Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

131–140 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#131
post #120

Earlier quoted context omitted.

I like when people complain about HN without understanding how it works. Actually, I don’t. Downvoting turns your comments grey. Flagging is a separate action.

semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site

[deleted]

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#132
post #23

Earlier quoted context omitted.

I have seen a couple of corporate hacks (not publicized) who happened to be Russian groups hosted in Syria.... By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything. In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponso…

I’ve seen these things, including large DDoS attacks from both sides, black hat and white hat. I’ve also been recruited by Cyber Command, NSA, etc. The one thing that rings true is that governments and corporations vastly overestimate the capabilities of nation states, and vastly underestimate the capabilities of unaffiliated hacking groups and individuals. Most of the cutting edge InfoSec work is being done in OSS a…

>...obsolete tech like SCADA...

...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#133
post #89

> “This is a nation state,” said a different person briefed on the matter. “We just don’t know which one yet.” So, how do they know then?

They probably don't but what better way to absolve themselves of any fault? If it's a nation state, then the attack is so sophisticated, that surely they can't be blamed for not having prevented it and following best practices would certainly not have been enough.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#134

Earlier quoted context omitted.

Also a problem with many places. Think about Pakistan, where the military is not the government per se, but has the resources. “Nation state adversary” says something without saying it.

> Pakistan, where the military is not the government per se, A distinction without a difference? I don't know a whole lot about Pakistan, but that's the way it seems to me.

It doesn’t matter if you or I don’t see that distinction, but the US government needs to make whatever distinction it chose from a policy perspective.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#135
I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems.

"No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out".

I suppose "we think it could be done by a group of two or three teenagers with decent knowledge of wget" doesn't have the same ring to it.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#136
post #110

Earlier quoted context omitted.

That isn’t Microsoft’s fault. They are providing a tool and your admins did not set it up in the most secure or sensible way. Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.

Imagine if an automobile manufacturer allowed you to configure the safety features of your car and had the defaults set to unsafe but convenient values to help sell vehicles... do you think the manufacturers should evade liability?

I live in New York, where the speed limits on highways vary from 50 mph in NYC to 65 in the rural areas. My car is governed at 110 mph. Why? There is no reasonable scenario where that is smart to discover.

Microsoft has billions of users. The security needs of the US Department of Justice are not the same as my mom’s real estate office.

When you use 3rd party IdP, for example, how does Azure MFA know what the app is?

The configuration described was not out of the can. Somebody decided to make it the way it was.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#137
post #7

Earlier quoted context omitted.

Could be just about anyone. Knowing what USA has done, it seems that even this type activity is standard even between "friendly" governments....

Yup. Jon Pollard, for one. He spied for Israel. Israel certainly has the chops to do something like this, but lots of other "friendly" countries with good geeks wouldn't mind having this kind of info.

I would bet on China, not Israel. Nation-states calculate risk/reward. With Jonathan Pollard, the reward was huge: getting your own nukes. Hacking the treasury? Not sure what Israel would gain from that; the costs of being perceived to attack a friend would be relatively higher. Whereas China has obvious reasons to want to know what US economic policymakers are thinking, and has little to lose in terms of reputation.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#138
post #109
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

Would MFA have prevented this from happening?

[deleted]

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#139
post #39
post #31

Earlier quoted context omitted.

This is actually pretty fucked up

Is it really? Theoretically with perfect information you don't need to go to war, you can just compute the result and start with treaty negotiations.

This. There's actually an argument that spying helps peace.

My dad (a journalist, RIP) was once at a UN conference in the 70s, and made the remark to a Chinese official in a light-hearted spirit: "of course you spy on us, we spy on you, and what's wrong with that?" This caused a major row and he was forced to apologize.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#140
post #125
post #98

Earlier quoted context omitted.

How did you determine that the attacker hijacked the existing O365 session rather than logging in with the phished username and password? For an app like O365, usually that kind of cookie-stealing doesn't happen without malware on a user's computer.

This was about 6-9 months ago and I didn’t lead the postmortem, so to be honest I don’t recall how we determined that. However anecdotal, the user who was compromised is aware enough not to re-enter their credentials outside URL schemes that match our password manager database, and they wouldnt have entered anything. “Oh but how can you trust the user, they clicked a bad link?!”... again this email came from a very r…

I sympathize, it's difficult to get a satisfying answer in a situation where you trust the user to accurately remember and own up to a mistake. You need both good logs (Microsoft's default logging and retention usually don't cut it) and a security vendor that knows O365, AAD, and the attacks on them well enough to make useful conclusions.

Notion.so is popular for phishing pages because it's a "reputable" "enterprise" application that doesn't raise the spam score when it's linked to in an email, can require signing in to view the page which further deters spam filters that actually check the links, and has less robust anti-phishing systems than Google Docs and Sharepoint (which are still used for the same purpose but require more tweaking of the template to avoid being auto-flagged).

Post reply on HN