Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

321–330 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#321

Earlier quoted context omitted.

How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…

> the most egregious offenders are software developers

Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#322
post #175

Earlier quoted context omitted.

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

You either believe it or you don't. There have been instances where more details were released (the Clinton campaign hack, IIRC), and it just gave more opportunity for people who did not want to believe it to nitpick details.

Whoever does such things doesn't exactly sign their exploits to prove ownership. So the evidence might be something like IP addresses in log files: totally convincing if it's your log file, but so easy to manipulate it's useful to convince someone who does not trust you.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#323

Earlier quoted context omitted.

Seems about right, maybe add in 0.1 didn't patch 14-month-old RCE.

0.09 - Installed the patch, just couldn't get Management approval for the downtime to reboot the machine for it to apply.

This is absolutely my favorite thing. I at one point had a weeks long debate about what "patched" means with the vuln scanning team. They couldn't understand why I thought checking the running kernel in addition to the file on disk might matter.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#324
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

> I'm just wondering why this response has become so popular recently.

Nihilistic cynicism sounds a lot like smartitude to stupid people.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#325

Earlier quoted context omitted.

I'm sure malicious people are very grateful that this platitude is in circulation.

Calling it a platitude is selling it short. Yes, it's a little strained in the context of people trying to deceive you, but the malicious are still vastly outnumbered by the incompetent.

In general, I agree that most bad things happen by accident, but I think generally it's an unhelpful statement. You should be slightly more suspicious of someone claiming innocence when they clearly experience benefits from the consequences of their actions.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#326

Earlier quoted context omitted.

Exacty. And we also know that the NSA/CIA have placed Russian language inside their exploits to frame other countries.

Source?

Marble Framework from Vault 7 leaks.

https://wikileaks.org/ciav7p1/cms/page_14588467.html

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#327
post #135

I'm always skeptical of these "nation state" claims, it seems like an easy way out of any tough question about the security of these systems. "No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out". I suppose "we think it could be done by a group of two or three teenager…

Your comment didn't age well.

https://www.fireeye.com/blog/threat-research/2020/12/evasive...

If this is not sophisticated, I don't know what is.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#328
post #216

It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…

> It's time to admit that computers connected to the internet can not be secured. Iranian centrifuges were air-gapped (ie no internet connection) and they still got hacked by Stuxnet via USB. https://en.m.wikipedia.org/wiki/Stuxnet We are well past the point where even stuff that's not connected to the internet can not be secured.

I am bit skeptical of the accidental USB insertion story.

A secure air gapped network won't have open USB ports . Only privileged users who know what they are doing should even have access to a port.

.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#330
post #212

Earlier quoted context omitted.

...and yet somehow people tell me I'm crazy when I demand that software not autoupdate without user intervention. Automatic updates are RCE vulnerabilities.

To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.

> There's not much that can stop attacks like this.

Not giving people RCE on your machine will stop attacks like this.

Post reply on HN