Earlier quoted context omitted.
> Russia has been the big bad wolf since 2016. For a very good reason.
I still cannot help but laugh at the intentional ignorance by a lot of people in the US right now. They have for some reason (we all know why) gotten the notion that Russia is some kind of innocent nation that does nothing at all and that US is unreasonably antagonistic against Russia. Russia is in NO uncertain terms a hostile and aggressive nation that we all need to be wary of.
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
291–300 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#292-more than 425 of the U.S. Fortune 500
-all ten of the top ten US telecommunications companies
-all five branches of the U.S. military
-all five of the top five U.S. accounting firms
-the Pentagon
-the State Department
-the National Security Agency
-the Department of Justice
-The White House"
Purely from a risk management perspective, it's a terrible idea to have a single point of failure for all of the above
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#293Earlier quoted context omitted.
NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
However I'm pretty sure PCIDSS does still say 90 days
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#294Earlier quoted context omitted.
NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(
PCI/DSS hasn't yet, so that's holding up a lot of them.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#295Earlier quoted context omitted.
The best proof that we went to the moon is that we left mirrors there that we use to bounce lasers off of to detect the distance to the moon.
That's difficult for people with poor science educations to fully grasp. For example, they might think that the moon's surface itself could reflect the laser light, etc... Not to mention that unmanned probes could also have placed reflectors without humans ever being sent to the Moon!
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#296Earlier quoted context omitted.
This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…
Considering HIPAA, upper management could see how not invoking this plan, and correspondingly risking more damage by leaving systems open, on balance could be worse than saving pennies and winging it. If the procedures described make it possible to lock everything down fast and gradually resume operations smoothly, the downtime could be short enough.
If you don’t know what’s happened, I can’t imagine you’d know enough about the impact to justify turning the business off. The only scenario I can think of where this plan would make sense is if you find out somehow that you’ve already been the victim of a major breach that you failed to detect, so you think it would be worthwhile to just turn everything off while you figure out what happened (because how much worse can it get at that stage, really?...).
Nothing about this seems impressive to me. It sounds like a plan for people who don’t have a plan.
Also, as a side note, anything that needs executive approval to be done during an incident is (as a general rule of thumb) never going to be done during an incident.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#297Earlier quoted context omitted.
Because Russia has somewhat of an oil monopoly in Europe and the US doesn't like that. We've been being fed Russia war propaganda for at least a decade. If it even feels like a "Russia kind of thing" to the general public that is just the result of intentional conditioning by warmongers. It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the c…
Hell, it could be a different part of the USA government, like those "sonic embassy attacks" were.
the amount of insane unfounded crap posted in HN comments is growing and i'm not sure if there is a fix.
BTW recent articles say it's microwaves
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#298Earlier quoted context omitted.
It seems to be laziness on the part of the IT system makers. There are (mostly) standardized ways to authenticate a CAC and associate it with a user for an information system. But people seem to prefer to roll their own. Either using traditional username/password combos, or a worse solution. The worse one is this (seen a few times): Username/password and then you register your CAC with it. They only check the CAC its…
As an IAM/trust systems enthusiast with a passing interest in the CAC system (and tangentially, Login.gov), this is disappointing to hear. Thanks for the context. I’ll keep my eye out for opportunities to contribute to improving the situation (USDS or 18F).
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#299https://en.wikipedia.org/wiki/Multilevel_security
Their are Operating Systems in existence which could prevent this and almost every other breach. However, most technical people aren't even aware of the fact that they CAN exist, and actively believe the opposite.
Hopefully Genode.org will have something useable for the average programmer like me, in a year or two, and I can use that as an existence proof.
Also, there are Data Diodes to help restrict what goes where.
https://en.wikipedia.org/wiki/Unidirectional_network
I think we'll finally get our act together in 2025 or so, 50 years after the first Multi Level Systems were finished.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#300Earlier quoted context omitted.
Clearly whoever is the CIO/CISO could care less? I find it hilarious that people get these positions without seemingly a care in the world. Or maybe they do care and the CEO didn't? Hardly anyone ever gets fired in these circumstances.
Surely he COULDN'T care less?
https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.