Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

181–190 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#181
post #59

Earlier quoted context omitted.

The insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my f…

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

Yes, but as far as I have seen, not auditing/compliance frameworks have updated their recommendations yet. Maybe its not the frameworks, but the individual auditors and their templates, but I have seen it a 'requirement' for PCI, sarbenes-oakly, etc.

its much easier to keep it in place to make the auditors happy than remove it, and risk exceptions on your report that you have to defend.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#182

So far I've seen ZERO EVIDENCE. Reuters and the Washington Post have breathless claims of Russian hackers "according to officials familiar with the matter." Uh huh. Saying "APT29" or "CozyBear" doesn't make the accusation any more credible. If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?" It's pretty amusing, in a depressing way, to see how quickly so many…

Why are there so many people who absolutely deny Russia does any hacking. It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on. I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.

He's not denying Russia does hacking. He's saying there is no evidence that ties this to Russia over any other group. Maybe Russia is most likely based on priors, but I don't think the average HN commenter has an accurate estimate of nation-state hacking frequencies.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#183
post #158

Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…

> While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!)

That's not a common recognition by any means. Cloud providers are more secure and spend more on infosec than any business managing their own tech & data centers. Pretending that the cloud provider being the point of entry is in the same ball park of risk (or greater risk) is a strange talking point in 2020

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#184

Earlier quoted context omitted.

If the U.S. didn’t go to war over Crimea why would they go to war over this?

Because Crimea is another country/outside of usa jurisdiction? Whereas this is a direct attack to USA institutions/government.

This isn’t an attack _yet_. This is potentially a part of the process of developing the capabilities for a later attack.

Crimea is the first time a nation state has meaningfully changed its borders that I know of since WW2. As a result I would consider Crimea a much more egregious attack on American values and western interests than a software vulnerability that hasn’t been leveraged to cause actual harm.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#185

Earlier quoted context omitted.

Is there any actual evidence that his was Russia? All I've seen so far is solarWinds unsubstantiated claim.

Attribution is very difficult in this space. According to most articles I've read, senior officials believe it's Russia (and it makes sense given the scope/scale) but smoking guns are hard to find.

The Russia attribution track record is not very good. E.g. that Afghanistan bounty story appears doubtful and many of the earlier allegations of ties between the Trump administration and Russia were not substantiated.

Not that Russia is not a threat to the US, but there is a sizable part of the federal bureaucracy that wants to pin things on Russia for various reasons (it's not all anti-Trump either).

Edit: Downvoters, feel free to prove me wrong. Here's one source for my claims[0]

[0]: https://www.nbcnews.com/politics/national-security/u-s-comma...

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#186

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#187
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

It is. Hope, after new administration takes office, "hell sanctions" package would be approved, as well as closing Russian embassies and increasing military pressure to its borders. Sanctions already work, and Russian regime does not enjoy a variety of options to oppose it.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#188
post #158

Since this is a supply chain attack on software downloads, I think it's interesting to consider the implications for the security posture of a cloud-native organization. While cloud-native is commonly recognized as less secure (because the cloud provider could be hacked!), there are a few categories of attacks exclusive to onprem software deployments: 1. You misconfigure the onprem software, making it more insecure t…

Things aren't black or white, but SaaS typically removes one layer of security (the corporate firewall). Misconfigurations are then typically exposed to the whole world.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#189

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

I guess if you can be as successful as SolarWinds with that level of incompetence I should stop worrying so much about myself.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#190

This also came out today: https://mattermost.com/blog/coordinated-disclosure-go-xml-vu... It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.

Doubt it - that bug has been known by Go/Mattermost since August.
Post reply on HN