Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

281–290 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#281

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

Hugo Chavez hacked our election from the grave. Oh and he also manufactured millions of paper ballots that match the electionic tabulation almost perfectly.

The deep state is deeper than we thought!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#282

Earlier quoted context omitted.

The best proof that the United States went to the Moon is that there was extensive Russian spying going on at the time, but Russia never claimed that the US was lying about the Apollo program.

The best proof that we went to the moon is that we left mirrors there that we use to bounce lasers off of to detect the distance to the moon.

That's difficult for people with poor science educations to fully grasp. For example, they might think that the moon's surface itself could reflect the laser light, etc...

Not to mention that unmanned probes could also have placed reflectors without humans ever being sent to the Moon!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#283

Earlier quoted context omitted.

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

Sounds like a solid information security incident response mechanism! The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics. I wish business continuity planning (which would include infosec procedures but has a much wider ov…

This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used.

You’re not going to turn the business off because somebody’s inbox got compromised, or because there’s some unexplained event in the SIEM, and those are the sort of events you’re actually going to have to respond to.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#284
post #197

Earlier quoted context omitted.

#2 is speculation. Seems possible that there's an unrelated bug causing checksum errors. In any event, it's not a good look right now.

Regardless of the motivation, cause, mechanism of #2 - #3 is not the appropriate way to handle the problem. Attack is indistinguishable from unintentional corruption. And #3 trains customers to do the wrong thing when they encounter an attack.

The malicious file was signed with the right certificate. So yeah you should ideally be more careful with checksums but there already was a much more robust and secure authentication mechanism and it was defeated.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#285
Let's assume this is a case of state sponsored attack. If I was in charge of organising such an attack, I would make sure my employer would be on top of the list of victims. Would not do any actual damage to steal my own information and would tremendously help with attributing the attack to my enemy.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#286
post #108

Earlier quoted context omitted.

Harmj0y, who is probably the best public AD hacker right now suggests 3 month rotations, IIRC. My guess is the idea is to mitigate compromise of very old passwords, spray attacks using breached site creds, reduce insider threat and at least offer some mitigation for compromised hashes. I think this is wise compared in work environments - 90 days, 180 or even 360 would be a good mitigation over _none_ to too many.

I think those concerns are better addressed elsewhere with tools like MFA, automatically disabling inactive accounts, or monitoring public services like HIBP to deactivate accounts quickly. Attackers can move quickly so you hit diminishing returns on rotation policies trying to avoid usability issues incentivizing worse passwords while not rotating long after the account has been compromised.

Oh! Please tell me how you implement MFA on AD domains!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#287

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

It's just a necessary conspiracy if you're fully bought into the Trump victimhood worldview.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#288
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Did you also consider this[0] an act of war? [0] (U.S. Escalates Online Attacks on Russia’s Power Grid) [ https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-r... ]

That was retaliatory. We're already in a war.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#289

Consistent with the "Most Secure Election Ever" (tm) claims, Dominion Voting Systems use SolarWinds' Orion platform, too. [0] [0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...

Considering the EO regarding elections [1], SolarWinds is in trouble.

1. https://www.whitehouse.gov/presidential-actions/executive-or...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#290

Earlier quoted context omitted.

Sounds like a solid information security incident response mechanism! The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics. I wish business continuity planning (which would include infosec procedures but has a much wider ov…

This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…

Considering HIPAA, upper management could see how not invoking this plan, and correspondingly risking more damage by leaving systems open, on balance could be worse than saving pennies and winging it. If the procedures described make it possible to lock everything down fast and gradually resume operations smoothly, the downtime could be short enough.
Post reply on HN