Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

181–190 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#181
post #175

Earlier quoted context omitted.

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

I totally agree with your point (and would trust a hazy dream more than anything coming from this government), but I'd add that even if they claim to identify these parties forensically, they're often using parallel construction through their own espionage. like in the mueller investigation, they had a lot of firsthand knowledge of the IRA's business from inside the building (and the names of everyone that worked there). It's often not a technical conclusion based on the intrusions, but a conclusion reached by evidence gathered through other means

bellingcat has also done a pretty remarkable job of identifying state-employed hackers and spies just through buying russian passport control information and other private information that's out there on the market

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#182
post #48

Earlier quoted context omitted.

>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?

This is my experience with Microsoft: they view all security features as binary. As in: Encryption: Yes. Multi-factor authentication: Yes. Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No. There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "…

I literally reported an issue a year ago where under some circumstances, logging out of Microsoft would not actually log you out if their JavaScript redirect fail to execute, which it did on some devices. Nothing. They didn’t give a shit. It made me so angry that we had to code our application around it.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#183
post #53
post #41

Earlier quoted context omitted.

Nation-state prevents confusing with lower level states. State is the more appropriate term, but it would cause a lot of confusion in the US.

Could just use "country".

Problem is that a country can be sovereign or part of a larger state. I think sovereign state is the correct wording to use in that case.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#184

> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…

r/wallstreebets only skill is making really funny Memes and is exposing the Federal Reserve and printing machine.

So now that I think about it maybe they did do it... That's the only way to find out what the Fed is up to next.

Hack a hot stock tip.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#186
>The breach presents a major challenge to the incoming administration of President-elect Joe Biden as officials investigate what information was stolen and try to ascertain what it will be used for.

Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:

  Stealing Data vs Unauthorized Data Access:

                    C - I - A

  Stealing Data     Y   Y   Y

  Unlawful Access   Y   !   N



  C=Loss of Data Confidentiality
  I=Loss of Data Integrity
  A=Loss of Data Accessibility
  !=Data may or may not have been altered depending on level of access.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#187
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

Who would be trusted to design and procure the hardware for such a device?

https://leanprover.github.io

While it is difficult to design a secure procurement chain all the way to the SiO2, we could at least design simple enough hw/sw systems for which formal verification is an economical option. And then force government entities to use formally verified systems instead of the bug ridden crap most shops, especially the sw ones, have to ship under intense deadline pressure. The market has led us into a broken local optima, no way to get out short of state level action.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#188
Related:

FireEye, a Top Cybersecurity Firm, Says It Was Hacked by a Nation-State. The Silicon Valley company said hackers — almost certainly Russian — made off with tools that could be used to mount new attacks around the world.

https://www.nytimes.com/2020/12/08/technology/fireeye-hacked...

Post reply on HN