U.S. cybersecurity agency warns of 'grave' threat from hack
latimes.com
latimes.com
In some cases, we had systems standing by ready to swap out. Trying to find and remove the malware can be a needle in a haystack and next to impossible to find, and take longer that just swapping them.
I imagine we're going to see a lot of equipment sold off next year to try and recoup after being decomissioned.
https://www.techdirt.com/articles/20201215/13203045893/secur...
https://www.cisa.gov/news/2020/12/16/joint-statement-federal...
Microsoft claims [2], "We believe this is nation-state activity at significant scale ... Because of the sophistication of the techniques and operational security capabilities of the actor, we want to encourage greater scrutiny by the broader community..."
[1] https://en.wikipedia.org/wiki/Cozy_Bear
[2] https://blogs.microsoft.com/on-the-issues/2020/12/13/custome...
The Washington Post claimed it was specifically APT29/CozyBear, also based on "3 anonymous sources familiar with the hack" with no supporting information.
Neither FireEye nor the US government have officially attributed the attack to any state actor, nonetheless russia, though it would be unusual to make an attribution this quickly anyways.
FireEye makes no note of any tools used in the hack that have been previously associated with either APT29 or Russia in general. Their countermeasures [0] seem to suggest all injected code was either in english or encrypted, but it would be pretty dumb to leave unencrypted russian (or any other language) text in your hack of a US program.
The security group Intel 471 apparently [1] found a russian-language actor trying to sell access to the solarwind network in April 2020, but it is unclear if they actually had that access, if that access was connected with this hack, or if this individual was anything more than a middleman. I just googled the name, and there is a facebook page for someone with no friends or activity who is signed up for a couple of ukrainian groups (a support group for the mayor of a town, a public transit department, etc) so the facebook page is clearly a bot but there may be no association.
That's the closest thing I could find to evidence.
[0] https://github.com/fireeye/sunburst_countermeasures [1] https://twitter.com/Intel471Inc/status/1339233255741120513
[1] https://www.nationmaster.com/country-info/compare/Russia/Uni...
[2] https://en.wikipedia.org/wiki/List_of_states_and_territories...
It's a declining global power, but a rising regional power. It's nowhere what it was in the soviet days, but it certainly has been growing since the post 90s collapse.
> with a GDP the size of Texas [1,2]
That's only on a nominal basis, but on a PPP basis, they are the 6th largest economy in the world.
https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(PPP)
It's not rising in any sense.
Uh oh.
Even if the positions paid more and had more modern drug testing policies, I have never, NOT ONCE, met someone who works in software at a government agency or at a company doing government contract work who wasn't a massive fuddy-duddy-boomer.
These breaches will continue to happen until the Gov takes a more pragmatic approach to it's technology and brings it's culture more in line with the private sector.
When organizations rely on hundreds to thousands of platforms to operate, and those platforms are under the weight of hundreds and thousands of dependencies, it's not unlikely one could discover and quickly take advantage of randomly sprinkled secrets in some github repository. Humans, weak passwords, and improperly configured ACL are often the common denominator in the majority of recent breaches, not the systems themselves. People get lazy and start overlooking well established protocols that could have prevented these attacks. It's hard to do this right unless you hire red teams to perform monthly audits of every possible leakage or attack vector.
The objective evaluation of a comprehensive security architecture depends on its holistic effectiveness, not merely the effectiveness of the parts the designers thought about. By that metric, I am not aware of any commercial IT system that even meets the low bar of protecting against an attack with a mere $10M in funding, let alone the billions a state actor has access to. So, a question for you, are you aware of any commercial IT system in the entire world that you think would survive a $10M open bounty let alone $1B? If so, what objective, empirical evidence do you have to justify that claim? Hopefully one day I might get a convincing response to this question.
Even if we restrict ourselves to only consider the magic bank vault, it is still unreasonable to completely ignore everything else. It is a common problem for systems to be so hard to use or configure that it is nearly impossible to effectively use them. It would be like the magic bank vault requiring you to leave the keys unprotected on the ground at which point it would be unreasonable to claim the magic bank vault is a secure component since it can only be effectively integrated in an insecure fashion. Any claim that it was, in fact, integrated securely would need to positively demonstrate this fact against the common expectation of insecure integration.
Frankly, this is also getting very unrealistic. If any company had a system with even 10x that number of critical, trivial flaws I would be amazed. From my experience there are hundreds to thousands of such flaws which run through components at every level of design. Any system with hundreds of stupid flaws across hundreds of different components each of which can cause critical compromise is so poorly designed as to be anti-redundant and also hopelessly insecure. It is not even worth it to quibble over factors of 10 as by my reckoning these systems must improve by a factor of 1,000 to pose any real obstacle to a dedicated state actor unless somebody can actually point to a system that can withstand a $10M open prize with meaningful verifiable evidence for that claim.
I am not a huge fan of alcohol, but if a job told me I could never drink again and they will test me to see if I have been drinking it would feel super invasive and be a huge turn off.
Ah, but on the contrary, I can confirm, based on what I consider a “high level” of coding, that some people cannot code without smoking weed every day. I can also assure you that many, many devs are daily users, quality of code output not withstanding.
Adversely tons of sleep, creatine and coffee seem to expand my context and I can hold a lot more simultaneously.
Life is also not about being the best programmer though, so I would definitely trade ability for comfort if weed was offering that.
That's probably worse for doing anything technical. NSA has a track record of solving hard problems. Homeland Security is a collection of police departments gathered together for political reasons.
It's not California, but it's nothing either.