U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
krebsonsecurity.com
krebsonsecurity.com
https://twitter.com/KyleHanslovan/status/1338360093767823362
Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed
https://twitter.com/vinodsparrow/status/1338431183588188160/...
Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and installing it manually, LOL
https://twitter.com/KyleHanslovan/status/1338419999665508354...
1. Customers complain that they can't install latest version because it's checksum doesn't match what SolarWinds posted
2. The checksum doesn't match because malware has been inserted into the package during build/delivery
3. SolarWinds tells customers to ignore this and install it manually
Did no one think to check why the checksum didn't match?
head desk
https://careers-salientcrgt.icims.com/jobs/11200/network-sys...'
https://i.imgur.com/d8KbSZp.png
But, wow, imagine that's a job, just walk in, look at two programs and swap out parts as needed.
Vulnerabilities publicly available are numerous, and I gave no such details to anyone that would give them an easier time finding said compromises.
Its like saying windows 10 bug found --> HEY THE MILITARY USES WINDOWS 10.
It's also not relevant to the current attack since the code was legitimately included in the official release and, as such, baked into the valid checksum results.
Amazing. While I'm sure the attackers have already shut up shop and the threat no longer exists, this feels insanely tone-deaf from SolarWinds.
I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down all inbound/outbound traffic, snapshot all our running machines for later forensics, lock our AWS IAM access down to a single incident response account, and move DNS for our web properties to a "we've been hacked" page. (OK, it obviously doesn't say that, but something similar that has been heavily vetted by legal and marketing ;-)). We've drilled and timed it out and can stop the ship in ~5 minutes.
Either SolarWinds doesn't have a major security incident response plan, or they don't have the stomach to pull the trigger. Neither is promising.
The only missing piece is making sure that VP+ level folks are not incentivized in any way to suppress incidents. However, that’s beyond infosec—in that treacherous area between information security, shareholder interests and organizational politics.
I wish business continuity planning (which would include infosec procedures but has a much wider overall scope) was paid more attention and more widely scrutinized.
You’re not going to turn the business off because somebody’s inbox got compromised, or because there’s some unexplained event in the SIEM, and those are the sort of events you’re actually going to have to respond to.
If you don’t know what’s happened, I can’t imagine you’d know enough about the impact to justify turning the business off. The only scenario I can think of where this plan would make sense is if you find out somehow that you’ve already been the victim of a major breach that you failed to detect, so you think it would be worthwhile to just turn everything off while you figure out what happened (because how much worse can it get at that stage, really?...).
Nothing about this seems impressive to me. It sounds like a plan for people who don’t have a plan.
Also, as a side note, anything that needs executive approval to be done during an incident is (as a general rule of thumb) never going to be done during an incident.
duh, those get handled several pages before "press the red button" is even discussed. You think "turn off the business" is the only page in the playbook?!
> and those are the sort of events you’re actually going to have to respond to.
Tell that to SolarWinds.
You need a IR plan that has appropriate responses to the threats you are facing. But at the scale and impact of a company like SolarWinds it's actually rather reassuring to have a "stop the world" backstop because your threat model absolutely includes catastrophic levels of risk.
And "you won't be incentivized to push the button"? Come on. When things get to "state level adversary on your network, using your software to attack DHS and the Treasury" bad, you're going to absolutely push the button because in a few months when your CEO is answering questions in Congress they'll want to be able to talk about something that went right.
The only scenarios in which you'll have enough information to justify activating this plan, are scenarios where you'll also have enough information to respond to the actual threat, rather than just shutting everything down.
It's something that might sound impressive to people who aren't experienced with incident response, but it's practical uses are so close to non-existent, that any time that was spent developing this solution was most certainly wasted in lieu of doing something actually useful.
2. My own knowledge of folk rock and subsequent visits to Google and Wikipedia have not helped me interpret this reference, in this context:
"Electric Dylan/Pete Seeger with the axe"
Help, please :-D
https://en.wikipedia.org/wiki/Electric_Dylan_controversy
http://communityvoices.post-gazette.com/arts-entertainment-l...
> The Cliff Notes version is Dylan, whose latest album Bringing It All Back Home had upset many folk purists with its amplified accompaniment, performed at Newport on July 25 with amplified backing by the Paul Butterfield Blues Band, who played the festival on their own. As an offended audience booed Dylan performing with Butterfield's band (minus Butterfield himself), an incensed Seeger, outraged at his friend's apostasy, wanted the audio shut off and sought an axe to cut the cables as Dylan and the band ripped through "Maggie's Farm" and "Like A Rolling Stone," Dylan's just-released single.
I read this as, "we have a policy that under no circumstances will someone at a VP+ level declare a major incident."
It's one thing to try to duck bad publicity, it's another to not act quickly and risk the ire of the federal government.
https://www.oxfordlearnersdictionaries.com/us/definition/eng... lists it as a usage in North American English.
https://www.zdnet.com/article/sec-filings-solarwinds-says-18...
1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc.
2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's the only way to actually get work done. And then such glaring weaknesses that no one cares to fix. With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure).
Govt you are forced to write down these insanely long passwords with super complexity that cannot be cut and pasted that change very 30 or 60 days.
Because lost passwords are so common in these settings, the password reset process is usually a MASSIVE weakspot. I've seen it just be a phone call to a third party, you give them your username, they give you a new temp password - that's literally it. And the passwords end up everywhere. In lots of documents that float around, emailed around etc etc. And lots of password sharing when you get locked out of a tool and it will take a long time to get a new account setup (months). Pretty soon the procedures manual also gets you root access to everything.
In theory, the DOD CAC system (they've gotten better over the years) eliminates the need for passwords entirely, but somehow most teams never tie their system to it properly.
They wrote 60 days into FEDRAMP I believe, something I jaw-droppingly realized last year sometime. Whoever is writing these policy frames don't know what they're doing. NIST did away with those periodic password change recommendations for a very good reason but IMO they need to now recommend the opposite, directly, because the constant password changes are doing real harm.
> It's right there in section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-network. Security didn't care, it took the realization of the cost (delays, people too busy moving data to do their actual jobs) for management to step in and end the nonsense.
The same will be required for things like password policies. Until the issue becomes realized (weak/written passwords lead to a compromise), these policies will stay in place within organizations and teams. It doesn't help that the majority of the policy setters are not IT professionals (or only in the loosest sense, they can install software but have no real understanding of IT systems). In DoD, most come from a physical security background (retired/separated security forces).
It's not that, it's inertia and poor incentive structures.
In a large organization, if a policy was set in place by someone else, then, even when you know it's a sub-par policy, it's still in your interest to leave it alone. Doing so gives you a way to deflect blame in the event of a breach related to that decision. You can just blame the policy itself. If, on the other hand, you change the policy, you're more likely to be held personally accountable.
That said, you're also absolutely right about the expertise problem. I don't know much about government, but, in private industry, I've observed that the best way to get put in charge of cybersecurity is to start from somewhere completely outside of IT, and become good friends with the CEO.
This is the psychological/economics point of view, and I think it's the correct one for this problem. The other tricky issue, besides the CYA prioritization, is that being a dynamic entity requires other entities to do the same. If you start changing procedures in your section, other sections that rely on you need to adapt to these, and they may have the CYA attitude and resist that change.
edit: I wasn't calling OP a liar, I just couldn't find it.
"Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
My guess is the idea is to mitigate compromise of very old passwords, spray attacks using breached site creds, reduce insider threat and at least offer some mitigation for compromised hashes.
I think this is wise compared in work environments - 90 days, 180 or even 360 would be a good mitigation over _none_ to too many.
Without those other mitigations, pw rotation may still help more than it hinders, although I am definitely not a fan of it and recommend implementing all of the NIST’s recs instead.
For those looking to head that route, haveibeenpwned offers an API to check hashes against previous breaches. For a pw strength meter, have a look at zxcvbn.
its much easier to keep it in place to make the auditors happy than remove it, and risk exceptions on your report that you have to defend.
The worse one is this (seen a few times): Username/password and then you register your CAC with it. They only check the CAC itself for the cert expiration date. When it does finally expire (or gets revoked, say you need a new one early like happened to me a couple times, not to loss just became unreliable in the CAC reader), then you have to use the username/password combo (the password has been getting updated every 60-90 days during all this time) and register your new CAC.
But, since they aren't checking revocation data a stolen CAC + PIN (say it's weak, beaten out of you, or they observe you using it) even revoked would still be able to authenticate against that system until the cert expires or the admin (usually) manually removes the revoked CAC.
Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.
In an office? Absolutely not, never, not once. Offices are not private and not secure and in any kind of even vaguely sensitive setting allowing a colleague to have access to your password and impersonate you is a massive risk.
It is moronic to write passwords down and stick them underneath the keyboard.
Selling a subscription to a government org should look like a tasty enough piece of revenue pie to attract multiple bidders, I assume.
>“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
And still, very few have :(
Microsoft seems to be fairly forward thinking[1] on passwords, doing away with expiration requirements and focusing more on their risk based MFA stuff.
[1]https://www.microsoft.com/en-us/research/wp-content/uploads/...
Enforces minimum password complexity of case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type; Enforces at least 5 changed characters when new passwords are created: Stores and transmits only cryptographically-protected passwords; Enforces password minimum and maximum lifetime restrictions of 60 days; Prohibits password reuse for 10 generations ...
Jump over to healthcare, the worker with full access to the govt it system for cases WILL lookup their friend / family members / neighbors / famous person if they see them on site or realize they are in system.
I have one experience with a private health HMO. A close relative, senior doctor, absolutely knew they would be immediately fired if they looked up family records. It was crazy, they would not do ANYTHING related to family stuff even by request of person involved. Obviously this place had some type of audit trail, some type of monitoring team for non-assigned patient record lookups etc.
My govt IT job, to do billing you had to be able to see case notes, and the system was integrated across of a ton of agencies, so everyone basically had access to everything and because you had to share logins and passwords (it took like 6 months to get a new account setup) there wasn't any accountability (not that I think they monitored anyway).
I came away very unimpressed. We had to use outdated IE / Java combos etc. as well and block all system updates. The default landing page was an unregistered domain name.
Muskets beat bows and arrows, but we're in the 21st century now.
So I just typed them into notes on the VM and left them there.
The amount of fortune 500 and fortune 100 companies that I worked at where this is commonplace is staggering. The amount of businesses that never change their passwords is quite frankly, shocking. I left a fortune 500 company two years ago and I just tried my login on their external facing portal - and it still worked.
I've seen passwords being passed around in word docs and internal blog posts. At one place they were mixing development information with financial information. The idea you had several folders of corporate contracts mingling with developer docs on a sharepoint server was a real eye opener for me.
Nobody else seemed to care when I brought up the fact you just gave a bunch of developers access to facebook contracts and other financially important docs they have no reason to have access to. Their reason? It was too hard to set up a new folder with access restricted.
After a few years of experiencing these, I just became kind of apathetic to it. If nobody in authority cares, then why should I??
I too hope this is not just security theater as well.
It's heavily based on the NIST guidelines, so strong on 2FA, and discourages arbitrary password rotation.
> Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.
“SolarWinds.Orion.Core.BusinessLayer.dll is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. We are tracking the trojanized version of this SolarWinds Orion plug-in as SUNBURST.”
“ Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website. The trojanized update file is a standard Windows Installer Patch file that includes compressed resources associated with the update, including the trojanized SolarWinds.Orion.Core.BusinessLayer.dll component. Once the update is installed, the malicious DLL will be loaded by the legitimate SolarWinds.BusinessLayerHost.exe or SolarWinds.BusinessLayerHostx64.exe. After a dormant period of up to two weeks, the malware will attempt to resolve a subdomain of avsvmcloud[.]com.”
“This actor prefers to maintain a light malware footprint, instead preferring legitimate credentials and remote access for access into a victim’s environment.”
“In observed [trojan] traffic these HTTP response bodies attempt to appear like benign XML related to .NET assemblies” “Command data is spread across multiple strings that are disguised as GUID and HEX strings.”
Edit: Silly me, that was the first article on hn, see thread: https://news.ycombinator.com/item?id=25413053
Ouch!
Saying "APT29" or "CozyBear" doesn't make the accusation any more credible.
If multiple US agencies are trumpeting the same story, you really must ask yourself "Why? Why this? Why now?"
It's pretty amusing, in a depressing way, to see how quickly so many otherwise intelligent people can be made to snap to attention and fight the Russian Menace with a few anonymous government claims.
See: moon landing. Of course we went to the moon otherwise, what, 50,000 people are keeping a perfect and scandalous secret for half a century?
Not to mention that unmanned probes could also have placed reflectors without humans ever being sent to the Moon!
Scientists have reflected lasers just off the surface, and there are unmanned probes (Russian ones) that placed reflectors on the moon.
But the point should still be that, if anyone cares to learn about the difference, and how we know the difference between all these different types of reflectors, that information is freely available and could easily be understood by most people.
It's always some big conspiracy theory that multiple cyber security agencies, all the three letter agencies, and multiple news agencies are in on.
I'd bring up tin foil hats, but nowadays we can make fabric faraday cages so we can all be fashionable no matter what we believe.
Because there are many people paid to do so. (and soon if not already automated bots).
These are the techniques that have turned my family and many of their friends (and clearly a measurable percentage of Americans) into the exact opposite of the values they taught me and demonstrated for decades.
They truly believe virtually anything spoken by people like Limbaugh, Glenn, Orielly, Carlson, etc.
If you try to use some logic or evidence, even showing two conflicting statements made by one of those idols, they just shut down. The cognitive dissonance is too uncomfortable.
I don't think there's any doubt about the former claim, personally. The latter though, I think it's too early to tell, especially since we've seen recently how certain hackers have explicitly started putting bait signs from other nation-states to misdirect.
Has there been any indication at all that it was Russia in particular? A lot of people believe it was a state-level attacker based on the sophistication of the attack, but even conceding that doesn't make Russia the only alternative.
So...Operation Mockingbird?
I dont think the russian goverment is behind most attacks.
https://en.wikipedia.org/wiki/Cozy_Bear
Did you read the Fancy Bear incitements for the DNC hack?
https://www.justice.gov/file/1080281/download
The evidence was absolutely overwhelming. It isn't like someone saw an IP in Russia and assumed it must be Russians. The intelligence agencies had been tracking them for years. They knew exactly who was doing exactly what within the Fancy Bear organization. They know when people joined up and how they were introduced to their GRU handlers. The idea that these attributions are just thrown around whimsically is pure ignorance.
(source) https://nos.nl/nieuwsuur/artikel/2213767-dutch-intelligence-...
(summary) https://www.cbsnews.com/news/dutch-intelligence-us-fbi-russi...
Misattributions happen, but Fancy Bear / Cozy Bear is extremely well understood, and they don't generally make much of an effort to hide the fact that it was them that did it. For them, it's often about sending a message.
“There will unfortunately be more victims that have to come forward in the coming weeks and months,” he said. While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor, he said. A Kremlin official denied that Russia had any involvement.
https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...
Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0]
The US Government has spent two decades and hundreds of millions of dollars building tools to undermine the security of systems around the world, and withholding information from "Industry" that would help harden those systems.
I have no idea who "did" this, I don't really care. The NSA has been loading this footgun for decades.
[0] https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital-eb...
They work extensively with industry to patch vulnerabilities. There's a whole committee and process for it.
One of the core themes in the latter half of the book was how the government obtains zero-days, and then has a "committee of government and industry experts" that think about responsible disclosures, assuming the government is willing to "concede" the "national security advantage" of not disclosing the vulnerability.
Most vulnerabilities don't get disclosed.
Most systems go unpatched.
Just so the USG can exploit foreign systems.
It's very possible this particular vulnerability was found, but it's potential for spying outweighed the concern for patching.
We'll never know.
1. You misconfigure the onprem software, making it more insecure than the alternatives. This does not occur with SaaS products.
2. The software delivery system is tampered with, and you download and run malicious code on your systems with high privileges. If you don't run it, this can't happen.
Cloud deployments aren't obviously safer, but they have clear advantages unless you are willing to pay top people to work on and secure each onprem deployment full-time.
NB: I don't actually believe "the cloud" is fundamentally more or less secure than onprem deployments. Rather, I frequently hear people argue that a website being hacked - or the potential for it - justifies a movement to onprem, and I think this is (usually) false.
(GCP is similar but SCC is earlier in the development cycle and their threat detection isn’t well designed.)
That's not a common recognition by any means. Cloud providers are more secure and spend more on infosec than any business managing their own tech & data centers. Pretending that the cloud provider being the point of entry is in the same ball park of risk (or greater risk) is a strange talking point in 2020
Misconfigured, insecure AWS configurations are a dime a dozen. Not sure this point tracks.
How is this NOT an act of war?
How the capacity is applied may be another story.
There's also evidence that Russia infiltrated the Treasury in 2015, unrelated to the election interference afterwards.
It's been war for a long time, and we have not been winning.
Because spying is not an act of war.
If it was, the entire world would be at war with the entire world.
This is just what countries do to eachother. Welcome to the 21st century.
Does the US escalate to a shooting war with the second biggest nuclear power in the world?
So it's not surprising Russia thinks they can act with a lot of impunity without facing catastrophic consequences.
If we do nothing, we're sending the message that these actions are okay.
I think it sends the message that these actions won’t trigger nuclear war. How would you even get public support for war with Russia?
We don't hear about it much. But if this is an "act of war" the US has conducted dozens of these kinds of "attacks" on others over the last ten or fifteen years.
Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon [0]
[0]: https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital-eb...
Essentially make life difficult for the people who actually run Russia.
You sure about that? "They" have been claiming Russia is the boogie man for years, but it's never been proven. In this case, it does appear like a complex hack. Wouldn't be surprised if it's China, Iran, North Korea, Russia, U.S. Government (yes, hacking itself), etc.
It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the culprit is.
the amount of insane unfounded crap posted in HN comments is growing and i'm not sure if there is a fix.
BTW recent articles say it's microwaves
The only common element among USA facilities in Havana, Guangzhou, and Tashkent is the USA facilities themselves. Much like the situation described in TFA, those facilities were built by the most corrupt bidders. It will surprise no one when it is revealed that some corner was cut, and American personnel were exposed to harmful amounts of some ghastly chemicals, radiations, etc.
It is literally a conspiracy theory to reject this simplest possible explanation in favor of some outlandish three-way joint venture among the Cubans, the Chinese, and the Uzbeks, three nations not known for ever having done anything together.
I'm totally on board with accident/malpractice from shitty construction.
But implying or outright saying the CIA used a weapon on their own employees is crazy - without actual proof - especially to write out on HN.
Sure as pointed out below the US has done - and probably is - doing stupid things. But I really don't buy testing a WEAPON without consent
So you want bombing to start over this? I don't.
Anyways, no sane, decent person should wish a war.
[1]: I am a whole lot less interested in defending us around the middle East and in Afghanistan though.
Very simply because it's not an act anyone would initiate armed conflict over.
[0] (U.S. Escalates Online Attacks on Russia’s Power Grid) [ https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-r... ]
Just because the tip of the iceberg has been discovered doesn't mean its mitigated. Even Fireeye is probably still compromised. It will take a while to understand the actual scope of this.
And in the meantime new attacks are likely happening also.
https://www.reuters.com/article/uk-usa-cyber-treasury-exclus...
It's hard to get less credible than unnamed sources with no evidence.
I, and many others, no longer have any faith or trust in the news media. Time and time again the news media has been caught spreading lies and disinformation so sorry I am no longer going to "take their word" for it, and trust they have properly vetted their sources
Also They do not lead themselves to credibility by having a Matrix style photo with "hooded hacker" trope prominent in the article
Your distrust is misplaced because it's been confirmed by multiple people in the government now.
Crimea is the first time a nation state has meaningfully changed its borders that I know of since WW2. As a result I would consider Crimea a much more egregious attack on American values and western interests than a software vulnerability that hasn’t been leveraged to cause actual harm.
I took a look out of curiosity, and there have been a lot more border changes in the world than I was expecting. Lots due to decolonization in Africa. The partition of India in 1947 was huge. Lots of European changes, of course. Many small border cleanups. The changes go on for page.
See https://en.wikipedia.org/wiki/List_of_national_border_change... (That page is since WWI, so skip to 1945.)
Ultimately, the hack is the practical responsibility of the victim.
Don't fall for the Kissinger style war mongering.
“There will unfortunately be more victims that have to come forward in the coming weeks and months,” he said. While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor, he said. A Kremlin official denied that Russia had any involvement.
https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...
https://www.trendsmap.com/twitter/tweet/1338708743782092800
Edit: Had a thought - Since the NetFlow Traffic Analyzer tool stores historical network traffic data, I wonder if Dominion traffic was pulled before the breach was closed.
"Engineers are expensive, so don't build, buy!"
How about... the middle way? Let your own engineers deploy open source, something you can verify, even audit, if you ever have to.
Ah, I forgot. Those usually don't come with fat envelopes from the provider to the people making the decisions.
Literally how is this not the take away from this story? It's time to stop putting stock in one big company to do all the work for you.
I suspect there will likely be further agencies and of course private companies to come forward in the upcoming weeks/months.
[1] https://twitter.com/Bing_Chris/status/1338552048342753288
Off the top of my head, the only real solution is to feed a lot of this arbitrary traffic through trusted brokers which is going to make us even more dependent on Google, Microsoft or whoever else takes up that mantle.
-more than 425 of the U.S. Fortune 500
-all ten of the top ten US telecommunications companies
-all five branches of the U.S. military
-all five of the top five U.S. accounting firms
-the Pentagon
-the State Department
-the National Security Agency
-the Department of Justice
-The White House"
Purely from a risk management perspective, it's a terrible idea to have a single point of failure for all of the above
Use the products of multiple companies for everything tech related?
Give AMD processors for the army, and INTEL to the white house?
Should telcos use windows, and the pentagon linux?
NSA can use excel, and NSA libreoffice?
Collecting the generic common components and software used by large chunks of people would yield an endless list.
Even then, when an exploit comes out for something, the only benefit is that you can limit the extent of damages, not prevent it.
Removing all single points of failure in this scale seems impossible.
Nonetheless, everything I've read points to Solarwinds conduct being borderline negligent. For example, they not only told customers to ignore inaccurate checksums but they also failed basic server security.
I'd recommend giving it a read. It gives an accurate-but-uncomfortable overview of how the US government handles cyber security issues.
SolarWinds says it has over 300,000 customers including:
-more than 425 of the U.S. Fortune 500
-all ten of the top ten US telecommunications companies
-all five branches of the U.S. military
-all five of the top five U.S. accounting firms
-the Pentagon
-the State Department
-the National Security Agency
-the Department of Justice
-The White House
If they just did "consulting" and trained the staff against social security attacks, and improved a company's policies, how could managers that authorized the expense justify it? Where's the shiny "product" that "keep us safe"?"Do you mean we have to periodically expend money to keep ourselves safe? I'll go with Vendor B, they have a blockchain-based Machine Learning tool that's going to safeguard us against current and future threats!"
Salesmen (external or even worse internal) convincing inexperienced CTOs or VPs that they need <this exact software> regardless of any real world factors...
These are the people I would throw out with their own bathwater.
The two sites I monitored w/ that tool, we used it to determine when a 3rd party account’s login info has expired.
So, I would expect my saved credentials to be invalid, but that is just my anecdote.
The rest is just simple uptime and response time monitoring of specific URLs, which we publicly expose anyway, so no threat there.
https://en.wikipedia.org/wiki/Multilevel_security
Their are Operating Systems in existence which could prevent this and almost every other breach. However, most technical people aren't even aware of the fact that they CAN exist, and actively believe the opposite.
Hopefully Genode.org will have something useable for the average programmer like me, in a year or two, and I can use that as an existence proof.
Also, there are Data Diodes to help restrict what goes where.
https://en.wikipedia.org/wiki/Unidirectional_network
I think we'll finally get our act together in 2025 or so, 50 years after the first Multi Level Systems were finished.
They're playing a VERY dangerous game, as if they would rather the entire world be destroyed before facing the possibilities of justice (Gitmo, military court tribunals, and everything else that the EO from 9/18 outlined).
The bottom line: the MSM has been full of $&@T for quite some time, and this claim in Reuters is most likely more of the same.
Attribution is hard, but those two companies have a solid reputation and do not make BS claims.
Shameless disclosure: i was doing something similar (I do not have a plan to maintain long time) but would love to hear better solutions: https://github.com/getsumio/getsum
This happened months ago and there is no telling how much data the attackers have exfiltrated from these companies.
https://www.zdnet.com/article/sec-filings-solarwinds-says-18...
A password generator that allows retries means people will hit that button until the string is memorable, reducing the entropy.
As a simplifying assumption, assume everyone agrees about which of any 2 strings are more memorable.
If someone takes m random samples, and of those, takes the one they find most memorable, how much does this reduce the entropy? If there are N possible strings, and so with a uniform distribution there would be, uh, -log_2(1/N) bits of entropy, I think(?) (because, summing over the N terms of -(1/N) * log_2(1/N) , gives a total of log_2(N) ) If one takes the maximum of m samples, what does that look like? The cdf of the uniform distribution over the terms (identified with their order in the list ordered by memorability) would be P[x \le a] = a/N , and with m independent samples , P[max(x_1,x_2,...,x_m) \le a] = (P[x \le a])^m = (a/N)^m = (1/N)^m a^m, and so the pdf would be, around (1/N)^m * m * a^(m-1) (approximating it as continuous because N is large. I am not sure that this is a reasonable approximation.) Then, the sum becomes, uh, again approximating as continuous, integrating from a from 0 to N, (1/N)^m * m * a^(m-1) * (-1) * log_2((1/N)^m * m * a^(m-1)) da , which is integral of (1/N)^m * m * a^(m-1) * (-1) * ( mlog_2(1/N) + log_2(m) + (m-1)log_2(a)) da which is, (mlog_1(1/N) + log_2(m)) + integral of (1/N)^m m(m-1) a^(m-1)*log_2(a) da ...
uh..... ok I just threw wolframalpha at it, and I got, -log_2(m/N) + ((m-1)/(m ln(2))) which, subtracting that from the initial -log_2(1/N) , gives log_2(m) - ((m-1)/(m ln(2))),
and that "((m-1)/(m ln(2)))" is about like, 1 or 2 or therabouts (it is 0 if m=1 of course).
so, if all the perhaps questionable approximations I made didn't mess this all up (and I didn't mess this up in some other way), I think that says that, if you pick the most memorable out of m random strings, by doing so you reduce the entropy by about log_2(m) + 1 bits.
That doesn't sound too bad to me, really. Well, I suppose it depends how many bits you have to spare, and how big of an m you pick.
Here’s a slightly different approach to this. Let’s instead assume that the set of “memorable” strings is constant (say of size N/M where N is the number of all strings) and the user hits as many retries as needed to get a string from the memorable set. If the number of retries is a random variable X, then if we know the distribution of X we know M. Since the number of bits lost is something like \log_2(M), we just want to find out how X relates to M.
EX = \sum_{i\geq 0}i(1-1/M)^i(1/M) = WolframAlpha :) = M - 1
So it matches: if your average number of tries is M - 1, you lose something like \log_2(M) bits of entropy.
Makes me feel better about all those times when I hit retry a dozen times.
You can't punish lack of ability, just like you don't punish someone for scoring a B at school.
Everything happens after the fact, and no one knows what the next breach will be. And that will continue until the your average Joe's system no longer has 100 vendors each ordained by high management that basically acts as malware themselves.
Someone even started blaming the H1Bs, the mentality is amusing - fix nothing and find blame first and (often) blame it on the wrong thing - I'm glad I don't work for an organization that has the same mentality. Though I can certainly see many of the largest companies and a large percent of people have the exact MO. That also needs to change.
[0]: https://www.theepochtimes.com/dominion-voting-systems-uses-f...
[0]: https://www.theepochtimes.com/crucial-logs-missing-from-antr...
Their origin story read like how we supported the original mujahideen in Afghanistan. We all knew how that turned out.
[0]: https://dvsfileshare.dominionvoting.com/Web%20Client/Mobile/...
The story also turned out to be not necessarily true, from another comment.
That is literally what an ad hominem attack is. Attacking the source instead of the claim.
> The story also turned out to be not necessarily true, from another comment.
The other comment doesn't actually contradict the story, though it is pertinent information.
The story discusses the problems with Orion and points out that Dominion uses SolarWinds software, with a link to the page where they use SolarWinds Serv-U. That doesn't necessarily mean they also use Orion, but the article doesn't claim that.
Interestingly (?) they just changed the linked page in response to the story. It no longer contains the SolarWinds logo when it did earlier:
http://web.archive.org/web/20201214102053/https://dvsfilesha...
I don't understand why people think doing things like that helps them. Of all the election fraud claims, the Dominion Hugo Chavez bit is the furthest out in conspiracy theory land, and then they do things like that which are just going to end up on Glenn Beck's nightly rant.
You might want to avoid The Epoch Times as a source of information in the future, they are unreliable. [1]
[0] https://krebsonsecurity.com/2020/12/u-s-treasury-commerce-de...
The next question is obviously whether they use Orion in addition to Serv-U. Or whether the Serv-U updater was compromised in addition to Orion.
> You might want to avoid The Epoch Times as a source of information in the future, they are unreliable.
Note that they get the same rating ("MIXED") as CNN, MSNBC and Fox News:
https://mediabiasfactcheck.com/cnn/
https://mediabiasfactcheck.com/msnbc/
https://mediabiasfactcheck.com/fox-news/
Not that this is any kind of ringing endorsement of The Epoch Times.
The deep state is deeper than we thought!
1. https://www.whitehouse.gov/presidential-actions/executive-or...
The 6k vote flipping in Michigan was claimed to be some sort of computer error. But why were the logs deleted? that seems like a hacker thing to do to delete the logs. A judge just released the audit report.
https://www.freep.com/story/news/politics/elections/2020/12/...
Likewise, we are to Trust and accept the results on Dominion Machines. When the only audit that was permitted to be performed, uncovered a 68% error rate, and logs deleted.
Trust but verify. The verify part has not really been done. We are only told to Trust.
https://www.washingtonpost.com/outlook/2020/12/10/voter-supp...
If so, this is on scale with the OPM hack in 2015. This is huge.
Smart to use the election timing while authorities were focused elsewhere.
Not that Russia is not a threat to the US, but there is a sizable part of the federal bureaucracy that wants to pin things on Russia for various reasons (it's not all anti-Trump either).
Edit: Downvoters, feel free to prove me wrong. Here's one source for my claims[0]
[0]: https://www.nbcnews.com/politics/national-security/u-s-comma...
For a very good reason.
Russia is in NO uncertain terms a hostile and aggressive nation that we all need to be wary of.
https://mattermost.com/blog/coordinated-disclosure-go-xml-vu...
It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.
Also, I realize the SAML -> SolarWinds connection is a bit of speculation on my part, but SAML is mentioned in Microsoft's advisory: https://msrc-blog.microsoft.com/2020/12/13/customer-guidance...
It sounds like a privilege escalation using the Go/SAML issue.
I've always done my best to err on the side of "let's try not to add yet another level of complexity" and this strategy has yet to fail me.
So, never. At least, not in our current software development industry.
They're not really "yet another startup".
I also don't think that the departments of the US Government are all going around all willy-nilly dropping tools from "yet another startup" into their core infrastructure.
While your overall point may be valid, it's tough to come to the conclusion that it is applicable here.
Corporate IT, too, from what I've seen.
Today it is. If we knew when SolarWinds was added to the government systems, his comment might stand.
And, if we're being honest, those technologies probably are based off startup tech; SolarWinds purchases and incorporates startup companies (such as Vivid Cortex recently).
Age doesn't imply its good either, but blaming startups isn't the problem here.
Russia agrees.