Live data from Hacker News

U.S. government probes VPN hack within federal agencies, races to find clues

reuters.com

31–40 of 61 posts

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#31

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

The attack vector Makes more sense. Your enemies will always have new backdoors they don’t report so you need a many as you can get. Closing loop holes isn’t super effective because there will always be a new bug or exploit

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#32
post #31

Earlier quoted context omitted.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

The attack vector Makes more sense. Your enemies will always have new backdoors they don’t report so you need a many as you can get. Closing loop holes isn’t super effective because there will always be a new bug or exploit

There's another perspective on this that's often cited and if I remember correctly was used to argue against the release of stuxnet. who has the most to lose if there are widespread cyber attacks? Given the related attacks so far I'd say it's probably the US where most people are connected and everyone either wants to spy on or attack. But then again attacking sounds so much cooler which is why I guess we still do it

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#33
post #20

Earlier quoted context omitted.

>The government has no authority to demand a software bill of materials (SBOM) from everyone who publishes software. Speaking from US Gov perspective - if the company is part of a contract (and ~40% of the Gov are contractors), Gov certainly can. They can put nearly anything (legal) into the RFP/Q. Even if they do not say "give us your BoM", they can wrap it in requirements that in essence delivers the same exact res…

They could build in a requirement that the software has undergone penetration testing by a security firm, and that a copy of the penetration testing report along with any mitigations applied to the software be provided. I've never even heard of the software the government is using. Why aren't they using Cisco AnyConnect like literally every other company I've worked for who has a VPN?

Pulse Secure is pretty well regarded (or maybe was better regarded when it was a Juniper product). AnyConnect has had had will have its fair share of vulnerabilities as well. A few years ago I had to update the firmware our ASAs like four times in a year due to new vulnerabilities. Any commercial product you pick is going to have new vulnerabilities and you just need to stay on top of it.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#34

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

The only reason people use garbage like Pulse is compliance with stupid federal bullshit like FIPS 140.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#35

Earlier quoted context omitted.

For sure, my point was that the debate, instead of being between government figures who are in favor of keeping the right to listen in vs. non-government figures who want to keep them out, it will shift (has shifted?) to a within-government debate. In the days after 9/11, I don't get the impression there was much of an intra-government debate at all.

By intra-government you mean like US vs China? (or any other competitors? We could say Israel and Germany) I think this has always existed though the information age has swung the balance to there being more importance for average citizens to have encrypted data in a more general sense and not just finance.

"Intra" here means inside the same government (you're thinking of "inter"). The hypothesis is that there will be parts of the US government (like perhaps the FBI) that will advocate for government-controlled backdoors into all encryption, while other parts (like perhaps the NSA) will argue for the strongest, backdoor-free encryption possible.

I think it's an interesting hypothesis, but one weakness is that the government can have its cake and eat it too: they can mandate that all encryption have backdoors, except that the government is exempt from that requirement.

Of course, then it just becomes the usual "if you outlaw strong encryption, then only outlaws will have strong encryption". As long as backdoor-free encryption merely exists, the "bad guys" will get their hands on it and use it. So you haven't fixed the problem of being unable to prosecute crimes due to encryption, and at the same time you've weakened everyone's security. This state of affairs is still beneficial to the government, as it makes dragnet surveillance a lot easier, and your average citizen with "nothing to hide" won't seek out the (illegal) strong encryption.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#36
post #2

> The U.S. plans to address some of these systemic issues with an upcoming executive order that will require agencies to identify their most critical software and promote a “bill of materials” that demands a certain level of digital security across products sold to the government. Interesting, no mention of any requirements towards software manufacturers themselves. If you think about it, this will further incentiviz…

This theme keeps coming up. Some cohort of HN is upset that software manufacturers aren't directly required to produce "secure software" [1] I would suggest people look at a very foundational essay on this [2]. Key quote: " Security is a process, not a product. Products provide some protection, but the only way to effectively do business in an insecure world is to put processes in place that recognize the inherent in…

Sure, but if you're going to sell a "security product" and then the security turns out to be a joke -- or even decent, but flawed -- you should be held responsible for it in some way.

Obviously it's difficult to draw the line, and that's why we have courts. The company will argue that they did all that was possible, but as sometimes happens, something got through; the plaintiff will argue that the company's software had serious flaws because they were negligent or cut corners or had poor development processes or whatever. However imperfect the process is, the court can render judgment case-by-case.

(Before someone suggests this, I'm not trying to say that a random open source developer who works on OpenSSL should be held liable here. But if you're selling a product, you should hold some liability for when that product fails.)

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#37

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use.

If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else.

If the government started requiring all/most software to be open-source, it would create a market. There's no way big government vendors would refuse to create open source software. They would just shift to monetizing more heavily using consulting services, or support, or something.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#38

Earlier quoted context omitted.

Can you elaborate on what exactly do you mean by " software should be expected to provide some basic level of protection." ? In some sense security is binary - if your software happens to have even a single mistake that results in RCE or authentication failure, then it's totally exploitable and does not provide any level of protection whatsoever. And as experience shows, we seem unable to write any software without s…

You don’t have to perfectly secure in order to raise the bar past your adversary’s level of sophistication. But you do have to stop doing the same stupid shit that’s in easy reach of anyone who can program.

Once a complicated exploit is known, it can be added the arsenal of any script kiddie.

This isn't saying you're wrong that quality can raise the bar. It's saying that time and context also lower the bar. Especially, not being subject to "that’s in easy reach of anyone who can program" not guarantee by any purely default action - notably not guaranteed by spending X dollars.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#39
post #8

Wasn't Pulse Secure VPN the one that required an ActiveX control and IE in order to "secure" your system on Windows? I mean, when I see that kind of shit, I kind of assume the vendor sells some shit software.

Just yesterday I was on a federal government web site (FWS, BLM, or some similar agency), and it popped up a window saying that the web site doesn't work in Safari, and I should use IE10.

There are major federal government websites that have office hours. The EIN application website only works between 9am and 5pm. I like to imagine that it's this way because there's no webapp, there's just a team of people who get all the HTTP requests and manually respond to them. This would also explain its speed.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#40
post #39

Earlier quoted context omitted.

Just yesterday I was on a federal government web site (FWS, BLM, or some similar agency), and it popped up a window saying that the web site doesn't work in Safari, and I should use IE10.

There are major federal government websites that have office hours. The EIN application website only works between 9am and 5pm. I like to imagine that it's this way because there's no webapp, there's just a team of people who get all the HTTP requests and manually respond to them. This would also explain its speed.

If they're only paying support staff 9 to 5, it might make sense to shut it down outside of supported hours, even if it would probably still work, especially if they're not positive that it won't do something odd like start issuing duplicates if the back-end DB is down.
Post reply on HN