Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

341–350 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#342

Earlier quoted context omitted.

What? are you implying that the US government perpetrated attacks on US gov personnel? the amount of insane unfounded crap posted in HN comments is growing and i'm not sure if there is a fix. BTW recent articles say it's microwaves

Yes, one must see the most recent coverage to know the current story. ISTR someone had retired from CIA and was shopping a memoir around; apparently the only exploit he could mention on the record was that one time he got sick. Just his bad luck that in late 2020 we're mostly thinking about a different illness. The only common element among USA facilities in Havana, Guangzhou, and Tashkent is the USA facilities thems…

Or that foreign agents can roam basically freely in those (and basically all) countries?

I'm totally on board with accident/malpractice from shitty construction.

But implying or outright saying the CIA used a weapon on their own employees is crazy - without actual proof - especially to write out on HN.

Sure as pointed out below the US has done - and probably is - doing stupid things. But I really don't buy testing a WEAPON without consent

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#343
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Even potentially affected our election infrastructure:

https://www.trendsmap.com/twitter/tweet/1338708743782092800

Edit: Had a thought - Since the NetFlow Traffic Analyzer tool stores historical network traffic data, I wonder if Dominion traffic was pulled before the breach was closed.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#344

Earlier quoted context omitted.

Surely he COULDN'T care less?

This is one of those colloquialisms that has become so commonplace that it actually becomes a part of the language rather than being incorrect. https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.

Yes, when enough people do / say something wrong over and over again, it sometimes becomes normalised.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#345

Earlier quoted context omitted.

This is one of those colloquialisms that has become so commonplace that it actually becomes a part of the language rather than being incorrect. https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.

Yes, when enough people do / say something wrong over and over again, it sometimes becomes normalised.

Wrong would imply a right, but most interpretations of what is "right" are fairly arbitrary and mostly have to do with social and cultural hierarchy.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#346

Earlier quoted context omitted.

Yes, when enough people do / say something wrong over and over again, it sometimes becomes normalised.

Wrong would imply a right, but most interpretations of what is "right" are fairly arbitrary and mostly have to do with social and cultural hierarchy.

Logically it's wrong. If you COULD care less then that means you do care to some level whereas most people mean you COULD NOT care less. Simple...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#347
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Even potentially affected our election infrastructure: https://www.trendsmap.com/twitter/tweet/1338708743782092800 Edit: Had a thought - Since the NetFlow Traffic Analyzer tool stores historical network traffic data, I wonder if Dominion traffic was pulled before the breach was closed.

Significant after Chris Krebs testified to Congress that Dominion machines were connected to the internet.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#348

Earlier quoted context omitted.

Did you read the book? They work extensively with industry to patch vulnerabilities. There's a whole committee and process for it.

I did. Did you? One of the core themes in the latter half of the book was how the government obtains zero-days, and then has a "committee of government and industry experts" that think about responsible disclosures, assuming the government is willing to "concede" the "national security advantage" of not disclosing the vulnerability. Most vulnerabilities don't get disclosed. Most systems go unpatched. Just so the USG…

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#349
post #211

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

I wonder if they use password managers. All the household-name corporations and small startups alike where I worked for the last decade used a password manager. Selling a subscription to a government org should look like a tasty enough piece of revenue pie to attract multiple bidders, I assume.

how do you manage passwords at such a scale though? where do you keep the password DB?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#350
post #303

Earlier quoted context omitted.

It's from sources vetted by Reuters. Their public-facing anonymity was required for coming forward. https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...

This may have been a valid assertion in a time where news media could be trusted I, and many others, no longer have any faith or trust in the news media. Time and time again the news media has been caught spreading lies and disinformation so sorry I am no longer going to "take their word" for it, and trust they have properly vetted their sources Also They do not lead themselves to credibility by having a Matrix style…

Criticizing a stock photo is addressing the tone, not the content.

Your distrust is misplaced because it's been confirmed by multiple people in the government now.

Post reply on HN