Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

311–320 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#311

"SolarWinds says it has over 300,000 customers including: -more than 425 of the U.S. Fortune 500 -all ten of the top ten US telecommunications companies -all five branches of the U.S. military -all five of the top five U.S. accounting firms -the Pentagon -the State Department -the National Security Agency -the Department of Justice -The White House" Purely from a risk management perspective, it's a terrible idea to h…

What would the solution be?

Use the products of multiple companies for everything tech related?

Give AMD processors for the army, and INTEL to the white house?

Should telcos use windows, and the pentagon linux?

NSA can use excel, and NSA libreoffice?

Collecting the generic common components and software used by large chunks of people would yield an endless list.

Even then, when an exploit comes out for something, the only benefit is that you can limit the extent of damages, not prevent it.

Removing all single points of failure in this scale seems impossible.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#312
post #170
post #158

Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…

Whilst not being a "cloud is someone else's computer" adherent, the notion SaaS products can't be misconfigured into opening up security holes not present / so serious in some on-prem environments doesn't hold water - see the last decade's stories of accidentally open S3 buckets, plaintext secrets pushed to public GitHub repos, and all manner of other "minor misconfigurations"

This is true but there’s a big difference in how easy it is to audit. You can enable Security Hub and Guard Duty on AWS organization-wide in a few minutes and have a pretty solid baseline for hardening your infrastructure and flagging suspicious activity. Doing the same with on-premise infrastructure takes months and entails significant risk since things weren’t designed around APIs and low-privilege IAM.

(GCP is similar but SCC is earlier in the development cycle and their threat detection isn’t well designed.)

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#313
post #279

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

We've got like 12 years of historical records tracking the evolution of internal tooling and infrastructure that Cozy Bear uses. Yeah attribution is hard, yeah someone could have been trying to frame them, but in general these groups tend to use a lot of in-house tools and consistent infrastructure and techniques. https://en.wikipedia.org/wiki/Cozy_Bear Did you read the Fancy Bear incitements for the DNC hack? https:…

Here's the article I was trying to remember last night about how Dutch intelligence actually hacked security cameras and watched the DNC hack go down live.

(source) https://nos.nl/nieuwsuur/artikel/2213767-dutch-intelligence-...

(summary) https://www.cbsnews.com/news/dutch-intelligence-us-fbi-russi...

Misattributions happen, but Fancy Bear / Cozy Bear is extremely well understood, and they don't generally make much of an effort to hide the fact that it was them that did it. For them, it's often about sending a message.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#314

Seems like a good time to plug an excellent book: Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0] The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems. I have no idea who "did" this, I don't really care. The…

Did you read the book? They work extensively with industry to patch vulnerabilities. There's a whole committee and process for it.

I did. Did you?

One of the core themes in the latter half of the book was how the government obtains zero-days, and then has a "committee of government and industry experts" that think about responsible disclosures, assuming the government is willing to "concede" the "national security advantage" of not disclosing the vulnerability.

Most vulnerabilities don't get disclosed.

Most systems go unpatched.

Just so the USG can exploit foreign systems.

It's very possible this particular vulnerability was found, but it's potential for spying outweighed the concern for patching.

We'll never know.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#315

"SolarWinds says it has over 300,000 customers including: -more than 425 of the U.S. Fortune 500 -all ten of the top ten US telecommunications companies -all five branches of the U.S. military -all five of the top five U.S. accounting firms -the Pentagon -the State Department -the National Security Agency -the Department of Justice -The White House" Purely from a risk management perspective, it's a terrible idea to h…

What would the solution be? Use the products of multiple companies for everything tech related? Give AMD processors for the army, and INTEL to the white house? Should telcos use windows, and the pentagon linux? NSA can use excel, and NSA libreoffice? Collecting the generic common components and software used by large chunks of people would yield an endless list. Even then, when an exploit comes out for something, the…

I think what you describe seems entirely reasonable. Though more so for software than hardware; that way a single exploit can't take down our whole government.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#316

Earlier quoted context omitted.

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

It's just a necessary conspiracy if you're fully bought into the Trump victimhood worldview.

Right. If you don't accept it was the Russians, you're a fucking Trump supporter!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#317
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Don't worry, you'll get your war.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#318
post #284

Earlier quoted context omitted.

Regardless of the motivation, cause, mechanism of #2 - #3 is not the appropriate way to handle the problem. Attack is indistinguishable from unintentional corruption. And #3 trains customers to do the wrong thing when they encounter an attack.

The malicious file was signed with the right certificate. So yeah you should ideally be more careful with checksums but there already was a much more robust and secure authentication mechanism and it was defeated.

Yes, these are two orthogonal egregious security problems.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#319
post #108

Earlier quoted context omitted.

I think those concerns are better addressed elsewhere with tools like MFA, automatically disabling inactive accounts, or monitoring public services like HIBP to deactivate accounts quickly. Attackers can move quickly so you hit diminishing returns on rotation policies trying to avoid usability issues incentivizing worse passwords while not rotating long after the account has been compromised.

Oh! Please tell me how you implement MFA on AD domains!

Azure AD/Azure AD hybrid might be worth a look

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#320

Earlier quoted context omitted.

It's not just shady stuff. Recently, on a customer's Windows server, antivirus software randomly decided to permanently delete some our DLLs (!). We weren't doing anything remotely shady; it was a normal ASP.NET Core app.

Also, any task that involves reading or writing files will, in the presence of cutomer antivirus software, turn into a random number generator on whether the read/write goes through at all, how long it takes, etc. We are constantly having issues with customer AV because of this.

Strange to consider that stuff like this is (part) of why browser apps took off in the first place!
Post reply on HN