The latest Russian hack of gov't agencies
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
The latest Russian hack of gov't agencies
I'm sure most of you have now seen the news that a hack was discovered at the US Treasury & Commerce Dept's email accounts. The latest analysis has traced this to a very sophisticated attack on a very well known (well, well known in the corporate IT world) and widely used set of network monitoring & management tools sold by a company named SolarWinds. https://www.solarwinds.com/ These tools are used by IT departments at companies to monitor the health of the company's network, servers & storage, and to assist in managing the thousands of different pieces of technology that comprise a large corporate IT infrastructure. SolarWinds is used by A LOT of companies, and, as we now know, also used extensively in the US government networks. It is a darn good set of tools. The only reason I don't use it at my company is because we can't afford it. A couple of years ago my network manager was pleading with me to buy him these tools, and we went out and got a quote on just a small subset of the available tools - but I just couldn't fit it into our budget. I guess it is a good thing we're so cheap!
SolarWinds says it has over 300,000 customers including:
-more than 425 of the U.S. Fortune 500
-all ten of the top ten US telecommunications companies
-all five branches of the U.S. military
-all five of the top five U.S. accounting firms
-the Pentagon
-the State Department
-the National Security Agency
-the Department of Justice
-The White House
What is really scary about this hack was the method they used. What the bad guys (apparently a Russian hacker group) did was manage to infiltrate the software engineering group at SolarWinds that is responsible for their product updates. They were able to insert malicious code directly into a SolarWinds product update. So, anyone running SolarWinds products would get the malicious code as soon as they updated to the latest release. Once the update was installed, it created a backdoor into the customer's network that gave the hacker's the keys to the kingdom. The SolarWinds tools are installed EVERYWHERE on your network - the entire purpose of the tools is to let you see everywhere in your network. They had access to the very core of the network, where only the top & most trusted network & server administrators are allowed to work.
This is a developing story and they don't yet know the extent of the compromise. Did they only penetrate the US Treasury Dept email, or was it other servers there? Was it other US gov't agencies? Was it also corporations? This could be very, very big. I think the only thing we could have going for us is that some of the most important parts of the US Treasury & Commerce Depts, like the IRS & Social Security Administration, still run old mainframes that might not be as hackable as newer systems. It might be a case where being obsolete helps...
Best source I know for the real scoop: https://krebsonsecurity.com/2020/12/u-s ... ompromise/
SolarWinds says it has over 300,000 customers including:
-more than 425 of the U.S. Fortune 500
-all ten of the top ten US telecommunications companies
-all five branches of the U.S. military
-all five of the top five U.S. accounting firms
-the Pentagon
-the State Department
-the National Security Agency
-the Department of Justice
-The White House
What is really scary about this hack was the method they used. What the bad guys (apparently a Russian hacker group) did was manage to infiltrate the software engineering group at SolarWinds that is responsible for their product updates. They were able to insert malicious code directly into a SolarWinds product update. So, anyone running SolarWinds products would get the malicious code as soon as they updated to the latest release. Once the update was installed, it created a backdoor into the customer's network that gave the hacker's the keys to the kingdom. The SolarWinds tools are installed EVERYWHERE on your network - the entire purpose of the tools is to let you see everywhere in your network. They had access to the very core of the network, where only the top & most trusted network & server administrators are allowed to work.
This is a developing story and they don't yet know the extent of the compromise. Did they only penetrate the US Treasury Dept email, or was it other servers there? Was it other US gov't agencies? Was it also corporations? This could be very, very big. I think the only thing we could have going for us is that some of the most important parts of the US Treasury & Commerce Depts, like the IRS & Social Security Administration, still run old mainframes that might not be as hackable as newer systems. It might be a case where being obsolete helps...
Best source I know for the real scoop: https://krebsonsecurity.com/2020/12/u-s ... ompromise/
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- 1967redrider
- Gold Tier

- Posts: 21568
- Joined: Wed Feb 02, 2011 4:23 pm
- Location: Alexandria, VA
- Contact:
Re: The latest Russian hack of gov't agencies
If the older technology was more secure, why didn't this transfer into the new system? Our IT people, both City and State, like to constantly modify this and that, usually resulting in down time because it blows up. Case in point, it happened this morning with our State systems. Someone changed something over the weekend and it caused server issues. Do you have to be a nervous, fidget, compulsive personality in order to make it in the IT field?
Wish I knew the answer to that question. It's almost like the mantra is, if it's working we can break it! 
Pocket, fixed, machete, axe, it's all good!
You're going to look awfully silly with that knife sticking out of your @#$. -Clint Eastwood, High Plains Drifter
CHRIST IS KING
You're going to look awfully silly with that knife sticking out of your @#$. -Clint Eastwood, High Plains Drifter
CHRIST IS KING
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
It's apples & oranges - when I say "older" - what I am really saying is that they are not based on the same technology as modern computers. The hacks that are designed to work on modern computers running Microsoft Windows or a modern version of unix simply won't run on one of the older mainframes. It's not because the older mainframes are more secure - it is simply that no one writes hacks for those old beasts anymore. There are a million reasons why the new computers are better - just about anywhere you look, the newer will be better (faster processing, more storage, faster connections, lower power, cheaper to operate, etc, etc). I guarantee you that if those old mainframes were as popular today as Windows computers, they WOULD be hacked, and hacked hard!1967redrider wrote: ↑Tue Dec 15, 2020 12:50 am If the older technology was more secure, why didn't this transfer into the new system? Our IT people, both City and State, like to constantly modify this and that, usually resulting in down time because it blows up. Case in point, it happened this morning with our State systems. Someone changed something over the weekend and it caused server issues. Do you have to be a nervous, fidget, compulsive personality in order to make it in the IT field?Wish I knew the answer to that question. It's almost like the mantra is, if it's working we can break it!
![]()
As for why things need to keep changing...
There is an old saying: If you never change anything, then nothing needs to change.
If you were to take your current computer and completely disconnect it from the rest of the world, you could run it until the electronic & mechanical components finally failed due to age. You would never need to do anything to it. Of course, you would also not be able to do anything more with it than what you can do today. The problem is that there are many, many things that create change that you cannot control. New hacks are created, new hardware is produced, new users come up with new things they want to do with the hardware & software. As soon as you start wanting to respond to these outside changes, then *you* need to change.
The only thing that stays the same is the need for change...
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
The first reports I heard of this said it was Chinese hackers, probably government sponsored. Then the story quickly changed to Russians. I’m wondering if there was some new evidence linking the Russians, or if the fake news media changed it to fit their narrative.
We’ve been lied to by big media so much and so often, either by commission or omission, I don’t believe anything they say or print.
Ken
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
I get my information from the cybersecurity experts that know the people actually doing the analysis. Brian Krebs (the link I provided above) is one of the best there is. I completely ignore the rest of the media.
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Old Folder
- Posts: 2038
- Joined: Sat Jul 23, 2016 7:31 am
- Location: So. Central California.
Re: The latest Russian hack of gov't agencies
The first reports I heard of this said it was the "Chinese Rough Rider Knives" responsibility, from the flag wavers on AAPK.
Dan
Dan
It's always important to know what you don't know.
Dan
Dan
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
Well done. A classic example of fake news to fit a narrative.Old Folder wrote: ↑Tue Dec 15, 2020 2:53 am The first reports I heard of this said it was the "Chinese Rough Rider Knives" responsibility, from the flag wavers on AAPK.
Dan
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
- QTCut5
- Gold Tier

- Posts: 7771
- Joined: Thu Jul 31, 2014 1:59 am
- Location: Napo'opo'o, HI
Re: The latest Russian hack of gov't agencies
Very disturbing occurrence regardless of where it originated (and a fitting way to end 2020!)

~Q~
- Old Folder
- Posts: 2038
- Joined: Sat Jul 23, 2016 7:31 am
- Location: So. Central California.
Re: The latest Russian hack of gov't agencies
Fake News is not new.Mumbleypeg wrote: ↑Tue Dec 15, 2020 4:31 amWell done. A classic example of fake news to fit a narrative.Old Folder wrote: ↑Tue Dec 15, 2020 2:53 am The first reports I heard of this said it was the "Chinese Rough Rider Knives" responsibility, from the flag wavers on AAPK.
Dan![]()
![]()
Ken
Fake news has a long history in America. Benjamin Franklin intentionally published stories alleging that the British paid Native Americans to scalp men, women and children in the rebellious colonies. During the contentious election of 1800, Federalist newspapers tried to keep people from voting for Thomas Jefferson by running fake stories of his death.
Dan
It's always important to know what you don't know.
Dan
Dan
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
Unfortunately neither is election fraud.Old Folder wrote: ↑Tue Dec 15, 2020 6:44 amFake News is not new.Mumbleypeg wrote: ↑Tue Dec 15, 2020 4:31 amWell done. A classic example of fake news to fit a narrative.Old Folder wrote: ↑Tue Dec 15, 2020 2:53 am The first reports I heard of this said it was the "Chinese Rough Rider Knives" responsibility, from the flag wavers on AAPK.
Dan![]()
![]()
Ken
Dan
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
- Old Folder
- Posts: 2038
- Joined: Sat Jul 23, 2016 7:31 am
- Location: So. Central California.
Re: The latest Russian hack of gov't agencies
I agree Ken.
One would think that in the 21st century we would have a fail safe & honest way to vote.
Dan
One would think that in the 21st century we would have a fail safe & honest way to vote.
Dan
It's always important to know what you don't know.
Dan
Dan
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
More details emerging on the SolarWinds hack:
https://krebsonsecurity.com/2020/12/sol ... customers/
https://www.fireeye.com/blog/threat-res ... kdoor.html
There will be much more still to come over many months of analysis.
This is one of the most sophisticated hacks I have ever seen. The knowledge, skill & planning required to pull this off is Mission Impossible level stuff.
Current estimates say ~18,000 corporate & gov't customers could be affected. They don't know yet how many were actually infiltrated. One of the more interesting parts was this section of the post:
Think about that level of pre-planning: "We could go after the NSA, but if we do that, we'll probably get caught. So, let's go after these other guys because they probably won't have the means to catch us and we'll be able to operate the hack longer."
Total evil, but also genius. Can you imagine how much more advanced the human species could be if we didn't waste all this brainpower doing evil??
https://krebsonsecurity.com/2020/12/sol ... customers/
https://www.fireeye.com/blog/threat-res ... kdoor.html
There will be much more still to come over many months of analysis.
This is one of the most sophisticated hacks I have ever seen. The knowledge, skill & planning required to pull this off is Mission Impossible level stuff.
Current estimates say ~18,000 corporate & gov't customers could be affected. They don't know yet how many were actually infiltrated. One of the more interesting parts was this section of the post:
Alan Paller, director of research for the SANS Institute, a security education and training company based in Maryland, said the attackers likely chose to prioritize their targets based on some calculation of risk versus reward.
Paller said the bad guys probably sought to balance the perceived strategic value of compromising each target with the relative likelihood that exploiting them might result in the entire operation being found out and dismantled.
Think about that level of pre-planning: "We could go after the NSA, but if we do that, we'll probably get caught. So, let's go after these other guys because they probably won't have the means to catch us and we'll be able to operate the hack longer."
Total evil, but also genius. Can you imagine how much more advanced the human species could be if we didn't waste all this brainpower doing evil??
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
-
PigStikr
- Posts: 217
- Joined: Mon Feb 17, 2020 3:22 pm
- Location: Sand Lk./Hale, Mi.
Re: The latest Russian hack of gov't agencies
Well my phone & my computer wanted me to to do an update in nthe last 24 hrs....makes sense
Never Doubt Your Dawg
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
This specific hack would not affect a PC or phone unless you were running the Solarwinds Orion software. And you would only be doing that if you were a network engineer or admin.
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Just Plain Dave
- Bronze Tier

- Posts: 7724
- Joined: Sat Sep 05, 2009 3:54 am
- Location: Near East Texas (Cleveland area)
Re: The latest Russian hack of gov't agencies
I fear that if nothing is done to make me and a few million other people believe in the Election Process that we will never ever have a fair election again.
Looking for the magic penny!
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
What, exactly, would you want to see happen? What would have to happen for you to change your current opinion?Just Plain Dave wrote: ↑Thu Dec 17, 2020 1:22 am I fear that if nothing is done to make me and a few million other people believe in the Election Process that we will never ever have a fair election again.
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Beavertail
- Posts: 1202
- Joined: Sun Feb 24, 2008 9:47 pm
- Location: Way down south in Dixie
Re: The latest Russian hack of gov't agencies
Is this the same Solarwinds that some people are saying the Dominion voting machines were using?
Tim
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
Dominion has made a public statement saying that they have never used the versions of Solarwinds Orion software that was affected by this hack.Beavertail wrote: ↑Thu Dec 17, 2020 8:43 pm Is this the same Solarwinds that some people are saying the Dominion voting machines were using?
https://www.theblaze.com/news/ready-dom ... n-software
They may have used other Solarwinds software that was not part of this hack.
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
Which is all beside the point that no voting machines should ever have been connected to the internet. But they were.
Ken
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
- Just Plain Dave
- Bronze Tier

- Posts: 7724
- Joined: Sat Sep 05, 2009 3:54 am
- Location: Near East Texas (Cleveland area)
Re: The latest Russian hack of gov't agencies
I say throw out the current Election and do it over with PICTURE ID ONLY!
Or see Pelosi Schumer and Harris all thrown in Jail.
Or see Pelosi Schumer and Harris all thrown in Jail.
Looking for the magic penny!
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
You forgot the Biden’s - the whole family.Just Plain Dave wrote: ↑Thu Dec 17, 2020 10:36 pm I say throw out the current Election and do it over with PICTURE ID ONLY!
Or see Pelosi Schumer and Harris all thrown in Jail.
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
-
jmh58
- Posts: 14252
- Joined: Wed Apr 02, 2008 11:22 pm
- Location: Pgh,Pa
Re: The latest Russian hack of gov't agencies
Mumbleypeg wrote: ↑Thu Dec 17, 2020 11:06 pmYou forgot the Biden’s - the whole family.Just Plain Dave wrote: ↑Thu Dec 17, 2020 10:36 pm I say throw out the current Election and do it over with PICTURE ID ONLY!
Or see Pelosi Schumer and Harris all thrown in Jail.
Ken
John
Not all who wander are lost!!
Of all the paths you take in life,
Make sure some of them are Dirt!!!
Of all the paths you take in life,
Make sure some of them are Dirt!!!
- TwoFlowersLuggage
- Posts: 3113
- Joined: Sun Nov 26, 2017 8:18 pm
- Location: Stuck in traffic on a highway in Southern California
Re: The latest Russian hack of gov't agencies
I can't wait for all the outrage from all the sovereign citizens over the requirement to have a government issued picture ID in order to vote. "The gov't is trying to track me!", "I won't carry a gov't issued card that has embedded electronics!" and "The gov't issued card emits microwaves to make people they don't like sterile and give them cancer!"
"The Luggage had a straightforward way of dealing with things between it and its intended destination: it ignored them." -Terry Pratchett
- Mumbleypeg
- Gold Tier

- Posts: 15733
- Joined: Fri Apr 18, 2014 1:28 am
- Location: Republic of Texas
Re: The latest Russian hack of gov't agencies
You should get out of Commiefornia more and visit places like the existing 34 free states which already require government photo I.D. to vote.TwoFlowersLuggage wrote: ↑Fri Dec 18, 2020 2:59 am I can't wait for all the outrage from all the sovereign citizens over the requirement to have a government issued picture ID in order to vote. "The gov't is trying to track me!", "I won't carry a gov't issued card that has embedded electronics!" and "The gov't issued card emits microwaves to make people they don't like sterile and give them cancer!"
Ken
Member AKTI, TSRA, NRA.
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
If your religion requires that you hate someone, you need a new religion.
When the people fear their government, that is tyranny. When government fears the people, that is freedom.
https://www.akti.org/
- edge213
- Gold Tier

- Posts: 8502
- Joined: Sat Jan 25, 2014 12:48 am
- Location: The Crossroads of America
Re: The latest Russian hack of gov't agencies
Mumbleypeg wrote: ↑Fri Dec 18, 2020 4:05 amYou should get out of Commiefornia more and visit places like the existing 34 free states which already require government photo I.D. to vote.TwoFlowersLuggage wrote: ↑Fri Dec 18, 2020 2:59 am I can't wait for all the outrage from all the sovereign citizens over the requirement to have a government issued picture ID in order to vote. "The gov't is trying to track me!", "I won't carry a gov't issued card that has embedded electronics!" and "The gov't issued card emits microwaves to make people they don't like sterile and give them cancer!"![]()
Ken
David
"Glowing like the metal on the edge of a knife" Meat Loaf
"Glowing like the metal on the edge of a knife" Meat Loaf