Earlier quoted context omitted.
Microsoft and Fireeye have both made similar claims and released substantial technical details. Attribution is hard, but those two companies have a solid reputation and do not make BS claims.
I see where they claim it's a sophisticated / state-sponsored attack, but could you share where they attribute it to Russia in particular? If that's a political assessment made by the media that's one thing, but if these sourced have some sort of technical data that inherently links it to a particular nation... that's something I haven't seen.
U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
231–240 of 350 posts
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#232Earlier quoted context omitted.
Solarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.
And you posted this US military vulnerability on a publicly searchable internet site? head desk
Vulnerabilities publicly available are numerous, and I gave no such details to anyone that would give them an easier time finding said compromises.
Its like saying windows 10 bug found --> HEY THE MILITARY USES WINDOWS 10.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#233Earlier quoted context omitted.
Solarwinds is def. Used by acrive duty cyber units at Lackland afb...and they wonder why we tell them they can't just install what they feel like.
Good OPSEC, soldier! You must be a former marine...
Don't hate on marines, they do hard work.
Using a throwaway account to be trite seems par for the course tho for opinions that can be disregarded.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#234I’m completely out of the loop on what’s going on. Would anyone mind explaining like I’m from November and in high school?
This happened months ago and there is no telling how much data the attackers have exfiltrated from these companies.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#235Earlier quoted context omitted.
Am I understanding the last one correctly? 1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted 2. The checksum doesn't match because malware has been inserted into the package during build/delivery 3. SolarWinds tells customers to ignore this and install it manually Did no one think to check why the checksum didn't match?
This seems an unfair leap. The most common cause of a checksum mis-match is going to be a partial download or something similar. It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#236SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#237Earlier quoted context omitted.
An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…
> if someone at the VP+ level declares a major incident [...] I read this as, "we have a policy that under no circumstances will someone at a VP+ level declare a major incident."
It's one thing to try to duck bad publicity, it's another to not act quickly and risk the ire of the federal government.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#238Earlier quoted context omitted.
NIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
None the less, until the pandemic hit the US in March, at least one large government agency still had silly password complexity requirements and expired passwords every 60 days. They seems to have suspended password rotation at some point since I haven't had to change my password since March, but it's not clear whether it's going to come back at some point or not.
Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
#239So, am I reading this right? the Russian government had the ability to impersonate the credentials of ANYONE in the marjoity of the fortune 500, the US Government, the US DOD, and our telecomm infrastructure... and they likely had this access for a while. How is this NOT an act of war?