Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

251–260 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#251

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

> Yikes

Well thanks to working at a large org I can say the mountains of pointless conversations that anyone has to dig through to find anything useful is the biggest security feature. Not the security tech.

I mean this is the govt we are talking about. Known for inefficiency and incompotence. The person or team going through that shitpile is probably at high risk of brain damage.

Its easy to find something juicy happening in one dept, like looking down a random manhole in a giant sewage system. But to figure out the dynamics across the system is why govts end up employing tens of thousands of people. Which no nation state or group can match. If Singapore or Dubai or Switzerland leak thats a much simpler sewage system. But the US is operating at a totally different scale. Killing or manipulating a few ants wont change giant ant hill behavior other than in Star Wars movies.

We are still in the stone age in how we deal with large data describing large systems. The list of large leaks and breaches will grow but look for/at impact, filtering out the noise from the sky is falling buffoon class.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#252
post #223

I wonder why more attacks are not attributed to businesses. They have lots of resources and would benefit from attacking government agencies and competitors.

Most salaried employees aren't willing to risk going to prison for their paycheck.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#254
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

> It's time to admit that computers connected to the internet can not be secured.

Iranian centrifuges were air-gapped (ie no internet connection) and they still got hacked by Stuxnet via USB. https://en.m.wikipedia.org/wiki/Stuxnet

We are well past the point where even stuff that's not connected to the internet can not be secured.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#255
So the NSC met yesterday about this hack, and yet they're already reporting attribution, including:

"...three of the people familiar with the investigation said Russia is currently believed to be responsible for the attack. Two of the people said that the breaches are connected to a broad campaign that also involved the recently disclosed hack on FireEye"

Reuters obviously not going to get comment from Russia, but decided to throw this in: "The Russian foreign ministry did not immediately return a message seeking comment late Sunday."

"This is a huge cyber espionage campaign targeting the U.S. government and its interests."

"“This is a nation state,” said a different person briefed on the matter."

And yet: "The investigation is still its early stages and involves a range of federal agencies, including the FBI"

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#256
post #229

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

I believe it was an insider. I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.

I believe not everyone always checks the checksums.

"Never ascribe to malice that which is adequately explained by incompetence"

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#257

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

SolarWinds also owns some SaaS companies that seem popular among small-to-midsized tech companies; Pingdom and Loggly are a few that I’ve seen at more than one job.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#258

So apparently Russian hackers were able to infiltrate the Office 365 accounts of multiple federal agencies. They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer. And get this: "SolarWinds says on its website that its customers include most of America’s Fo…

curios as to how Russian hackers slipped their software into solar winds. sounds like a major breach.

An insider got them access to a trusted signing certificate would be my first guess.

PKI remains a pain in the ass and very few organizations do it well.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#259
post #120

Earlier quoted context omitted.

semantics..users can and do choose to Flag comments because they disagree —not because they are considered inappropriate for the site

True, and (in my opinion) improper. But users can vouch for comments that are improperly flagged. If you see it happening, don't gripe, fix it .

>If you see it happening, don't gripe, fix it.

Sometimes flags/downvotes are warranted.

In my experience, most dead/downvoted comments are dead/downvoted for good reason.

But that doesn't mean I don't want to see them. Which is why I enabled "showdead." IMHO, that's often a better answer than vouching for a comment, but YMMV.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#260
post #162

All these systems are just too complicated. We keep adding features on features to software without a second thought, because it's invisible and you can't immediately tell from looking at it how insane it is, in a way that you wouldn't be able to ignore if these were mechanical systems. Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simp…

Who would be trusted to design and procure the hardware for such a device?

It's been done for the OS (vis a vis seL4[0]), why not take a similar approach for the hardware? CSIRO[1] would happily take the funding!

[0] https://github.com/NICTA/seL4

[1] https://ts.data61.csiro.au/

Post reply on HN