Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

301–310 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#302
post #59

Earlier quoted context omitted.

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

However I'm pretty sure PCIDSS does still say 90 days

PCIDSS is largely security theater as well, there are many many many problems with it.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#303

Earlier quoted context omitted.

We (the public) have not been provided evidence that this was Russia. Let's not get ahead of ourselves. Some anonymous people claimed it's Russia. That is meaningless.

It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward. https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...

This may have been a valid assertion in a time where news media could be trusted

I, and many others, no longer have any faith or trust in the news media. Time and time again the news media has been caught spreading lies and disinformation so sorry I am no longer going to "take their word" for it, and trust they have properly vetted their sources

Also They do not lead themselves to credibility by having a Matrix style photo with "hooded hacker" trope prominent in the article

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#304
post #227

Earlier quoted context omitted.

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

This seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#305

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Given your use of "breathless" and "Russian Menace", it's clear which echo chamber you spend time in.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#306

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

This isn't the only area where otherwise sane, normal people seem to have lost their minds. There's a term from a few years ago - "Foxbrain".

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#307
post #196

Earlier quoted context omitted.

> Why are there so many people who absolutely deny Russia does any hacking. Because there are many people paid to do so. (and soon if not already automated bots).

Not everyone who questions something is a paid shill.

The beauty, from a nefarious standpoint, is that you don't have to pay people to spread disinformation. You just have to use the right psych techniques on them and ensure they get proper reinforcement.

These are the techniques that have turned my family and many of their friends (and clearly a measurable percentage of Americans) into the exact opposite of the values they taught me and demonstrated for decades.

They truly believe virtually anything spoken by people like Limbaugh, Glenn, Orielly, Carlson, etc.

If you try to use some logic or evidence, even showing two conflicting statements made by one of those idols, they just shut down. The cognitive dissonance is too uncomfortable.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#308

So was the election hacked too? I'm a little confused how Biden can get 80 million votes, and almost no one watched his acceptance speech today. 40k views on youtube. The 6k vote flipping in Michigan was claimed to be some sort of computer error. But why were the logs deleted? that seems like a hacker thing to do to delete the logs. A judge just released the audit report. https://www.freep.com/story/news/politics/ele…

Nobody really cares about Biden, they just want to get rid of Trump.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#309
I wonder scanning their own uploads and validating checksums via cron job would have prevented or at least would give an early alert

Shameless disclosure: i was doing something similar (I do not have a plan to maintain long time) but would love to hear better solutions: https://github.com/getsumio/getsum

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#310

Earlier quoted context omitted.

Sounds like a solid information security incident response mechanism! The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics. I wish business continuity planning (which would include infosec procedures but has a much wider ov…

This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…

> You’re not going to turn the business off because somebody’s inbox got compromised, or because there’s some unexplained event in the SIEM,

duh, those get handled several pages before "press the red button" is even discussed. You think "turn off the business" is the only page in the playbook?!

> and those are the sort of events you’re actually going to have to respond to.

Tell that to SolarWinds.

You need a IR plan that has appropriate responses to the threats you are facing. But at the scale and impact of a company like SolarWinds it's actually rather reassuring to have a "stop the world" backstop because your threat model absolutely includes catastrophic levels of risk.

And "you won't be incentivized to push the button"? Come on. When things get to "state level adversary on your network, using your software to attack DHS and the Treasury" bad, you're going to absolutely push the button because in a few months when your CEO is answering questions in Congress they'll want to be able to talk about something that went right.

Post reply on HN