Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

121–130 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#121
post #110

Earlier quoted context omitted.

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

Imagine if an automobile manufacturer allowed you to configure the safety features of your car and had the defaults set to unsafe but convenient values to help sell vehicles... do you think the manufacturers should evade liability?

They absolutely do. In northern climates where there is snow and ice on the roads for 3+ months out of the year, a car MFG will GLADLY sell you a vehicle with sport/summer tires. If you try driving with those in the winter: at best you'll get stuck, at worst you'll slide through the first intersection you come to and die in a fiery crash.

Just about every business will have options that are a perfectly reasonable choice in some circumstances and really, really stupid in others.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#122
post #23

Earlier quoted context omitted.

I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…

I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS a…

And if you arent RPCing into a random Russian computer 5 minutes after browsing darknet markets, what are you doing aside from being discriminated against by captcha’s all day?

I would not trust any declaration of “state sponsored hack” and it is a distinction that doesn't really matter but causes more harm than good

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#125
post #98
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

How did you determine that the attacker hijacked the existing O365 session rather than logging in with the phished username and password? For an app like O365, usually that kind of cookie-stealing doesn't happen without malware on a user's computer.

This was about 6-9 months ago and I didn’t lead the postmortem, so to be honest I don’t recall how we determined that.

However anecdotal, the user who was compromised is aware enough not to re-enter their credentials outside URL schemes that match our password manager database, and they wouldnt have entered anything.

“Oh but how can you trust the user, they clicked a bad link?!”... again this email came from a very reputable vendor who we email with regularly, and the link would have been completely normal for a Monday morning in Q1 2020.

I also think part of our reasoning for why the credentials were not re-used was because all the sessions seemed to be headless chrome sessions, but no logins.

I’m not a data security expert, but in my best summary, it seemed they: - Had a “virus” that spread really well. I’m assuming they had two kinds of users. Spreaders, and targets. Our employee was a spreader, sending this bug out to his/our network. Once the targets were hit, they’d be selected out of the spreader pool (so the hackers could remain undetected). - The hack relied upon identifying ,mutually high volume (trusted) email senders. - The hack had something to do with leveraging the platform of Notion.io. Unsure if there is a bug on that platform which was also being abused, or if they just have a good system for hosting phishing pages. - The user’s authenticated sessions seemed to be hijacked and replicated across the globe in headless chrome browsers, which appeared to renew the session until the hack ended.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#127
post #105

Earlier quoted context omitted.

I think it's a mistake to limit the scope of consideration to countries that are antagonist to America. I doubt it was them, but at least in theory, might not Canada have an interest in having advanced knowledge of things the US Treasury might decide? Certainly the US economy impacts Canada as well, as it does nearly any other country to one degree or another.

Hahaha our military can't even figure out boots for the troops, you think we can hack the US Government? As much as Canadians like to shit on America, one thing they gave going for them south of the border is that "Fuck yeah America" attitude that leads people to pursue excellence. We don't have that in our public sector. We just have passive aggression, mediocrity and memes about being polite.

Well, maybe Canada is pretty unlikely I concede. But it seems possible that it might be some other first world nation that has friendly relations with America. I mean, America spied on Germany, right? Maybe Germany spies on America. I really haven't the foggiest clue who did it, but I wouldn't limit consideration to overtly adversarial countries.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#128
post #80

Too many snarky and overused jokes in this thread. Anyway, was this hack related to the one for FireEye last week?

Fourth paragraph in the article:

> Two of the people said that the breaches are connected to a broad campaign that also involved the recently disclosed hack on FireEye, a major U.S. cybersecurity company with government and commercial contracts.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#129
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

If your IT department cared, they could disable the app notification MFA method in AAD and force you to either use passwordless or a TOTP code, both of which prevent you from blindly approving a sign-in you aren't involved in.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#130
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

You are right.
Post reply on HN