duplicate: https://news.ycombinator.com/item?id=25413053 and a few others more
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
301–310 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#302Earlier quoted context omitted.
NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
However I'm pretty sure PCIDSS does still say 90 days
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#303Earlier quoted context omitted.
We (the public) have not been provided evidence that this was Russia. Let's not get ahead of ourselves. Some anonymous people claimed it's Russia. That is meaningless.
It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward. https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...
I, and many others, no longer have any faith or trust in the news media. Time and time again the news media has been caught spreading lies and disinformation so sorry I am no longer going to "take their word" for it, and trust they have properly vetted their sources
Also They do not lead themselves to credibility by having a Matrix style photo with "hooded hacker" trope prominent in the article
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#304Earlier quoted context omitted.
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?
This seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#305So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#306So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…
Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#307Earlier quoted context omitted.
> Why are there so many people who absolutely deny Russia does any hacking. Because there are many people paid to do so. (and soon if not already automated bots).
Not everyone who questions something is a paid shill.
These are the techniques that have turned my family and many of their friends (and clearly a measurable percentage of Americans) into the exact opposite of the values they taught me and demonstrated for decades.
They truly believe virtually anything spoken by people like Limbaugh, Glenn, Orielly, Carlson, etc.
If you try to use some logic or evidence, even showing two conflicting statements made by one of those idols, they just shut down. The cognitive dissonance is too uncomfortable.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#308So was the election hacked too? I'm a little confused how Biden can get 80 million votes, and almost no one watched his acceptance speech today. 40k views on youtube. The 6k vote flipping in Michigan was claimed to be some sort of computer error. But why were the logs deleted? that seems like a hacker thing to do to delete the logs. A judge just released the audit report. https://www.freep.com/story/news/politics/ele…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#309Shameless disclosure: i was doing something similar (I do not have a plan to maintain long time) but would love to hear better solutions: https://github.com/getsumio/getsum
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#310Earlier quoted context omitted.
Sounds like a solid information security incident response mechanism! The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics. I wish business continuity planning (which would include infosec procedures but has a much wider ov…
This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…
duh, those get handled several pages before "press the red button" is even discussed. You think "turn off the business" is the only page in the playbook?!
> and those are the sort of events you’re actually going to have to respond to.
Tell that to SolarWinds.
You need a IR plan that has appropriate responses to the threats you are facing. But at the scale and impact of a company like SolarWinds it's actually rather reassuring to have a "stop the world" backstop because your threat model absolutely includes catastrophic levels of risk.
And "you won't be incentivized to push the button"? Come on. When things get to "state level adversary on your network, using your software to attack DHS and the Treasury" bad, you're going to absolutely push the button because in a few months when your CEO is answering questions in Congress they'll want to be able to talk about something that went right.