Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

271–280 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#271

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

That is Serv-U, not Orion. [0] You might want to avoid The Epoch Times as a source of information in the future, they are unreliable. [1] [0] https://krebsonsecurity.com/2020/12/u-s-treasury-commerce-de... [1] https://mediabiasfactcheck.com/the-epoch-times/

> That is Serv-U, not Orion.

The next question is obviously whether they use Orion in addition to Serv-U. Or whether the Serv-U updater was compromised in addition to Orion.

> You might want to avoid The Epoch Times as a source of information in the future, they are unreliable.

Note that they get the same rating ("MIXED") as CNN, MSNBC and Fox News:

https://mediabiasfactcheck.com/cnn/

https://mediabiasfactcheck.com/msnbc/

https://mediabiasfactcheck.com/fox-news/

Not that this is any kind of ringing endorsement of The Epoch Times.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#272

Earlier quoted context omitted.

Solarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.

And you posted this US military vulnerability on a publicly searchable internet site? head desk

My employer has a knowledgebase on the public internet that is littered with lists of softwares and practices. There are thousands of employees. Name dropping software should be a risky thing to do, but that isn’t the world we live in.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#273

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Krebs: Update, 8:30 p.m. ET: An earlier version of this story incorrectly stated that FireEye attributed the SolarWinds attack to APT29. That information has been removed from the story.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#274

Earlier quoted context omitted.

I don't think OP meant to imply that backdoors had anything to do with this. It's meant to underscore the argument against backdooring encryption by pointing out that when you trust some entity with a backdoor, you're potentially opening that backdoor to anyone who can break that entity's security, which may be very, very flawed.

That's unrelated to backdoors (deliberate covert access mechanisms). All parties with access to data, regardless of whether it is via a backdoor, can put that data at risk due to their own security.

This is only unrelated if you don't consider government-mandated master key escrow a "backdoor," which seems deliberately obtuse to me. Regardless, the OP's point was that this is an additional argument against governments mandating a way to access your encrypted data, because you shouldn't be compelled to trust anyone else with a "don't worry, only we will have access" sort of system.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#275

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

> some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on.

So...Operation Mockingbird?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#276

Earlier quoted context omitted.

TO be fair, it isn't really secret, if you look at any job posting for lackland, you'll see it mentioned over and over.. https://careers-salientcrgt.icims.com/jobs/11200/network-sys... ' https://i.imgur.com/d8KbSZp.png But, wow, imagine that's a job, just walk in, look at two programs and swap out parts as needed.

The qualifications reads 'Someone from HR came up with this'

Isn't that true of most postings?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#277
post #197

Earlier quoted context omitted.

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

#2 is speculation. Seems possible that there's an unrelated bug causing checksum errors. In any event, it's not a good look right now.

Regardless of the motivation, cause, mechanism of #2 - #3 is not the appropriate way to handle the problem. Attack is indistinguishable from unintentional corruption. And #3 trains customers to do the wrong thing when they encounter an attack.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#278
post #47

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

Indeed. Sports Team + Year, Season + Year, Company + Year or some other such combination should get you a good 10% or more of your users with only a few dozen permutations. They wrote 60 days into FEDRAMP I believe, something I jaw-droppingly realized last year sometime. Whoever is writing these policy frames don't know what they're doing. NIST did away with those periodic password change recommendations for a very g…

Yeah I always use something + year + month + day, otherwise how am I supposed to get it around...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#279

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

We've got like 12 years of historical records tracking the evolution of internal tooling and infrastructure that Cozy Bear uses. Yeah attribution is hard, yeah someone could have been trying to frame them, but in general these groups tend to use a lot of in-house tools and consistent infrastructure and techniques.

https://en.wikipedia.org/wiki/Cozy_Bear

Did you read the Fancy Bear incitements for the DNC hack?

https://www.justice.gov/file/1080281/download

The evidence was absolutely overwhelming. It isn't like someone saw an IP in Russia and assumed it must be Russians. The intelligence agencies had been tracking them for years. They knew exactly who was doing exactly what within the Fancy Bear organization. They know when people joined up and how they were introduced to their GRU handlers. The idea that these attributions are just thrown around whimsically is pure ignorance.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#280

Seems like a good time to plug an excellent book: Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0] The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems. I have no idea who "did" this, I don't really care. The…

Did you read the book?

They work extensively with industry to patch vulnerabilities. There's a whole committee and process for it.

Post reply on HN