Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

171–180 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#171

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

> Why are there so many people who absolutely deny Russia does any hacking.

Because there are many people paid to do so. (and soon if not already automated bots).

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#172
post #167

The "Russia" allegation sounds like an extremely weak & repetitive claim made by people on a certain political side to divert attention away from their bad press for criminal behavior (to include all of the Chinese compromises that were recently revealed). They're playing a VERY dangerous game, as if they would rather the entire world be destroyed before facing the possibilities of justice (Gitmo, military court trib…

Microsoft and Fireeye have both made similar claims and released substantial technical details. Attribution is hard, but those two companies have a solid reputation and do not make BS claims.

I see where they claim it's a sophisticated / state-sponsored attack, but could you share where they attribute it to Russia in particular? If that's a political assessment made by the media that's one thing, but if these sourced have some sort of technical data that inherently links it to a particular nation... that's something I haven't seen.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#173

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Given the scope of this product — basically everyone runs it — any chance that this is some sort of hoax will be mitigated by the “too large to be a hoax” thing. Probably some sort of fallacy whose name I don’t know. See: moon landing. Of course we went to the moon otherwise, what, 50,000 people are keeping a perfect and scandalous secret for half a century?

The best proof that the United States went to the Moon is that there was extensive Russian spying going on at the time, but Russia never claimed that the US was lying about the Apollo program.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#174

Earlier quoted context omitted.

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

1. That's impressive 2. My own knowledge of folk rock and subsequent visits to Google and Wikipedia have not helped me interpret this reference, in this context: "Electric Dylan/Pete Seeger with the axe" Help, please :-D

Ha!

https://en.wikipedia.org/wiki/Electric_Dylan_controversy

http://communityvoices.post-gazette.com/arts-entertainment-l...

> The Cliff Notes version is Dylan, whose latest album Bringing It All Back Home had upset many folk purists with its amplified accompaniment, performed at Newport on July 25 with amplified backing by the Paul Butterfield Blues Band, who played the festival on their own. As an offended audience booed Dylan performing with Butterfield's band (minus Butterfield himself), an incensed Seeger, outraged at his friend's apostasy, wanted the audio shut off and sought an axe to cut the cables as Dylan and the band ripped through "Maggie's Farm" and "Like A Rolling Stone," Dylan's just-released single.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#175
post #122

Earlier quoted context omitted.

I'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional

Although I do not disagree with your comment, I would do a double take befpre accepting the source you cite because they are very much incentived to proclaim the result they proclaim.

MBAs discover companies desperately need MBAs!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#176
post #128
post #4

Earlier quoted context omitted.

SolarWinds is a 21-year-old publicly-traded company. They're not really "yet another startup". I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure. While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.

No longer publicly traded: https://www.solarwinds.com/company/press-releases/solarwinds...

Went public again Oct 18, 2018: https://www.solarwinds.com/company/press-releases/2018-q4/so...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#177

Seems like a good time to plug an excellent book: Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0] The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems. I have no idea who "did" this, I don't really care. The…

I can second that that book was great.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#178

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

>> In lots of documents that float around, emailed around etc etc.

The amount of fortune 500 and fortune 100 companies that I worked at where this is commonplace is staggering. The amount of businesses that never change their passwords is quite frankly, shocking. I left a fortune 500 company two years ago and I just tried my login on their external facing portal - and it still worked.

I've seen passwords being passed around in word docs and internal blog posts. At one place they were mixing development information with financial information. The idea you had several folders of corporate contracts mingling with developer docs on a sharepoint server was a real eye opener for me.

Nobody else seemed to care when I brought up the fact you just gave a bunch of developers access to facebook contracts and other financially important docs they have no reason to have access to. Their reason? It was too hard to set up a new folder with access restricted.

After a few years of experiencing these, I just became kind of apathetic to it. If nobody in authority cares, then why should I??

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#179

These breaches will continue to happen, and happen...and happen until our limp-dick federal government gives a shit and starts to punish companies for their malicious malfeasance regarding IT security.

And until we end the H1B visa and only allow Americans or American allies to run the IT systems of companies in America.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#180

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

I'm curious, are people saying that "Russia doesn't do any hacking" or that "there isn't yet enough evidence that this specific attack is by Russia". Those are two very different claims.

I don't think there's any doubt about the former claim, personally. The latter though, I think it's too early to tell, especially since we've seen recently how certain hackers have explicitly started putting bait signs from other nation-states to misdirect.

Post reply on HN