Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

231–240 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#231

Earlier quoted context omitted.

Microsoft and Fireeye have both made similar claims and released substantial technical details. Attribution is hard, but those two companies have a solid reputation and do not make BS claims.

I see where they claim it's a sophisticated / state-sponsored attack, but could you share where they attribute it to Russia in particular? If that's a political assessment made by the media that's one thing, but if these sourced have some sort of technical data that inherently links it to a particular nation... that's something I haven't seen.

Yeah, I think that every time someone/some org knee jerks "it was russia" without at least acknowledging there could be a variety of well funded actors interested in compromising the US Treasury [or any other target] for a variety of reasons and/or having the incentive to make it look like someone else could have done it, just pours more fuel on the attribution fire.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#232

Earlier quoted context omitted.

Solarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.

And you posted this US military vulnerability on a publicly searchable internet site? head desk

Facebook query Find people who work for US Air Force.

Vulnerabilities publicly available are numerous, and I gave no such details to anyone that would give them an easier time finding said compromises.

Its like saying windows 10 bug found --> HEY THE MILITARY USES WINDOWS 10.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#233

Earlier quoted context omitted.

Solarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.

Good OPSEC, soldier! You must be a former marine...

Give the OPSEC snide comment to the job postings publicly advertised.

Don't hate on marines, they do hard work.

Using a throwaway account to be trite seems par for the course tho for opinions that can be disregarded.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#234

I’m completely out of the loop on what’s going on. Would anyone mind explaining like I’m from November and in high school?

To summarise it roughly: A software company (SolarWinds) whose software (Orion) is used by thousands of companies and government agencies worldwide, was hacked and a backdoor inserted into an update. An update which was subsequently installed by 16000 customers including the US Treasury and Commerce departments.

This happened months ago and there is no telling how much data the attackers have exfiltrated from these companies.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#235
post #227

Earlier quoted context omitted.

Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?

This seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#236

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

To be fair, the number of times this type of error occurs due to a state-backed actor who's quietly hijacked the build system with an undetectable backdoor is low compared to the number of customers who see the error for some other reasons (bad download for example) - so it's not entirely surprising they'd give this advice.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#237

Earlier quoted context omitted.

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

> if someone at the VP+ level declares a major incident [...] I read this as, "we have a policy that under no circumstances will someone at a VP+ level declare a major incident."

Nah. If we ever had to pull this specific trigger we're already in "mandatory disclosure to individuals whose data was breached, the federal government, and possibly the media" territory.

It's one thing to try to duck bad publicity, it's another to not act quickly and risk the ire of the federal government.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#238
post #59

Earlier quoted context omitted.

NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.

None the less, until the pandemic hit the US in March, at least one large government agency still had silly password complexity requirements and expired passwords every 60 days. They seems to have suspended password rotation at some point since I haven't had to change my password since March, but it's not clear whether it's going to come back at some point or not.

IRS still requires stupid complexity and lockouts in the beloved pub 1075.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#239
post #5

So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?

Because hacking isn’t considered an act of war. If they turned off our infrastructure that is an act of war because it would have caused material harm.
Post reply on HN