Live data from Hacker News

U.S. government probes VPN hack within federal agencies, races to find clues

reuters.com

41–50 of 61 posts

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#41
post #37

Earlier quoted context omitted.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use. If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else. If the government started requiring all/mos…

I think this would be even worse. The number of people that would need to have access to the patched versions would be too large to effectively secure and the patch would deliver knowledge about the vulnerability to any potential attacker. Government computers would be protected, but contractors and other businesses placed at higher risk.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#42
post #6
post #2

> The U.S. plans to address some of these systemic issues with an upcoming executive order that will require agencies to identify their most critical software and promote a “bill of materials” that demands a certain level of digital security across products sold to the government. Interesting, no mention of any requirements towards software manufacturers themselves. If you think about it, this will further incentiviz…

If I were a federal contractor, wanting to make more from my cost plus contraction, what better way than generating text files full of dependencies that will cause billable meetings to discuss why we should be ok with some old insecure library being used... that will always end with even more billable work to update the old, insecure library. Even better would be if I had to incur some billable time and cost on certi…

Luckily not all federal contractors think like this. Some would report this behavior and some of us would be quite happy to report it. There are those that still believe in doing the right thing, value tax payer dollars, and want to deliver for the American people. If only more of us wanted to completely rip out the rot.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#43
post #20

Earlier quoted context omitted.

They could build in a requirement that the software has undergone penetration testing by a security firm, and that a copy of the penetration testing report along with any mitigations applied to the software be provided. I've never even heard of the software the government is using. Why aren't they using Cisco AnyConnect like literally every other company I've worked for who has a VPN?

Not all agencies, but the US gov't does use Cisco AnyConnect and pretty much everything they use for IT is COTS these days.

Federal contractors as well.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#44
post #37

Earlier quoted context omitted.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use. If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else. If the government started requiring all/mos…

Who is to say they don't already do this?

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#46
This new arms race can eventually lead us to militarization of the whole economy. Almost every business operation will cost 40% more than now because of security costs. Security doesn't scale well and can't be commoditized (until we get AGI I guess). You can't just outsource it to Google or other megacorp.

That would be an insane waste of resources.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#47
post #45

Do people know that Fortinet is pretty much a de-facto Chinese company?

Any links on that? Only notable incident was when they apparently sold intentionally mislabeled Chinese-made equipment to U.S. government end users. https://en.wikipedia.org/wiki/Fortinet#cite_note-37

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#48
post #2

> The U.S. plans to address some of these systemic issues with an upcoming executive order that will require agencies to identify their most critical software and promote a “bill of materials” that demands a certain level of digital security across products sold to the government. Interesting, no mention of any requirements towards software manufacturers themselves. If you think about it, this will further incentiviz…

If anyone is interested to read more about Software Bill of Materials and how you can implement it check out OWASP Dependency Track project - https://owasp.org/www-project-dependency-track/

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#49

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

Trolling prediction: all U.S. agencies will switch to open-source software on top of Gentoo Linux as a way to easier patch whatever vulnerabilities NSA finds and does not disclose

:)

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#50

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

Also, whatever happened to "we need to pass the surveillance-expanding Cybersecurity Act" that promised to deliver us from cyber attacks?
Post reply on HN