no evidence to the public. It's meaningless.

The sources are not anonymous to Reuters and they were authoritative enough in the matter to publish. It is not meaningless.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#268

Earlier quoted context omitted.

So it's an act of war. Now what? Does the US escalate to a shooting war with the second biggest nuclear power in the world? So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.

There are ways for US to retaliate through espionage, such as doing a mass round up of minor russian spy assets that usually aren't worth the effort to go after, going after russian operations in places in which neither country have jurisdiction in, exposing blackmail of some random oligarch, stirring up unrest with plausible deniability, etc. Essentially make life difficult for the people who actually run Russia.

You risk destroying your leverage if you do this, but some partial retaliation is indeed a good idea. It might be the case that those avenues for retaliation are already almost saturated.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#269

Earlier quoted context omitted.

Right, so anonymous sources who provided no evidence to the public. It's meaningless.

The sources are not anonymous to Reuters and they were authoritative enough in the matter to publish. It is not meaningless.

Do you remember when a named source, Colin Powell, showed some photoshops of "weapons lab trucks" to the UN leading to us going to war in multiple countries resulting in millions of dead people? That was a named person with claimed evidence. This is even less credible than Powell.

It's hard to get less credible than unnamed sources with no evidence.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#270

Earlier quoted context omitted.

Is the story actually false or is this just an ad hominem attack?

It is not an ad hominem attack when accurately describing the well known attribute of the source. The story also turned out to be not necessarily true, from another comment.

> It is not an ad hominem attack when accurately describing the well known attribute of the source.

That is literally what an ad hominem attack is. Attacking the source instead of the claim.

> The story also turned out to be not necessarily true, from another comment.

The other comment doesn't actually contradict the story, though it is pertinent information.

The story discusses the problems with Orion and points out that Dominion uses SolarWinds software, with a link to the page where they use SolarWinds Serv-U. That doesn't necessarily mean they also use Orion, but the article doesn't claim that.

Interestingly (?) they just changed the linked page in response to the story. It no longer contains the SolarWinds logo when it did earlier:

http://web.archive.org/web/20201214102053/https://dvsfilesha...

I don't understand why people think doing things like that helps them. Of all the election fraud claims, the Dominion Hugo Chavez bit is the furthest out in conspiracy theory land, and then they do things like that which are just going to end up on Glenn Beck's nightly rant.

Post reply on HN