U.S. Treasury breached by hackers backed by foreign government – sources
reuters.com
reuters.com
"No, no, you don't understand, it's not that our systems are insecure, it's that the attackers where highly sophisticated and had the resources of a nation state, otherwise it would never have worked out".
I suppose "we think it could be done by a group of two or three teenagers with decent knowledge of wget" doesn't have the same ring to it.
Equation Group is presumed to be (a front for) the NSA. It forged a (code signing) certificate that otherwise shouldn't exist, using an MD5 collision. But not the MD5 collision painfully created by researchers a little earlier to demonstrate that MD5 was vulnerable, it used a brand new collision purpose made for this attack. That's a considerable investment.
Then also, we can look at who benefits from what was done. Equation Group's "Flame" malware damaged the Iranian nuclear programme. That's something the US government, Israel, some other countries wanted, but it isn't something a bored teenager wants, or a drug cartel, or most for-profit corporations.
As described so far I don't see either the resource needs or the outcome satisfying this conclusion.
However the trouble is MD5 collision isn't like that hilarious "Send all zeroes" Microsoft bug from a few weeks back where you just try it a few times then it works because someone was very stupid - the MD5 collision is pretty hard, the Merkle–Damgård construction actually works, your attack avenue is hammering on the compression function, everything else in MD5 (and any other Merkle–Damgård construction) works because of mathematics unless you can break that compression function - so having a program that when you run it spits out an MD5 collision with your preferred shape is great, it's a cryptographic breakthrough - but maybe it'll take 5000 years to run on a typical home PC. If you're a government or a big crime boss then money turns that into 5 days or (if you've enough of it) 5 hours instead, but if you're a bored teenager or small time crook not so much.
And like I said, Flame depends on a never before seen collision, so it isn't like they just re-used work somebody else had done.
https://www.washingtonpost.com/national-security/russian-gov...
I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and how solid these claims are.
There are indeed many good reasons why specific people aren't cited in these articles, but who you're trusting is the Washington Post, not these individuals. The trust comes from what the Washington Post does when it finds out it has published false information, and its track record of making sure what it publishes as news is accurate, or corrected when discovered to be false.
As a overly generic rule, trust (or don't) the Institution over the individuals.
Is it "they forgot to switch their VPN on once and we got a direct connection from an IP that belongs to the Russian state" like that other time (still manipulable but fairly conclusive IMO) or is it "that really looks like the modus operandi of those damn russians and we really need somebody to pin it on right now"?
To be clear I'm not making one of those "fake news" pro-russian rants, I can totally believe that Russia would very much do the things being reproached here if given the opportunity, I just have a really hard time taking the word of an anonymous source without concrete elements in these matters because the potential for manipulation is so absolutely tremendous.
The Washington Post's record on verifying the claims of the US national security apparatus is poor. The newspaper uncritically reported false claims by the Bush administration about Iraqi WMD. Many people people at the time found those claims extremely dubious, but critical voices were belittled or shut out of most mainstream reporting. More recently, the Washington Post has been all-in on Russia paranoia. That doesn't mean that everything they publish about Russian hackers is wrong, but it very well may be misinformation leaked by US intelligence officials, or something insignificant blown out of proportion and presented without any context. In December 2016, for example, the Washington Post reported that the Russians had hacked a Vermont utility. That story turned out to be complete nonsense, but the Washington Post never fully retracted it. If you look at the story today, you'll still get the impression that the Russians attempted to hack the utility, even though that aspect of the story completely fell apart. The Washington Post on Russia is a bit like Bloomberg on Chinese hackers (e.g., Supermicro).
bellingcat has also done a pretty remarkable job of identifying state-employed hackers and spies just through buying russian passport control information and other private information that's out there on the market
Whoever does such things doesn't exactly sign their exploits to prove ownership. So the evidence might be something like IP addresses in log files: totally convincing if it's your log file, but so easy to manipulate it's useful to convince someone who does not trust you.
When a leading security group (FireEye) says it's a state-level actor, I don't think they are doing PR.
It's fine to be skeptical, but why are you being skeptical? Perhaps it's lost on me but I don't think the claim that PR would look bad _if it were teenagers_ is a good reason to promote widespread distrust of ???.
I see the compromise of SolarWinds Orion software as far more likely to be carried out by state level actors than by script-kiddies. What would script-kiddies stand to gain?
https://www.fireeye.com/blog/threat-research/2020/12/evasive...
If this is not sophisticated, I don't know what is.
Also, the attack was carefully crafted. How could anyone expect or defend against a carefully crafted attack, by a nation state no less.
The idea that there's face saving to be had by blaming it on someone sophisticated just doesn't ring true to me. It still happened, the details specifically about who and how don't make your board, your boss, or Wall St. care.
It's way more relevant how you react to the breach, than it is that the breach took place.
I'm not accusing the WaPo of being distrustful here, I just think that in these cases the potential for manipulation, half-truths and technical mistakes from their sources is very high, and without either knowing who these sources are or what are the concrete element they're using to make their conclusions I find it very hard to blindly trust these sources.
There is a huge divergence in understanding of the purport of recent events, starting with the Wikileaks release of DNC emails in 2016, and continuing through to Hunter Biden's laptop
One camp believes or suspects that Russia is more of a useful bugbear and scapegoat for certain political factions in the US, used cynically as FUD to manipulate public perceptions, than something to be so worried about
The other believes in good faith that Russia is a dangerous and sophisticated adversary with assets in the highest levels of the US government, and finds the first camp to be incomprehensibly obtuse at best
It's difficult for these 2 camps to communicate effectively for some reason
Nihilistic cynicism sounds a lot like smartitude to stupid people.
The Washington Post also stipulates that the group behind it also hacked FireEye [1].
Makes me wonder if the TTP used for this attack is similar to the FireEye breach (if of course it really was APT29 behind both attacks).
Edit: Reuters reporter Chris Bing says he is hearing the way FireEye got hacked is similar to these government agencies [2].
[1]: https://www.washingtonpost.com/national-security/russian-gov...
[2]: https://twitter.com/Bing_Chris/status/1338233592347045892
Also, not that it would have prevented this attack, but as a community we desperately need a fully open source FPGA-based ultra simple firewall appliance. The absolute minimum set of configuration options, the simplest possible hardware architecture; something you could actually trust with your life. Right now I have zero confidence that any of the commercially available security appliances are actually secure against nation-states.
Source: Am Sr. Systems Engineer.
Firewalls are sort of an anti-pattern. The idea of firewalls to most people is "let's make sure they can't get past this one network control and then we can stop thinking about security." But we've known for a long time that defense-in-depth is the only real black-box security strategy. Yes, it would be nice if we could get high-performance packet inspection and analytics for cheap, but by itself it's next to useless.
More than a "firewall" we need 1) federated authentication+authorization protocols to stick in between the network and application-layer protocols (these basically exist but nobody uses them, so it's time to make something trendy), 2) a standard for ephemeral credentials tied to identities (tied to #1), 3) a standard for supply chain verification in modern technology stacks along with a simple way to certify they've been followed. This ensures better integrity of network boundaries (authn+z rather than network security) and that the software along the way is secure against supply-chain attacks.
I don't know if #3 is even possible, but theoretically it is. Just maybe not with any network we have today.
While it is difficult to design a secure procurement chain all the way to the SiO2, we could at least design simple enough hw/sw systems for which formal verification is an economical option. And then force government entities to use formally verified systems instead of the bug ridden crap most shops, especially the sw ones, have to ship under intense deadline pressure. The market has led us into a broken local optima, no way to get out short of state level action.
When do we complain about the even more expensive defense budget in this story?
Maybe layers? For government agencies, the government could manage procurement.
For non-government organizations, realistically, maybe some sort of public-private/foundation partnership, if the NSA is willing to bend a little. Which at this point might be in their best interest.
I don't want to oversimplify, because there is of course an uncountable number of software packages and a lot of noise on any network. However, "super simple FPGA network firewall" is not going to save us. Trustworthy logging, least-privilege account credentials and a competent SOC, among a number of other things, are critical.
Many orgs know how to be secure, they just can't or won't be due to some financial or usability constraint.
https://www.cm-alliance.com/consultancy/compliance-gap-analy...
https://blog.cipher.com/hs-fs/hubfs/NIST%20Cybersecurity%20F...
0. Forgot to secure access with password.
100. Nation state.
I really dislike how deflection pretty much absolved the actual hacker of any scrutiny or liability.
Its like the old bugs bunny cartoons where the hacker - bugs bunny - puts on a disguise and says “he went that way”
By state 'sponsored' it can mean many things, even if the countries just let them be and some officials get bribed to not do anything.
In this case it was in Syria, which is a fundamental mess, but the fact that it was Russian groups and they have military presence there, it is enough to put it 'state sponsored' label...
..
Edit: This was a purely commercial/blackmail type of thing, so I doubt it was the Russian government/Putin involved directly, but it could just be a side hustle of the same people that do try to hack government targets.
If they have the facilities and the state protection, might as well make some money on the side.
...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...
>...wow. you're aware that "obsolete tech" is what basically all critical infrastructure uses, right? The world is bigger than FAANG webapps...
Wow! 2010 called. They want their ideas about what makes the world go back.[0]
That's just crazy talk. Everyone knows that hardware has been completely deprecated. It's all clouds. Mostly cumulo-nimbus, in fact.
Power plants, chip fabs, heavy machinery, machine tools, factory automation and logistics systems are completely obsolete and never, ever used anymore.
Because there's cloudiness, hardware is just a waste of money and space, which is why we can stack 600MB of js libraries on top of each other so we can have the browser render an opaque 40x40px box.
[0] https://en.wikipedia.org/wiki/Poe%27s_law
(Please refer to the above link reference to resolve any confusion.)
FORBORNE PENDLETON PIEDMONT
They all seem to suggest some level of breakthrough with regards to cryptography, including public key cryptography.
I would not trust any declaration of “state sponsored hack” and it is a distinction that doesn't really matter but causes more harm than good
Guaranteed nobody will come looking for me.
Sincerely yours,
Evil mastermind
The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep information on many system that would likely require badges or intensive social engineering to access, both of which leave traces. Do you really think you could hide?
I'm an expert (of sorts) and I'm not sure that I could buy drugs on the dark web 100% securely if those resources were hunting me.
greed comes worse from the other side.
It always just a matter of spending a few more billions in tax payer money, you see the program/agency/task/what ever would have work perfectly if we just spend more money
That ship sailed a long time ago.
It was normal back in the 1990s for InfoSec folk to assume that "if it's connected to the Internet, eventually, it will be compromised."
The goal (then, as now) is to implement layered (defense-in-depth) mechanisms to deter such activities -- at perimeters, network and systems infrastructure platforms and software implementation.
This is (and has been for a long time), a well-defined, although usually poorly (if at all) implemented set of processes and procedures.
The levels of complexity for Internet resources have vastly increased over the past 25 years. Info Security techniques have advanced as well, but again are often poorly or not at all implemented.
However, far too many organizations implement a "Skittles" type defensive posture rather than defense-in-depth posture.
There are a variety of reasons for this:
1. Those responsible are ignorant of good security practice;
2. Those responsible are aware of the risks, but ignore it as it negatively impacts profit;
3. Those responsible are aware of the risks, but implement inadequate defenses because of the impact on time-to-market and/or profit.
4. But the most egregious offenders are software developers, who often just bolt on weak security measures or just ignore security altogether, rather than design with security as a primary consideration.
There are other reasons, but those are the big ones, IMHO.
Police are credited with making arrests, but are almost never credited with treating people with respect.
By your logic, police should be encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.
Doing the right thing for the right reasons is (or should be) a thing. That it isn't doesn't say much for those who ignore an important aspect of software design.
I've always striven to meet the ideal that "if it's worth doing, it's worth doing properly."
I suppose that I shouldn't hold others to the standards I set for myself, but sometimes I still do.
Feel free to be offended, but I stand by my original statement:
"4. But the most egregious offenders are software developers, who often just bolt on weak security measures or just ignore security altogether, rather than design with security as a primary consideration."
> By your logic, police should be encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.
No, by their argument, to the extent your first quoted sentence is true, police are (not “should be”) encouraged to treat those they're supposed to protect and serve with disrespect and err on the side of locking people up, rather than trying to create a safer, more prosperous community.
Which seems pretty accurate.
Blame always rises. Management knows that any product without extensive review is going to be bad. They push it out the door without that review because quality costs. Stockholders know. Software is bad because you can't sue the companies that made it.
The reasons you list for a weak defense posture don't really apply to a government. Also the GAO has issued a constant stream of reports saying US government agencies have poor security. It was likely only a matter of time before something like this incident happened. Similarly it's probably only a matter of time until the IRS, Social Security, and other agencies are successfully attacked on a large scale.
Perhaps I'm a little dense, but I'm not sure what you're arguing here.
Are you asserting that since sophisticated threat actors exist, security processes and procedures are useless, and as such, shouldn't be adhered to or implemented?
Iranian centrifuges were air-gapped (ie no internet connection) and they still got hacked by Stuxnet via USB. https://en.m.wikipedia.org/wiki/Stuxnet
We are well past the point where even stuff that's not connected to the internet can not be secured.
A secure air gapped network won't have open USB ports . Only privileged users who know what they are doing should even have access to a port.
.
I wouldn't be surprised if any network connected device is vulnerable to being exploited, even if not directly connected to the internet, by association of other devices on the network.
[1] https://www.usatoday.com/story/news/world/2013/07/11/russia-...
Another problem is that the complexity in modern systems is increasing and designing secure systems on top of complexity is next to impossible. I think Unikernels have a good chance of delivering secure systems from a software perspective, but it seems even modern hardware has enough vulnerabilities to thwart those plans.
How so?
In fact, competent InfoSec folks will tell you that you should assume that "if you connect a device to the Internet, eventually it will be compromised."
That's not to say a device will be compromised, but making such an assumption, given the history of Internet connected devices is an eminently reasonable one.
I've yet to see any formal proof that computers connected to the Internet can be secured.
If you have, please link a reference. I'd love to see it.
But even ordinary claims require ordinary evidence.
The burden of proof is on the claimant, not the defendant. I believe that's the point parent was addressing.
Absolutely. I was pointing out that in this specific case (whether or not devices connected to the internet can be secured), the converse is also true.
https://en.wikipedia.org/wiki/Provable_security
If you read that article you'll see that current approaches don't even attempt some kinds of proofs such as proof of security against side channel attacks. It goes by other names as well such as proof of code correctness:
https://www.schneier.com/blog/archives/2009/10/proving_a_com...
A major problem with current attempts at proofs is you can at best create a proof based on a system specification and what you want it to be secure against, which basically means you have to already know all possible attacks including zero day attacks. So far the field has resulted in nothing practically useful as far as I know. Homomorphic encryption might be close to being practical for a limited set of problems and could be provably secure for a limited set of attacks, though I don't know if anyone has attempted such a proof yet.
A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt matter).
The hackers then appeared to hijack the “remember me” login session from our employees Chrome.app. Within a few hours, online webmail logins (edit sessions not logins) were occurring all over the world for this user’s mailbox. The hackers then spread the “virus” by emailing this employee’s known contacts the same spoof.
I don’t think Microsoft ever fixed the bug, as far as I know. Our method to protect ourselves was to upgrade to IP restricted logins on a higher level of Microsoft 365, and disable the “remember me for 30 days” feature. We’re debating turning off access to web-mail entirely because it does scare me that I think its still possible to do.
Anyone else experience this?
Individual’s account was compromised and was used to send emails to their address book asking them to review an RFP. They would then delete the emails that were sent and the account owner was none the wiser.
I am not 100% certain as to how the initial compromise happened, but it was an O365 environment and MFA was on. O365 did pick it up and send an alert, but due to a configuration error it did not disable the account.
Anyways, it worked out and we transitioned to M365 as well.
I work for Abnormal Security (https://abnormalsecurity.com), and we build products to try and catch these type of account takeover attacks.
You can reach me at egreenstein@abnormalsecurity.com.
However anecdotal, the user who was compromised is aware enough not to re-enter their credentials outside URL schemes that match our password manager database, and they wouldnt have entered anything.
“Oh but how can you trust the user, they clicked a bad link?!”... again this email came from a very reputable vendor who we email with regularly, and the link would have been completely normal for a Monday morning in Q1 2020.
I also think part of our reasoning for why the credentials were not re-used was because all the sessions seemed to be headless chrome sessions, but no logins.
I’m not a data security expert, but in my best summary, it seemed they: - Had a “virus” that spread really well. I’m assuming they had two kinds of users. Spreaders, and targets. Our employee was a spreader, sending this bug out to his/our network. Once the targets were hit, they’d be selected out of the spreader pool (so the hackers could remain undetected). - The hack relied upon identifying ,mutually high volume (trusted) email senders. - The hack had something to do with leveraging the platform of Notion.io. Unsure if there is a bug on that platform which was also being abused, or if they just have a good system for hosting phishing pages. - The user’s authenticated sessions seemed to be hijacked and replicated across the globe in headless chrome browsers, which appeared to renew the session until the hack ended.
Notion.so is popular for phishing pages because it's a "reputable" "enterprise" application that doesn't raise the spam score when it's linked to in an email, can require signing in to view the page which further deters spam filters that actually check the links, and has less robust anti-phishing systems than Google Docs and Sharepoint (which are still used for the same purpose but require more tweaking of the template to avoid being auto-flagged).
Edit:: Another commenter in this thread indicated MFA did Not protect them.
And if this is a hack of data hosted on Microsoft Office 365 servers, how does it get detected?
Does Microsoft implement traffic monitoring for high-value clients?
Or do sophisticated organizations embed tracking pixels in emails to see what clients load them, and then check that those are authorized clients?
However, the US government has their own IDS/IDP that they use for the .gov domain, namely EINSTEIN (and its variants).
Then again, I have seen crazier things and sometimes government takes quite a while to catch up with technology implementations.
They were able to do to this by targeting one of the government's suppliers, a company called "SolarWinds" in Austin. The hackers were able to slip their software into a software update from SolarWinds over the summer.
And get this: "SolarWinds says on its website that its customers include most of America’s Fortune 500 companies, all top ten U.S. telecommunications providers, all five branches of the U.S. military, the State Department, the National Security Agency, and the Office of President of the United States". Yikes.
https://en.wikipedia.org/wiki/Executive_Office_of_the_Presid...
I have personal experience delivering software/software updates to the USG. I'm actually baffled as to how something like this can happen without an insider. I've never had any slight sliver of concern over the security of our supply chains.
"Never ascribe to malice that which is adequately explained by incompetence"
The attack that was simulated in my case utilized convincing social engineering, spear phishing, domain spoofing, and malicious OAuth apps meant to look like an internal resource/service to gain access to sensitive material.
It was very sophisticated and I’m glad I fell for it during a simulation rather than in a “real life” situation. It was a learning experience and a situation I’m way more paranoid about now. I could easily see admins and developers anywhere falling for it if they were specifically targeted.
This sounds like a post I saw on Reddit a few days ago.
This person's IT organisation had been talking about migrating to Github Enterprise, they got an email saying that it had been rolled out from an internal IT mailbox to an OAuth application that had been pre-approved on their Github Organisation.
For that particular scenario - if the org-admins have approved the OAuth application and are able to send mail from within the organisation - then it's probably game over anyway, since to approve the application they probably needed Admin rights anyway.
PKI remains a pain in the ass and very few organizations do it well.
Automatic updates are RCE vulnerabilities.
Nowadays, the general attitude amongst the "experts" is to assume that you/your company/organization WILL -- at some point -- get compromised and to, instead, plan for that eventuality and work to minimize the damage an attacker can do once they have gotten a foothold inside your network.
That means doing just the things you mentioned: preventing oateral movement, privilege escalation, and exfiltration of data, concentrating on RPO/RTO (a.k.a., getting things back up and running as quickly as possible once the shit hits the fan), and so on.
I've certainly not heard of anyone recommending that software and systems NOT be updated. There's only so much you can do, though. You can make sure that all of your software is only coming from "trusted sources", verify the published checksums (if any) and attached digital signatures, scan files with an up-to-date anti-virus (although, nowadays, that may not actually be worth anything), and yet STILL get hit by something like this.
So, you do what you can, try to protect yourself and your organization as best you can, and prepare yourself for when the day comes that it's your name in the headlines instead of the Commerce Department and Treasury Department.
(Personally, I'm of the opinion that if a nation-state wants in your network, they will -- one way or another -- get in. I'm looking forward to the day that hosts don't have a default route, are blocked at egress, and all "external" traffic has to go through firewalls and proxies before it can get out.)
Not giving people RCE on your machine will stop attacks like this.
https://www.politico.com/news/2020/11/04/georgia-election-ma...
Making the decision for a user is the issue. Consent to run software A on Monday is not consent to run unknown/unexamined software B on Tuesday.
In the vast majority of cases, receiving userspace updates in a timely fashion is not worth this real-time remote access vulnerability.
"...three of the people familiar with the investigation said Russia is currently believed to be responsible for the attack. Two of the people said that the breaches are connected to a broad campaign that also involved the recently disclosed hack on FireEye"
Reuters obviously not going to get comment from Russia, but decided to throw this in: "The Russian foreign ministry did not immediately return a message seeking comment late Sunday."
"This is a huge cyber espionage campaign targeting the U.S. government and its interests."
"“This is a nation state,” said a different person briefed on the matter."
And yet: "The investigation is still its early stages and involves a range of federal agencies, including the FBI"
0: https://office365itpros.com/2020/10/28/teams-115-million-use....
1: https://www.axios.com/google-g-suite-total-users-9a6d3df6-c9...
We're moving to 365 and I'd like to know what f*ckery to expect. =(
Anyway, was this hack related to the one for FireEye last week?
> Two of the people said that the breaches are connected to a broad campaign that also involved the recently disclosed hack on FireEye, a major U.S. cybersecurity company with government and commercial contracts.
Source: https://www.nytimes.com/2020/12/13/us/politics/russian-hacke...
If these reports and this surmise bear some resemblence to reality, I look forward also to seeing more reporting about steps and countersteps taken in response to these breaches. The timing for this reporting is too neat to not be intended to spur some stronger response.
After Jamal Khashoggi was assassinated, for example, it turned out audio of the entire murder had been recorded through surveillance. (I'm still not sure we ever found out how exactly it was recorded?) So there were lots of announcements that certain governments "knew" or "suspected" it was Saudi Arabia with little or no substance to back up their claims until the existence of the recording was later leaked.
I think there was similar discussion after MH17 when western governments "knew" Russia-backed rebels had shot down the plane and only later did we learn there was a recording of a conversation about what happened.
I guess even after Snowden governments like to do their best to pretend they don't have the entire world under surveillance at all times.
I would say it’s also quite likely that the US knows who did this or has known who has been doing it for a while. It’s highly unlikely that this press release wasn’t coordinated by the intelligence agencies to play into some advantageous scenario they’ve drawn up.
Israel certainly has the chops to do something like this, but lots of other "friendly" countries with good geeks wouldn't mind having this kind of info.
Nothing to lose at all. Deny the attacks and thank the news gods for publicity that distracts from reporting on their ongoing concentration camps.
Don't think israel is really concerned about attacking "friends".
https://en.wikipedia.org/wiki/USS_Liberty_incident
They live by different rules when it comes to the US due to their control/influence over our political parties, media, etc. But you already knew that.
Not to mention, that forensic analysis of tactics, tools, etc. often clearly point to borrowing/surveiling of other APTs.
Has anyone ever said they were hacked by a group of unsophisticated group of script kiddies?
FireEye, a Top Cybersecurity Firm, Says It Was Hacked by a Nation-State. The Silicon Valley company said hackers — almost certainly Russian — made off with tools that could be used to mount new attacks around the world.
https://www.nytimes.com/2020/12/08/technology/fireeye-hacked...
Seems like a commonality between the two that happened recently (2 weeks ago for us).
This is just an observation, nothing more. I'm sure MSFT spends a fortune on securing that platform (among other things).
> "Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website, including hxxps://downloads.solarwinds[.]com/...
So does this mean that the attacker masqueraded as SolarWinds and somehow (brute force?) forged the signature? Or that the attacker had agents working at SolarWinds?
This report reads like 'Russia attacked the US in cyberspace' when there is no transparency about the quantities of cyber attacks by governments in the world.
We're under attack by the Russians(again), according to anonymous sources(again) that are purportedly government officials. Where is the skepticism? Are we simply to, yet again, blindly accept evidence-free assertions made by anonymous government officials? As technically literate people know, it can be very difficult, if not impossible to determine who exactly intruded into a network, even in the best of circumstances. As historically literate people know, evidence-free government assertions of attacks by our "enemies" are often baseless, deliberately misleading, or outright fabrications.
The Treasury may very well have been hacked, and the culprits may have been Russians, but its madness to believe any of this without evidence that be scrutinized. There's been a lot of recent outcry for "gatekeepers" that sift through disinformation and decide what people are allowed to see and hear. As illustrated with this article(and the reception it has received), the problem isn't the existence of evidence-free assertions, its the uncritical acceptance of these evidence-free assertions. We need to maintain our skepticism and maintain the same demands for evidence regardless of what assertions are offered or who they are offered by. Lies and unsubstantiated statements are just as bad (if not worse) whether they come stamped with the approval of officially designated gatekeepers or not.
Not buying off on more than the fact the report was made.
Skepticism is the order of the day.
Maybe trusting Microsoft with the keys to your kingdom is a bad idea.
"Peace sells, but who is buying?"
Let's start a war, based on this "hack"!
https://news.ycombinator.com/item?id=25409459
Seems some are interested in keeping the populace scared. Wonder what scare tomorrow will bring.
That's an interesting way of saying a U.S. organization. Does this mean the NSA? I would have assumed they were talking about the FCC, but why not name them?
> Treasury and the Commerce Department’s National Telecommunications and Information Administration
I feel like we never hear about them in the news.
1- https://www.reuters.com/article/us-germany-usa-spying-idUSKC...
2- https://m.dw.com/en/how-the-uss-cia-and-germanys-bnd-spied-o...
Some are too poor (take your pick). Others are rich, but small (the Vatican). Most just don't care enough to prioritise it over better things they could be doing.
And then, there are countries that simply consider the US an ally, and consider it morally dubious or practically unpromising to spy on them.
Add this up, and I'd be willing to give at least 10:1 odds it's one of a list of maybe ten suspects, even when adjusted for GDP or population.
As an aside, I'd really be curious why this "everyone does it" is used anytime something like this comes up? Is it just macho "I don't have friends but there are useful idiots that consider themselves my friend" talk? Is it nihilistic/cynical pretentiousness? International whataboutism to defend one's team?
Because it certainly isn't based on any actual data. If you add up offensive hacking by the USA, China, Russia, Israel, and maybe two or three others, you're pretty well done with the full list, but still close to <x> nations short, where <x> is the number of nations that exist.
It's not like war where innocent people die and a there's a lot of human suffering. It's just a tech race where the nations doing a good job get a deserved advantage without doing direct damage to the population.
Perhaps if the NSA focused more on defense instead of offense, they'd have been better able to protect our own government against this sort of attack. Who can say if some of the vulnerabilities used were ones the NSA in fact knew about but was keeping in it's pocket for it's own use. A well-resourced expert federal agency actually focused on security could make everyone safer from snooping; when they instead prioritize snooping themselves, they instead help make everyone less safe from snooping.
Trump admin also did a press push after changing policy to ramp up digital offense [1]. Notably these stories were obviously is coordinated and on purpose. e.g. not just someone leaker talking to reporter it was strategy.
[1] https://www.nbcnews.com/politics/national-security/under-tru...
[0] https://www.npr.org/2019/09/26/763545811/how-the-u-s-hacked-...
But that doesn't seem to stop Russia who doesn't give AF already under huge sanctions, or non-state groups like ISIS
I know "America Bad" is trendy now, but I don't see the connection.
> The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press.
> “This is a nation state,” said a different person briefed on the matter. “We just don’t know which one yet.”
I bet it was someone on r/wallstreetbets
So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
Encryption: Yes.
Multi-factor authentication: Yes.
Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No.
There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "do not approve". You don't get any input information for making this decision.
Hacking this is trivial. If you know someone's password, you just have to occasionally try logging in. Eventually the user will accidentally click approve even though they didn't trigger the authentication.
You'd assume that nobody would ever fall for something like this, because surely nobody would be so stupid as to approve an MFA prompt they didn't trigger.
Meanwhile, my Microsoft Authenticator app triggers randomly about 5-10 times per day because every single MS app insists on "reauthenticating" me every 24 hours. So I'll be sitting at my desk and my phone will pop it up randomly. I'll look up, and sure enough, Teams wants me to re-MFA for some stupid reason.
I'm paranoid enough that I'll always reject these MFA prompts and then start the login cycle manually, but most people would just peck the button like a trained bird.
Similarly, I've run scripts before that needed 6 MFA prompts to complete (don't ask). I ran the script once and it asked 7 times... uh-oh. Is this an Azure bug, or a hacker from China? How could I possibly know?! The information is not provided to me!
This is Microsoft's fault, 110%, and I dare anyone here to argue otherwise.
So instead of reaching for the downvote button, make your case on how "yes, yes, yes, yes" is not a security disaster below in the comments please.
> All of the organizations were breached through a network management system called Solar Winds, according to three people familiar with the matter, who spoke on condition of anonymity because of the issue’s sensitivity.
https://www.washingtonpost.com/national-security/russian-gov...
>SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information
Notably, Microsoft's consumer MFA, the type used to protect Hotmail and XBox accounts shows more information in the exact same mobile app!
It's not that they don't have the capability, or don't know that it's important. Microsoft has explicitly chosen to never ever show additional information of any type for enterprise customers only.
They care about the security of their own things, not you stuff, in other words.
I'm just glad I'm not the only one who sees this as a problem.
Your actions may make it some If these things happen as well. I can think of a few organizations where your script would have resulted in your account being locked down and a security incident.
It is is on by default however when using the same mobile app for Hotmail or XBox live accounts.
Microsoft thinks the data of Fortune 500 companies is less valuable than your Minecraft skins.
If they offload auth to a on-prem or third party IdP (common in big hybrid O365 tenants), there are often different paths, implementation screwups or bugs that let you bypass MFA. Microsoft’s position is “buy Azure AD, Buy M365, Buy ATP” and other paths are poorly tested, or they explicitly tell you to F off.
Also remember that federal agencies are bigger than most fortune 50 companies, are usually global in scope and have lots of collaborations with other agencies and other third parties, and may have independent pockets within the agency. Those friction points are where problems tend to happen!
> I bet it was someone on r/wallstreetbets
Both could be true? ;-)
So now that I think about it maybe they did do it... That's the only way to find out what the Fed is up to next.
Hack a hot stock tip.
So, how do they know then?
Because that's what I believe.
> Staff emails at the agency were monitored by the hackers for months, sources said.
so krebs was in fact not defending against such an attack?
Damnit editors! First of all, don't end your sentence with a preposition. Second, nothing says the data was stolen. Here is a handy chart that will clarify between "stealing" data and accessing data without authorization:
Stealing Data vs Unauthorized Data Access:
C - I - A
Stealing Data Y Y Y
Unlawful Access Y ! N
C=Loss of Data Confidentiality
I=Loss of Data Integrity
A=Loss of Data Accessibility
!=Data may or may not have been altered depending on level of access.(I believe you'll find that the "A" is for "Availability", not "Accessibility".)
https://www.doc.ic.ac.uk/~ajs300/security/CIA.htm
https://www.pearsonitcertification.com/articles/article.aspx...
There isn’t a real rule against that in English grammar. See https://www.merriam-webster.com/words-at-play/prepositions-e...
For some reason it is very common amongst people who are interested in cybersecurity (or national security in the US).
This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation.
But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to non-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".
Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.
Sec+ is also a requirement for a lot of government related computer work, so it's not surprising that the guy they interviewed used the term.
But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translating German "Bundesland" as "state"), "nation" to refer to not-necessarily-ethnic bodies politick, and "nation-state" to specify "what we call a nation, what the Old World calls a state".
Which of course leads to a lot of confusion about the connotations of "EU member state", which in European discourse implies real sovereignty, but in US discourse implies a federalist Europe.
https://www.bnnbloomberg.ca/gavin-newsom-declares-california...
Its used because it makes the victim seem less incompetent, and doesn’t misidentify the attacker, doubling the ownage.
Or Israel. Israel is the nation state that has subverted the US govt more than any other.