US under a major cyberattack

Discuss anything not covered in another forum (life, the universe etc.)... Please keep it PG-13 and avoid spam.
Post Reply
User avatar
Philip
SG VIP
Posts: 11731
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

US under a major cyberattack

Post by Philip »

What do you think about the cyberattack that is affecting the US government right now? This seems like a huge breach, according to CISA parts of this attack have been ongoing since March, and it "poses a grave risk" to federal government agencies, critical infrastructure, as well as local governments and private organizations.

https://www.speedguide.net/news/us-unde ... ssian-7409
Disclaimer: Please use caution when opening messages, my grasp on reality may have shaken loose during transmission (going on rusty memory circuits), even though my tin foil hat is regularly audited for potential supply chain tampering. I also eat whatever crayons are put in front of me.
๑۩۞۩๑
User avatar
Easto
SG Elite
Posts: 5881
Joined: Sat Dec 02, 2000 12:00 am
Location: So. California

Post by Easto »

To me it sounds like it's probably even worse than they're letting on. I was really surprised when they said it had been going on this long. Pretty scary stuff. They obviously got more than just names and phone numbers. I'm not even sure the government will let us know how bad it may have been.
User avatar
Philip
SG VIP
Posts: 11731
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

It likely also involves many corporations.
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

Looking at my logs and firewall logs (don't go sideways with me on the number of logs I have) it would appear they hacked into my .GIF folder. Good for them. There are so many bug and virus in there that they will be forever cleaning their computer(s) for the next 5+ years.

Poor slobs......
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
User avatar
Philip
SG VIP
Posts: 11731
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

It is a rather large target area. SolarWinds has over 30,000 clients, and many of them automatically installed updates containing a malicious code that was introduced without anyone's knowledge. Maybe it should've been caught early on, rather than going on for months though.
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

When this happened (back last year)...I said "2021 is going to be a VERY bad year for breaches.

....just released a week ago, some agency noted that 47 major defense related companies were breached so far this year from mis-use of fire eye tools.
Doesn't matter what you have for firewalls or other security best practices, FireEye tools cut through the like a hot knife through butter.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
David
SG Elite
Posts: 9393
Joined: Sun Feb 20, 2000 12:00 pm
Location: Nova Caesarea

Post by David »

Yikes!!

Hell_Yes

Luck is where preparation meets opportunity - Seneca

"Anti-intellectualism has been a constant thread winding its way through our political and cultural life, nurtured by the false notion that democracy means that 'my ignorance is just as good as your knowledge.'" - Isaac Asimov

It is my ambition to say in ten sentences what others say in a whole book. - Friedrich Nietzsche
User avatar
Norm
SG VIP
Posts: 14195
Joined: Tue Mar 27, 2001 12:00 pm

Post by Norm »

Two words come to mind.
Complacency and ridiculous

So easy to defend against, yet so many don't follow simple rules no matter what. Playing Russian Roulette with potentially devastating consequences

How hard would it be to have a service running looking for any encryption about to take place, and stop it while sending a message to confirm before continue. (I know, that's a simplistic way of putting it)
Many other solutions to the problem I'm sure.

Looks good on those who pretend to be "security "EXPERTS""

Maybe it's impossible to count on the average office Joe, but come on, IT specialists should have made this impossible long ago,
User avatar
David
SG Elite
Posts: 9393
Joined: Sun Feb 20, 2000 12:00 pm
Location: Nova Caesarea

Post by David »

The word is diligence. The complacency comes from automation, it is assumed that the computer is remedying the situation itself. The caretakers are asleep at the switch.

I agree heartily that it would seem easy to mitigate, however the black hats are a clever lot in hiding their intrusions and managing to avoid the "three tries and your locked out" scenario,

Hell_Yes

Luck is where preparation meets opportunity - Seneca

"Anti-intellectualism has been a constant thread winding its way through our political and cultural life, nurtured by the false notion that democracy means that 'my ignorance is just as good as your knowledge.'" - Isaac Asimov

It is my ambition to say in ten sentences what others say in a whole book. - Friedrich Nietzsche
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

Norm wrote:Two words come to mind.
Complacency and ridiculous. IT specialists should have made this impossible long ago,
The man speaks the truth. I worked in IT with the Federal government for 30+ years. Miss-management of funds and political priorities screwed the pooch back when I was at a keyboard. Today the same thing is happening without anything learned from the past. Ack.
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
g0qu2021
New Member
Posts: 5
Joined: Thu Jul 22, 2021 2:52 pm

Post by g0qu2021 »

MadDoctor wrote:The man speaks the truth. I worked in IT with the Federal government for 30+ years. Miss-management of funds and political priorities screwed the pooch back when I was at a keyboard. Today the same thing is happening without anything learned from the past. Ack.
True but you have to realise that it's all hype and crap, the bug in Microsoft's exchange was fixed in most UNIX boxes week's before they even noticed an issue in Windows, so it's very much the case that they where probably notified of the vulnerability and then sat on it and did sweet FA whilst every bad apple and vandal and miscreant downloaded it to go to town and have a rave up on everyone else's property.

As for Mismanaged funds and screwing the pooch has anyone ever explained to them who's property they're all using whilst they're slagging off the Russians and the Chinese?

TCP/IP - The Communist Parties / Intellectual Property - UNIX is of course UNIQ and no, not just made in the USA.

But this is whilst they sanction 1.4 Billion Social party members who live largely off there own production and community spirit and tell them they cant have Semi-Conductors and then they wonder why the Chinese are calling them a bully and threatening to take away all semi-conductor production full stop.
g0qu2021
New Member
Posts: 5
Joined: Thu Jul 22, 2021 2:52 pm

Post by g0qu2021 »

First they went off and got Racist in the Middle East...
Then they went off and got Racist with a load of Russians..
Now they want to be Racist to a load of the Chinese.

I agree with China's assessment "Unsophisticated & largely uneducated patronising Barbarians!"
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

g0qu2021 wrote:True… but you have to realise that it's all hype and crap.
The word ”True” from my post is correct. After that… your anger blurred everything else you posted. Would you (please) back off the stick up your butt and make me want to understand. Your anger blurs my attention.
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
g0qu2021
New Member
Posts: 5
Joined: Thu Jul 22, 2021 2:52 pm

Post by g0qu2021 »

MadDoctor wrote:The word ”True” from my post is correct. After that… your anger blurred everything else you posted. Would you (please) back off the stick up your butt and make me want to understand. Your anger blurs my attention.
Then allow me to specify something that will not be said in anger, but will be easy for you to digest..

This is "De Oppresso Libre" the US Military - and this is there Level 1 NSA approved digital signage player.

https://en.wikipedia.org/wiki/HAIPE
https://info.publicintelligence.net/NSA-HAIPE.pdf

This device retails for £6'950 to £7'000 and upwards for any prospective buyer to deploy on there network - it's sold exclusively by the Military!

Included in it's unique algorithms is the FireFly Protocol (EFF) PSO and Swarming Technology...

:lol:

Now let me introduce you to the "Retail" version of the exact same product... Which sell's commercial **RETAIL** for the huge sum of £38.91 and is built on the exact same design!

https://buy.advantech.eu/Compact-Comput ... 22010.htm?

An just so you know.. It's made in China - the RK3399 (FIREFLY) algorithm was made by a Chinese developer announced by ARM at Mobile World Congress in February 2016, and it features six 64 bit CPUs...

Rockchip (Fuzhou Rockchip Electronics Co., Ltd) It has offices in Shanghai, Beijing, Shenzhen, Hangzhou and Hong Kong.
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

g0qu2021 wrote:Then allow me to specify something that will not be said in anger
Thank you. The words you typed are logical. Not said in anger. Welcome to Speedguide. :)
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
Post Reply