Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

291–300 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#291

Earlier quoted context omitted.

> Russia has been the big bad wolf since 2016. For a very good reason.

I still cannot help but laugh at the intentional ignorance by a lot of people in the US right now. They have for some reason (we all know why) gotten the notion that Russia is some kind of innocent nation that does nothing at all and that US is unreasonably antagonistic against Russia. Russia is in NO uncertain terms a hostile and aggressive nation that we all need to be wary of.

This is content-free. It's the equivalent of replying to somebody who says "I don't think X committed this murder" with "So you think that X is a saint and can do no wrong?"

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#292
"SolarWinds says it has over 300,000 customers including:

-more than 425 of the U.S. Fortune 500

-all ten of the top ten US telecommunications companies

-all five branches of the U.S. military

-all five of the top five U.S. accounting firms

-the Pentagon

-the State Department

-the National Security Agency

-the Department of Justice

-The White House"

Purely from a risk management perspective, it's a terrible idea to have a single point of failure for all of the above

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#293
post #59

Earlier quoted context omitted.

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

However I'm pretty sure PCIDSS does still say 90 days

You are allowed to use the NIST Guidance as a reason to change that to a longer timeframe. I have a couple of clients that are using 365days as of 2019.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#294
post #245
post #52

Earlier quoted context omitted.

NIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(

PCI/DSS hasn't yet, so that's holding up a lot of them.

You are allowed to use the NIST Guidance as a reason to change that to a longer timeframe. I have a couple of clients that are using 365days as of 2019.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#295

Earlier quoted context omitted.

The best proof that we went to the moon is that we left mirrors there that we use to bounce lasers off of to detect the distance to the moon.

That's difficult for people with poor science educations to fully grasp. For example, they might think that the moon's surface itself could reflect the laser light, etc... Not to mention that unmanned probes could also have placed reflectors without humans ever being sent to the Moon!

Why even go to those lengths? If they lied about the moon landing surely they are lying about lasers even hitting the moon, or it not being made of cheese...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#296

Earlier quoted context omitted.

This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…

Considering HIPAA, upper management could see how not invoking this plan, and correspondingly risking more damage by leaving systems open, on balance could be worse than saving pennies and winging it. If the procedures described make it possible to lock everything down fast and gradually resume operations smoothly, the downtime could be short enough.

The situation would have to be so out of hand by that stage that I can’t imagine being able to do it in 5 minutes would matter. For this scenario to make sense, you’d have to know things were really bad, but not know enough about how bad they are to only isolate the systems you need to.

If you don’t know what’s happened, I can’t imagine you’d know enough about the impact to justify turning the business off. The only scenario I can think of where this plan would make sense is if you find out somehow that you’ve already been the victim of a major breach that you failed to detect, so you think it would be worthwhile to just turn everything off while you figure out what happened (because how much worse can it get at that stage, really?...).

Nothing about this seems impressive to me. It sounds like a plan for people who don’t have a plan.

Also, as a side note, anything that needs executive approval to be done during an incident is (as a general rule of thumb) never going to be done during an incident.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#297

Earlier quoted context omitted.

Because Russia has somewhat of an oil monopoly in Europe and the US doesn't like that. We've been being fed Russia war propaganda for at least a decade. If it even feels like a "Russia kind of thing" to the general public that is just the result of intentional conditioning by warmongers. It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the c…

Hell, it could be a different part of the USA government, like those "sonic embassy attacks" were.

What? are you implying that the US government perpetrated attacks on US gov personnel?

the amount of insane unfounded crap posted in HN comments is growing and i'm not sure if there is a fix.

BTW recent articles say it's microwaves

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#298

Earlier quoted context omitted.

It seems to be laziness on the part of the IT system makers. There are (mostly) standardized ways to authenticate a CAC and associate it with a user for an information system. But people seem to prefer to roll their own. Either using traditional username/password combos, or a worse solution. The worse one is this (seen a few times): Username/password and then you register your CAC with it. They only check the CAC its…

As an IAM/trust systems enthusiast with a passing interest in the CAC system (and tangentially, Login.gov), this is disappointing to hear. Thanks for the context. I’ll keep my eye out for opportunities to contribute to improving the situation (USDS or 18F).

Happy CAC user here. I would love to see them as common as driver's licenses. Maybe then we could do away with SSNs as a secret identifier.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#299
For the last 15 years, I keep pushing information about Multi Level Secure Systems every time another incident like this happens. The fact that we haven't been using them since the 1970s everywhere drives me nuts!

https://en.wikipedia.org/wiki/Multilevel_security

Their are Operating Systems in existence which could prevent this and almost every other breach. However, most technical people aren't even aware of the fact that they CAN exist, and actively believe the opposite.

Hopefully Genode.org will have something useable for the average programmer like me, in a year or two, and I can use that as an existence proof.

Also, there are Data Diodes to help restrict what goes where.

https://en.wikipedia.org/wiki/Unidirectional_network

I think we'll finally get our act together in 2025 or so, 50 years after the first Multi Level Systems were finished.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#300

Earlier quoted context omitted.

Clearly whoever is the CIO/CISO could care less? I find it hilarious that people get these positions without seemingly a care in the world. Or maybe they do care and the CEO didn't? Hardly anyone ever gets fired in these circumstances.

Surely he COULDN'T care less?

This is one of those colloquialisms that has become so commonplace that it actually becomes a part of the language rather than being incorrect.

https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.

Post reply on HN