Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

321–330 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#321

Earlier quoted context omitted.

As an IAM/trust systems enthusiast with a passing interest in the CAC system (and tangentially, Login.gov), this is disappointing to hear. Thanks for the context. I’ll keep my eye out for opportunities to contribute to improving the situation (USDS or 18F).

Happy CAC user here. I would love to see them as common as driver's licenses. Maybe then we could do away with SSNs as a secret identifier.

That’s the end goal, adopting a system similar to Estonia’s national ID infrastructure.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#322
post #128

Earlier quoted context omitted.

No longer publicly traded: https://www.solarwinds.com/company/press-releases/solarwinds...

Went public again Oct 18, 2018: https://www.solarwinds.com/company/press-releases/2018-q4/so...

I stand corrected.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#323

Earlier quoted context omitted.

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

He's not denying Russia does hacking. He's saying there is no evidence that ties this to Russia over any other group. Maybe Russia is most likely based on priors, but I don't think the average HN commenter has an accurate estimate of nation-state hacking frequencies.

"Attribution is hard."

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#324
post #308

So was the election hacked too? I'm a little confused how Biden can get 80 million votes, and almost no one watched his acceptance speech today. 40k views on youtube. The 6k vote flipping in Michigan was claimed to be some sort of computer error. But why were the logs deleted? that seems like a hacker thing to do to delete the logs. A judge just released the audit report. https://www.freep.com/story/news/politics/ele…

Nobody really cares about Biden, they just want to get rid of Trump.

This is what we're being told, among other things like Trump voters did not vote by mail, at sometimes like 9 to 1 ratio. But we are told to accept these things as True at face value.

Likewise, we are to Trust and accept the results on Dominion Machines. When the only audit that was permitted to be performed, uncovered a 68% error rate, and logs deleted.

Trust but verify. The verify part has not really been done. We are only told to Trust.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#325
post #279

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

We've got like 12 years of historical records tracking the evolution of internal tooling and infrastructure that Cozy Bear uses. Yeah attribution is hard, yeah someone could have been trying to frame them, but in general these groups tend to use a lot of in-house tools and consistent infrastructure and techniques. https://en.wikipedia.org/wiki/Cozy_Bear Did you read the Fancy Bear incitements for the DNC hack? https:…

According to Charles Carmakal, senior vice president and chief technical officer at Mandiant, FireEye’s incident response arm

“There will unfortunately be more victims that have to come forward in the coming weeks and months,” he said. While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor, he said. A Kremlin official denied that Russia had any involvement.

https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#326
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

According to Charles Carmakal, senior vice president and chief technical officer at Mandiant, FireEye’s incident response arm

“There will unfortunately be more victims that have to come forward in the coming weeks and months,” he said. While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor, he said. A Kremlin official denied that Russia had any involvement.

https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#327
post #250

The widespread use of unvalidated automatic updates will go down as one of the biggest security blunders of the last decade.

Unvalidated by whom? From the info that has been released these updates were properly signed.

I meant validate the code changes, either by the party that owns the system the software is being installed on, or some neutral third party.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#328

Earlier quoted context omitted.

This doesn’t sound like a good incident response plan to me at all, precisely because it provides a very clear incentive to not activate it. If you have to be so sure that you’re having a serious incident that you’re prepared to put a stop to all operations in the organization, then you can be pretty sure that plan is never going to be used. You’re not going to turn the business off because somebody’s inbox got compr…

> You’re not going to turn the business off because somebody’s inbox got compromised, or because there’s some unexplained event in the SIEM, duh, those get handled several pages before "press the red button" is even discussed. You think "turn off the business" is the only page in the playbook?! > and those are the sort of events you’re actually going to have to respond to. Tell that to SolarWinds. You need a IR plan…

In the real world, you're never going to know that you have a "state level adversary on your network, using your software to attack DHS and the Treasury" until after all the damage has already been done, and you've had enough time to assess the total impact. That's presuming you're even alerted to it in a timely manner. In that scenario, the appropriate response almost certainly not going to be "turn off the business" and even if it is, it's not going to matter whether you can do it in 5 minutes or 5 hours.

The only scenarios in which you'll have enough information to justify activating this plan, are scenarios where you'll also have enough information to respond to the actual threat, rather than just shutting everything down.

It's something that might sound impressive to people who aren't experienced with incident response, but it's practical uses are so close to non-existent, that any time that was spent developing this solution was most certainly wasted in lieu of doing something actually useful.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#329

Earlier quoted context omitted.

Hell, it could be a different part of the USA government, like those "sonic embassy attacks" were.

What? are you implying that the US government perpetrated attacks on US gov personnel? the amount of insane unfounded crap posted in HN comments is growing and i'm not sure if there is a fix. BTW recent articles say it's microwaves

I don't know about jessaustin's claims, but it definitely isn't beyond a US government agency to attack its own personnel:

https://en.wikipedia.org/wiki/Kiki_Camarena

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#330

Earlier quoted context omitted.

Surely he COULDN'T care less?

This is one of those colloquialisms that has become so commonplace that it actually becomes a part of the language rather than being incorrect. https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.

Those of us who know better bristle and retain pedantry. Consider semi-annual and biannual. Grr.
Post reply on HN