REAL WORLD EVENT DISCUSSIONS

There's the IOT ... and then there's the internet, as vulnerable as ever

POSTED BY: 1KIKI
UPDATED: Saturday, January 2, 2021 19:48
SHORT URL:
VIEWED: 852
PAGE 1 of 1

Friday, December 18, 2020 3:26 PM

1KIKI

Goodbye, kind world (George Monbiot) - In common with all those generations which have contemplated catastrophe, we appear to be incapable of understanding what confronts us.



This is just a limited sampler, and I hope to return to the topic later with more information.



Why the US government hack is literally keeping security experts awake at night
https://edition.cnn.com/2020/12/16/tech/solarwinds-orion-hack-explaine
d/index.html


Microsoft identifies more than 40 organizations targeted in massive cyber breach
https://edition.cnn.com/2020/12/17/politics/microsoft-hack-organizatio
ns/index.html



https://edition.cnn.com/2020/12/17/politics/us-government-hack-extends
-beyond-solarwinds/index.html


https://edition.cnn.com/2020/12/17/politics/trump-silence-cyber-hack/i
ndex.html

NOTIFY: Y   |  REPLY  |  REPLY WITH QUOTE  |  TOP  |  HOME  

Friday, December 18, 2020 6:14 PM

SIGNYM

I believe in solving problems, not sharing them.


ALSO, ABOUT THE HACK FROM A DIFFERENT PERSPECTIVE


Quote:

CONFIRMED: Dominion Uses SolarWinds Software, Denies Using Software Included In Devastating Hack

Sources confirm that Dominion Voting Systems uses the SolarWinds Serv-U product.

Multiple sources have confirmed Dominion Voting Systems utilizes products from SolarWinds, a recently hacked software company that provides IT service management to businesses, the executive branch, intelligence services, and the US military. Dominion denies using SolarWinds products included in the hack.

SolarWinds was hacked in March

MARCH.
Quote:

by who the ODNI, FBI, and CISA refer to as “malicious actors.” The breach of the SolarWinds’ Orion platform was announced this month
DECEMBER. NINE MONTHS LATER
Quote:

, just six days before SolarWinds investors sold hundreds of millions of dollars in stock.

The Daily Dot claims that a Dominion Voting Systems spokesperson said “Dominion Voting Systems does not now — nor has it ever — used the SolarWinds Orion Platform, which was subject of the DHS emergency directive dated December 12, 2020.”

DISCOVERED IN MARCH. EMERGENCY DIRECTIVE IN MID-DECEMBER. WHAT AM I MISSING HERE?


Quote:

However, multiple sources have pointed out that Dominion does, in fact, use some SolarWinds’ software.

So, I’ve seen folks pointing out that Dominion Voting Systems uses #SolarWinds.

DVS definitely uses the SolarWinds Serv-U product; however, according to @AlexaCorse, they do not use the Orion product line. (1/n)

— Jon Gorenflo ? ??????? (@flakpaket) December 15, 2020

DVS recently deleted references and links to SolarWinds off their website, as was pointed out by Ron Watkins, a former administrator for the message board website 8chan.

Dominion Voting Systems uses SolarWinds products and it is still not powered down.

Was Dominion Voting Systems a target?
Was Dominion Voting Systems hacked? https://t.co/YJVHPilN1Rhttps://t.co/JDWWFVfofr https://t.co/MSgJ7yxoFY pic.twitter.com/hbaLZSYSPF

— Ron (@CodeMonkeyZ) December 14, 2020

Amid the concerns regarding the SolarWinds hacking incident, the ODNI, FBI, and CISA issued a joint statement regarding a “cyber security campaign against America,” as National File reported.

“As the joint statement reads, the agencies issued an Emergency Directive which instructed federal civilian agencies “to immediately

NINE MONTHS LATER ...
Quote:

disconnect or power down affected SolarWinds Orion products from their network” due to exploitation from “malicious actors.”

SolarWinds Orion products (affected versions are 2019.4 through 2020.2.1 HF1) are currently being exploited by malicious actors. This tactic permits an attacker to gain access to network traffic management systems. Disconnecting affected devices, as described below in Required Action 2, is the only known mitigation measure currently available.

CISA has determined that this exploitation of SolarWinds products poses an unacceptable risk to Federal Civilian Executive Branch agencies and requires emergency action.

Dominion Voting Systems uses SolarWinds products, but has recently removed a reference link to SolarWinds from their official website. Dominion has been criticized recently for their potential role involving mass voter fraud in the 2020 US election.”

This story is still developing and National File will continue to cover the SolarWinds hacking incident and its potential implications.



https://nationalfile.com/confirmed-dominion-uses-solarwinds-software-d
enies-using-software-included-in-devastating-hack
/


-----------
Pity would be no more,
If we did not MAKE men poor - William Blake

#WEARAMASK

NOTIFY: Y   |  REPLY  |  REPLY WITH QUOTE  |  TOP  |  HOME  

Friday, December 18, 2020 8:41 PM

1KIKI

Goodbye, kind world (George Monbiot) - In common with all those generations which have contemplated catastrophe, we appear to be incapable of understanding what confronts us.



I'll go there.

The votes are counted and certified, so Solar winds and Hunter Biden are OK to talk about publicly now.

NOTIFY: N   |  REPLY  |  REPLY WITH QUOTE  |  TOP  |  HOME  

Saturday, January 2, 2021 7:48 PM

1KIKI

Goodbye, kind world (George Monbiot) - In common with all those generations which have contemplated catastrophe, we appear to be incapable of understanding what confronts us.



Back to the hack

What happened was that breaches occurred in software suppliers, and the codes they sent out as updates had malware embedded in them. (That's the meaning behind it being called a "supply chain" hack - the suppliers of code were hacked and their product code was corrupted.)


This is from the NYTimes, so a LOT of intentional misdirection lying is included! (Here's one example, after REPEATEDLY calling it a Russian hack, buried way down in the text is the truth: "(which) intelligence agencies BELIEVE TO BE an operation by Russia’s S.V.R. intelligence service" - of course with no evidence provided. They say they "believe" so we're supposed to "believe", too.
Here's another misdirection lie: "General Nakasone and other American officials responsible for cybersecurity are now consumed by what they missed for at least nine months", when, in fact, they (merely claim they) didn't pursue what was evident 9 months earlier).

With all the usual caveats regarding the NYTimes in place, this is a NYTimes quotable quote:
Quote:

At a minimum it has set off alarms about the vulnerability of government and private sector networks in the United States to attack and raised questions about how and why the nation’s cyberdefenses failed so spectacularly.

Those questions have taken on particular urgency given that the breach was not detected by any of the government agencies that share responsibility for cyberdefense — the military’s Cyber Command and the National Security Agency, both of which are run by General Nakasone, and the Department of Homeland Security — but by a private cybersecurity company, FireEye.


How COULD they fail so spectacularly?

There are common elements and from all that I've read, it's SolarWinds Orion platform, and Microsoft.
Quote:

SolarWinds is believed to be one of several supply chain vendors Russia used in the hacking. Microsoft ... initially said that it had not been breached, only to discover this week that it had been — and that resellers of its software had been, too.
SolarWinds was warned about its poor security years ago.
Quote:

SolarWinds Adviser Warned of Lax Security Years Before Hack
https://www.bloomberg.com/news/articles/2020-12-21/solarwinds-adviser-
warned-of-lax-security-years-before-hack

And even the NYTimes agrees,
Quote:

SolarWinds, the company that the hackers used as a conduit for their attacks, had a history of lackluster security for its products, making it an easy target ... Employees say that under Mr. Thompson, an accountant by training and a former chief financial officer, every part of the business was examined for cost savings and common security practices were eschewed because of their expense.

Ian Thornton-Trump, a former cybersecurity adviser at SolarWinds, said he warned management that year that unless it took a more proactive approach to its internal security, a cybersecurity episode would be “catastrophic.” After his basic recommendations were ignored, Mr. Thornton-Trump left the company.

Microsoft was also deeply hacked.
Quote:

... the company, which said Thursday that the hackers viewed its source code, has not disclosed which of its products were affected or for how long hackers were inside its network.
And there was even a dry-run WAY back in 2019.
Quote:

Hackers last year conducted a 'dry run' of SolarWinds breach https://news.yahoo.com/hackers-last-year-conducted-a-dry-run-of-solar-
winds-breach-215232815.html

The NYTimes article also blames the election.
Quote:

The government’s emphasis on election defense, while critical in 2020, may have diverted resources and attention from long-brewing problems like protecting the “supply chain” of software.
Hm.

The US cybersecurity resources wouldn't have to have been diverted to the election if we had - how does that go again?
paper ballots
hand counted
in public



Now, maybe the focus is on SolarWinds for a reason. Or maybe it's being made a scapegoat for Microsoft's OS.

NOTIFY: N   |  REPLY  |  REPLY WITH QUOTE  |  TOP  |  HOME  

YOUR OPTIONS

NEW POSTS TODAY

USERPOST DATE

OTHER TOPICS

DISCUSSIONS
Elections; 2024
Fri, November 1, 2024 10:30 - 4426 posts
Kamala Harris for President
Fri, November 1, 2024 10:20 - 602 posts
The Sorrows Of Empire by Chalmers Johnson
Fri, November 1, 2024 07:41 - 80 posts
Is isolationism bad?? What happens if or when the USA Withdraws from the World?
Fri, November 1, 2024 07:38 - 36 posts
Russia Invades Ukraine. Again
Fri, November 1, 2024 07:28 - 7409 posts
Hollywood expensive movies & Tv shows keep crashing, Sportsball and LeBron...what will be the next box office Flop?
Fri, November 1, 2024 07:17 - 79 posts
How truth is manufactured in the West
Fri, November 1, 2024 06:51 - 112 posts
The Saudi-al Qaida puppet-masters (not PN)
Fri, November 1, 2024 06:43 - 20 posts
Turkish F-16 shoots down Russian aircraft
Fri, November 1, 2024 06:35 - 62 posts
State of the Nation - Hungary
Fri, November 1, 2024 06:32 - 5 posts
The economy is so bad even Joe Biden*'s job got outsourced to an Indian
Fri, November 1, 2024 06:27 - 11 posts
PREDICTIONS THREAD (v.2)
Fri, November 1, 2024 06:05 - 128 posts

FFF.NET SOCIAL