Microsoft says it found malicious software in its systems
reuters.com
reuters.com
https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...
"One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation using text messages and encrypted messaging apps."
"a second evolving threat, namely the growing privatization of cybersecurity attacks through a new generation of private companies, akin to 21st-century mercenaries."
"As humanity raced to develop vaccines, Microsoft security teams detected three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19."
"One indicator of the current situation is reflected in the federal government’s insistence on restricting through its contracts our ability to let even one part of the federal government know what other part has been attacked. Instead of encouraging a “need to share,” this turns information sharing into a breach of contract. It literally has turned the 9/11 Commission’s recommendations upside down."
Given there are moves to make sure end to end encrypted messengers have backdoors for authorities, isn't this kind of infomation prepared to seed association of encrypted messaging with something bad, so that in the future when there is a talk about making these apps either illegal or making sure they employ backdoors, people wouldn't be outraged?
On a more serious note though, it certainly appears this is how its going. APT41 turned out to be some private company in chengdu and APT39 I think it was some outfit in vietnam. Its pretty interesting (cool?) to think that some of these global cyber-threats are essentially just a handful of people in some non-descript office somewhere.
Get access, pass it on to HQ for exploration. If it's valuable, office hacker gets to be employee of the month.
It seems like malicious actors had unrestricted access to almost every major computer system in the US Government, and now possibly microsoft itself as well?
How are these people ever going to be able to trust any of this equipment ever again? This just seems unbelievably catastrophic.
Remediation and recovery for most threats involves OS/app reinstallation, perhaps restoring from backups and images. However, if your threat is a sophisticated state actor based out of Russia, it's hard to rule out that they're got hooks in your server's firmware, that they've corrupted your backups as well, etc, etc.
One wonders how Russia could exploit the systems they've penetrated. Brick every gov't system on Jan 20th? Shut down SCADA systems? It's a cybersecurity nightmare.
Except for all those SolarWinds admins arguing that doing a simple scan and infected binary removal is enough and then moving on and anything more is "overreacting"
I feel sorry for all these people who are stuck working with such inflexible risk assessment/ITIL processes who are now trying to justify not taking any action because "SolarWinds said everything is ok"
There's obviously a contemporary movement that all your systems should be rebuildable by code, which would make getting the systems back into a trusted state (assuming you trust other layers / your code) a lot easier.
Obviously this doesn't help if your data is already messed up, if firmwares are hacked, and if your code itself hasn't had te rigour to be trusted, but it's a hell of a lot better position than "scan, remove, forget".
Microsoft won't be the last company ..
I mean...the smart controllers on the HVAC systems in these companies have to be replaced don't they? The smart locks, everything IoT, everything with a network interface in it at this point has to be assumed compromised. This seems like by far the worst cyber security incident of all time.
Did you recently binge-watch Mr. Robot?
And my comment was also a nod to that prominent hack. The discussion back then revolved a lot around the idea that Target had done a really good job of hardening most of their network, but then allowed a smart HVAC controller onto it. What seemed at the time like something minor (I believe it was a remote diagnostic device or something like that) is what the intruders used to gain access.
> Fazio Mechanical Services just issued an official statement through a PR company, stating that its “data connection with Target was exclusively for electronic billing, contract submission and project management.”
Namely: was that "exclusively" a contractual exclusion or a technically sound, enforceable exclusion? And on top of that, how was it secured? If the connection setup was breached, what was the maximum blast radius?
If there is a connected device in a supposedly otherwise secure network that allows traffic in or calls home, that device is an attack vector. Pure and simple. The only safe assumption is that such a thing is an insecure, unmaintainable black box that was put together by the cheapest fly-by-night contractor.
A "smart" device is worse, and guaranteed to be a dumpster fire. One should not be allowed anywhere near a secure network, regardless of its function. Printers, VoIP phones, climate control systems, ... they're all the same.
https://forrestheller.com/Apollo-11-Computer-vs-USB-C-charge...
Hah, no. And it’s definitely not the worst of all time. There is really no reason to be any more concerned than you were at this time last year.
You mean everyone should have a panic attack? As deeply terrifying this is, anyone giving in to panic would make them unfit for their job. I assure you they are very scared, but huge companies have protocols to deal with situations like this.
A million eyes will make short work of the cleanup.
http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thom...
Now ask about all of the things opening source wouldn’t affect: beyond compilers, modern devices have a lot of software running in firmware which can alter data. Proving that every component involved in the process hasn’t been subverted is a massive undertaking.
It's obviously true that open source is not sufficient to good software quality, or even necessary, but it does correlate, especially for open source projects with many users.
I often read through the libraries I use in projects (if their source is available). And if I find errors or shortcomings I will write an issue about it.
The "everyone gets to get in everyone else's business" model clearly is a disaster. This disaster.
Note that being hacked isn’t a binary state. What matters is what they were able to obtain. It could range from full compromise of the C-suite and domain admin, to phishing some marketing employee with no access to anything interesting. If anything, you should be afraid of companies who haven’t been hacked. It most likely means they’re either irrelevant, or they have been hacked and don’t know it yet.
This isn’t even the first time they’ve been hacked by Russians. It’s honestly not a big deal.
As someone who has been on the inside of these attacks, I’m just saying, what probably sounds earth shattering to most people is just a slightly more interesting Thursday for us. My expectations for security have been calibrated to be unfazed by yet another one. Honestly, it’s actually a little refreshing to see something slightly novel (although this isn’t actually that novel).
"We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth. Perlroth said the company stood by a statement it issued on Sunday saying it had no indication of a vulnerability in any Microsoft product or cloud service in its investigations of the hacking campaign."
No, they haven't
> "We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth.
That's not a categorical denial of being penetrated, it's a denial of having information about being penetrated.
On the other hand, if you read the CISA alert[1], it's clear that (1) many industrial targets were compromised, given the ubiquity of the Orion product and the amount of time that transpired; and (2) the attackers had their merry f'ing way with MS products like AD. So at this point I think it would be more surprising if they were not compromised than if they were.
Even if the information was discovered during a government or private investigation of the hacks that didn't include Microsoft, the investigators likely would have notified Microsoft immediately.
Don't apply to matters of national security. Seeing as solar winds supplied every branch of government and just about every company that matters in the U.S., I would imagine that there are a lot of people under gag orders, or prohibited from talking about classified Intel with people that don't have clearance. To be safe, it'd be wise to not have company officers who also hold clearances.
The statement about supposed CISA opsec guidelines is equally confusing, can you please cite the specific guidance you're referring to which would keep executives in the dark? I'm pretty familiar with the guidance CISA has issued and I don't believe any such advice has ever been given.
Before an executive would talk to the media about a subject like this, they would absolutely have gotten details from their internal security team.
> Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.
Oh, I agree that no company will ever make a categorical denial of something like this; I just don't think that justifies promoting a lesser denial into a categorical one.
I don't think the statement was meant that way, but it just shows how defensive the wording is.
Microsoft found code related to that cyber-attack “in our environment, which we isolated and removed,”
https://www.msn.com/en-us/news/technology/microsoft-says-its...
“Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.”
https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...
I believe there is common overestimation of security of cloud providers. Microsoft Azure was just breached and that's only what we know. There might be breaches at other cloud providers we're not aware of.
Centralization creates an exponentially growing incentive for bad actors. Decentralization has been given up too soon.
By the way, a piece of pedantry apropos a recent HN article: "...the Internet will devolve into regional internets." I.e. there is one Internet that connects to essentially everything; regional networks can practice internet working but aren't the proper noun "Internet"
> internet working
Wouldn't it be inter-networking/internetworking or internet networking?
In order for a country to cut itself off effectively enough, it has to be (a) huge enough to replicate any service its citizens might want that is found elsewhere and (b) authoritarian enough to crush/jail/imprison/ostracize them for circumventing it.
So far even Russia hasn't managed both. I don't think any country but China can pull it off, so we're looking at worst case a Real Internet and a ChinaNet. The only other countries that will succeed will be backwater countries dooming themselves to perpetual backwater status (I can name a few but won't).
https://www.solarwinds.com/securityadvisory#:~:text=.%20We%E....
> We’ve been advised that the nature of this attack indicates that it may have been conducted by an outside nation state, but SolarWinds has not verified the identity of the attacker.
But members of the US subcommittee on Cybersecurity have attributed it and asked for the evidence they saw to be declassified.
Having said that, it wouldn't surprise me if in coming days it is able to be positively attributed from non-classified sources. This attack seems very widespread, and while it seems extremely professionally done in the past we've seen how small errors make attribution possible.
Usually it's that an exploit developer reused some supporting infrastructure that has been previously seen and it can be attributed from that.
I have no specific knowledge, but essentially, most of the evidence is likely to be circumstantial, with chains of inferences from co-occurences of targets, tools, techniques, and other 'fingerprints', various bits of which may occasionally be confirmed or refuted by humint (which may or may not be reliable).
It is very unlikely that there is any single piece of info that definitively ties the attack to a particular actor (except maybe sigint), and with sufficient effort a false-flag operation can successfully lead to a mistaken conclusion, at least temporarily, but that's harder than it seems.
Any actor that tries to imitate the signature of a different actor by only using stuff from the other guy's bag of tricks is by definition only using tools that have been detected and are known; which means that countermeasures are likely to also be known and in use. Adding anything novel on top of that to increase the chances of the attack's success is incorporating a signal that WON'T be present in the chosen fall-guy's future efforts (unless previously undetected tools can be stolen from the fall-guy), which may (eventually) undermine the desired conclusion.
Figuring out whodunnit requires an essentially Bayesian approach, except the data is usually circumstantial, and priors - themselves always contingent on even earlier data - are of uncertain reliability and must when possible be tested against later assumed-reliable data from other channels for consistency (and when inconsistent, deciding whether new data trumps priors or vice-versa is a bitch).
Nevertheless, given how much data there typically is, it isn't too often that something comes along (like the discovery of a mole, which invalidates assumptions about what the opposition knows, and knows you know, etc.) to upend everything and break or reverse whole chains of inference.
So, while we might eventually find out some of the circumstantial evidence that lead to the attribution to a particular actor, we won't ever be told what other previous evidence (itself circumstantial) ties that evidence to that actor. Eg. "Toolchain X used in this attack is linked to Actor Y, but we can't tell you how we know they are linked. Sorry-not-sorry." ¯\_(ツ)_/¯
This all smells extremely suspicious.
There is a big asymmetry here: On the one hand this whole "cyberattack" boils down to a) the password for the build server being <companyname>123 and b) publishing said password on github. The customers, federal agencies including intelligence, failed to find this for a year, which simply is gross incompetence. I mean really: Did the agencies integrate this software into their critical systems without any checks?
Yet these agencies are at the same time so competent that they can reliably attribute usage of the password (this wasn't even a hack) to the Russian government within days?
Edit: It is of course quite possible to be Russia, but hacking is comparatively cheap, so the list of possible culprits is larger than just Russia and China. It could also be way more than just one country, as the password was public for everyone to use for almost a year.
At this point, any evidence pointing to Russia will be met with responses like "I'm still waiting for evidence that Russia is behind this," or "I need to see this quote unquote evidence myself..."
I gotta admit though, they have apparently really honed their English grammar. Can't use that technique to detect them anymore.
Show me it then.
> I gotta admit though, they have apparently really honed their English grammar.
Maybe that's because what you're insinuating is false and you refuse to believe it? Also, you've still not outwardly said what you are insinuating. You're still beating around the bush. So I'll say it for you: "anyone who asks for evidence is a Russian shill." That's what you're getting at, right?
The first story on HN about this linked to an article which said that investigators saw what looked like them to be clearly "Russian" in the techniques used, based on their own previous experience.
I will trust a reporter over a random HN commenter any day of any year.
The GOP and right wing types traditionally pulled a hard line against Russia and Russian interest. Then that softened — remember George W Bush “staring into Putin’s soul.” Conservatives picked up an infatuation of sorts with Russia early in the Obama administration. Talk radio personalities took a shine to Mr. Putin because Russia allowed transit of US troops and supplies on Russian railways to Uzbekistan, for example. Policy positions on Syria we’re strange.
It flipped to obsequiousness mysteriously in 2017. Anything critical of Russia suddenly became a tangle of whataboutisms and other nonsense. Old hawks now roost as Russia doves. Senators who are ok with child separation want pardons for Edward Snowden.
This is partly why I find the "no politics" rule on hackernews absolutely hilarious sometimes because it's such an insight into the American psyche where everything is political but also in denial that politics is anything other than a catch-all term for anything involving people, power and any end result other than sex or violence.
The stuff that attracts folks to Trumpism, UFOs or other weird things of the ilk that make little sense appeals to that philosophy. We like mysteries and inside knowledge. We don’t always have the answers, but we know the problems that nobody else understands.
It’s an easy thing for propagandists to exploit. UFOs have been used to conceal weapons programs in plain sight. (In my home area, tomahawk missile testing in the 80s was often linked to that). Now anyone with a little money can mobilize an army of bots and idiots to push any message.
He is the first president in the past 40, 50 years I think, that didn't start any conflict.
Also he been trying to pull out troops, to the point officials lied to him about troop movements to prevent him from pulling more troops (O.o I am surprised people will let that one fly...)
Biden on the other hand already appointed as secretary of defense a guy on the board of Raytheon...
https://thewire.in/world/chinese-communist-party-members-inf...
They've been doing extensive industrial espionage for decades.
It's really the other way around, there are a lot of people claiming that it was Russia without any apparent evidence:
https://twitter.com/ggreenwald/status/1339560149799854081
But there is a political subtext here. The red team is rooting for it to be China because it plays into a "Trump was right that China is a problem" narrative and coincides with the Hunter Biden thing and also the recent scandal about Congressman Swalwell (D-CA) having a relationship with a Chinese spy. The blue team correspondingly wants it to be not-China and thereby benefits from preemptively asserting that it was Russia.
This unfortunately makes it less likely that we'll ever know because it's hard enough to figure it out when there isn't a political motive for both sides to fudge the answer.
* Because people on this forum have enough expertise to make decisions themselves, given the evidence.
* Because in the past, when evidence has been presented, we've seen the federal intelligence community claim absolute certainty when they're actually only mostly-sure.
We've also seen them just fabricate things out of whole cloth, e.g. Iraq WMD.
It's generally best to read "according to sources in the intelligence community" as "according to professional liars who are aware you have no way of verifying anything they tell you."
Also keep in mind that revealing real classified intelligence to the media is a federal crime but making stuff up is totally legal.
Probable Suspected Alleged Linked Unnamed Probably Highly Likely
I think that sums it up, there are none.
From now until that day, I will simply assume nothing.
FireEye (who discovered the SolarWinds breach when investigating their own breach) have said they are currently unable to attribute it[1]:
"While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor [FireEye subsidary VP Carmakal] said"
However US Subcommittee on CyberSecurity member Senator Richard Blumenthal said about it:
"Stunning. Today’s classified briefing on Russia’s cyberattack left me deeply alarmed, in fact downright scared. Americans deserve to know what's going on. Declassify what’s known & unknown"[2]
Having done some work in this field, attribution is definitely possible and fairly reliable with enough data, but releasing that data is usually not done because it shows what data sources you have access to.
I'd be relatively confident that there is classified sources showing it is at least probable[3] that the source is Russian if subcommittee members are tweeting that.
Edit: FireEye/Mandiant has a good primer on how they do their tracking of unknown groups. Attribution is similar: https://www.fireeye.com/blog/products-and-services/2020/12/h...
> Not looking to start political flame bait here just curious what details are out there.
Just wait until you see what happens to this reply. But <shrug>.
[1] https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...
[2] https://twitter.com/SenBlumenthal/status/1338972186535727105
[3] Probable in the "words of estimative probability" sense. https://en.wikipedia.org/wiki/Words_of_estimative_probabilit... and https://www.cia.gov/library/center-for-the-study-of-intellig...
His tweet is referenced in the same article ([1] above) if that's what you mean?
I need some popcorn.
But anyway, the largest problem isn't even Windows, it's AD. Every corporate bases its entire access control in a baroque undocumented extension of a bad protocol with its security frozen at late 2000's years (upgraded by force a decade ago, because 90's security was too ugly). It's just insane.
> The SolarWinds Orion supply chain compromise is not the only initial infection vector this APT actor leveraged.
So far negligence in cybersecurity hasn't resulted in anything spectacularly failing like a giant explosion or a building collapsing and hundreds or thousands of people dying. Until something horrific like that happens there won't be pressure or political will to exert the appropriate measures that responsible governance should put in place.
There must be a lot of all nighters behind the scenes.
Uncle Sam will need to do better but Uncle Sam has lots of contractors and doesn’t pay full fare.
I worked at a healthcare company that stored its production credentials (with no login auditing) in a plain text file accessible by half the employees and contractors and when I complained that this was dumb (and violated HIPAA) was told "we passed our audits and we trust our employees".
https://www.canada.ca/en/security-intelligence-service/corpo...
I keep seeing this information repeated all over the place, but no mention of how that is actually known.
There are what, three countries capable of an attack of this magnitude? China, Russia, and Israel? I wouldn't rule out a clandestine non-governmental operation, but that is unprecedented at this scale.
I'm looking for evidence that would make me believe the attackers were indeed Russian-backed. So far we've seen no evidence, which means we have to take what the government sayhs at face value, and I'm sure I don't need to spell out why that's problematic.
Just because it's hard to find/provide evidence doesn't mean we blindly have to accept what we're told.
That being said, asking for attribution with evidence right now is absurd. No one, except the attackers, knows the full depth or breadth of the attack. To make a positive id at this moment, and explain how investigators are attributing responsibility is reckless. Asking for evidence behind attribution at this time is essentially flamebait. If you doubt the attribution it may be better to question the record of those making these accusations and what they stand to gain by making them.
Oh yeah, and the US is definitely capable. I'm not sure they would do this in their own nest, though.
FEYE was the honeypot that triggered the warning to the rest of the world.
Edit: does sound promising but hard to tell, seems like everyone is trying save face in this debacle
Thoughts on this? It seems unlikely to me that someone who compromises literally the enterprise desktop OS manufacturer isn't going to take advantage of the situation.