# Russians hack many US government systems

**URL:** <https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 14, 2020, 1:46pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023 "2020-12-14T13:46:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 14, 2020, 1:46pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/1 "2020-12-14T13:46:37Z")

</div>

Solar Winds has an office nearby and this is probably really bad news for them to get more contracts with feds.

> **[CISA Issues Emergency Directive to Mitigate the Compromise of Solarwinds...](https://www.cisa.gov/news/2020/12/13/cisa-issues-emergency-directive-mitigate-compromise-solarwinds-orion-network)**
>
> The Cybersecurity and Infrastructure Security Agency (CISA) tonight issued Emergency Directive 21-01, in response to a known compromise of SolarWinds Orion products that are currently being exploited by malicious actors. This Emergency Directive...

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 14, 2020, 5:21pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/2 "2020-12-14T17:21:18Z")

</div>

This is a major, major story. For why, these simple graphics will explain:

[![Google Photos](https://lh3.googleusercontent.com/Xfawv1HLFcSFEca16BPJ0WP3n0FD5Vd-yF8oPigB4bUzm9jni0TUASxgVlofRor1j6jTDn_seUpBXBEp2q3I0EYuXsJdWfO-7vQdJ9nqWwGvRwtZRpHsLR1Ngy-V1vJ7ZV9cD2LKFA=w600-h315-p-k "New item by John Thornton") ](https://photos.app.goo.gl/nVr4rEsxsawxnquS9)

[![Google Photos](https://lh3.googleusercontent.com/tPbL8NxTMwk05wz1ePuj3og3qzJ-DLK2iK0T1oOYILmuEfk697ikW_dlW2rHw8ZOfwxYX2UtXqUknlSwfYUGU0MbaL_0qiIIxJAFGJlOMjCJmf9jGdFZ6pEmv3qOYiqUke5mGRQcmw=w600-h315-p-k "New item by John Thornton") ](https://photos.app.goo.gl/zLLqoLYQYChwwkQS8)

The above are images from their website, a page which apparently has been taken down:

[https://www.solarwinds.com/company/customers](https://www.solarwinds.com/company/customers)

This hack has been ongoing since MARCH.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 14, 2020, 6:58pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/3 "2020-12-14T18:58:50Z")

</div>

did not know about them until I drove past their building. I assumed they were solar energy until I looked them up.

---

<div class="post-metadata">

**Author:** ![bump](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bump](https://boards.straightdope.com/u/bump)\
**Post date:** [December 14, 2020, 7:11pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/4 "2020-12-14T19:11:28Z")

</div>

They do network monitoring- what servers are up, is the network slow, etc… so their software is pretty much ideally positioned to see a lot about a network.

I’d guess they’re done in the public sector- no city/state/county or any other agency with critical infrastructure is going to buy this after today.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 14, 2020, 8:18pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/5 "2020-12-14T20:18:35Z")

</div>

Why would non government people want to use them as well? there are freeware software packages that can do network monitoring on linux. And I assume other commercial packages.

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [December 14, 2020, 8:41pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/6 "2020-12-14T20:41:17Z")

</div>

> [@Bijou\_Drains](#):
>
> Why would non government people want to use them as well? there are freeware software packages that can do network monitoring

For most people, Solar Winds _is_ a freeware software package. Paid stuff slots into their free platform, but there is also a lot of free stuff, and stuff that is free with restrictions.

There are other freeware network monitoring _platforms_, but … they don’t compete with SolarWinds. As a guide, have you ever tried using metasploit? You need _training_ to use the metasploit platform. Or at least a couple of free weeks. (I use that only as an example)

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 15, 2020, 1:39pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/7 "2020-12-15T13:39:53Z")

</div>

freeware hobbit on Linux does some of that monitoring. They changed the name after the hobbit movie came out but I forget the new name.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 15, 2020, 6:28pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/8 "2020-12-15T18:28:56Z")

</div>

only 18,000 places impacted!! Nothing to see.

> **[SEC filings: SolarWinds says 18,000 customers were impacted by recent hack](https://www.zdnet.com/article/sec-filings-solarwinds-says-18000-customers-are-impacted-by-recent-hack/)**
>
> In SEC documents filed today, SolarWinds said it notified 33,000 customers of its recent hack, but that only 18,000 used a trojanized version of its Orion platform.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 15, 2020, 6:43pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/9 "2020-12-15T18:43:13Z")

</div>

‘Only’ is doing some heavy lifting there, tbh.

---

<div class="post-metadata">

**Author:** ![Aspenglow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aspenglow/32/76_2.png) [@Aspenglow](https://boards.straightdope.com/u/Aspenglow)\
**Post date:** [December 15, 2020, 6:59pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/10 "2020-12-15T18:59:37Z")

</div>

This is one of those occurrences that is so huge, it’s hard to get one’s arms around its vast nature. (I’m struggling to see it in MPSIMS.) Simultaneously, it is the most predictable thing in the world, given Russia’s assistance to Trump and vice versa over the past 5-6 years.

Russia did extremely well out of their subversion of our 2016 election and for very little cost. As a nation, we will be paying for Trump’s and his enablers’ traitorous choices for decades.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 15, 2020, 7:13pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/11 "2020-12-15T19:13:05Z")

</div>

probably a lot more Russian hacks we don’t know about yet. Or may never know about .

---

<div class="post-metadata">

**Author:** ![AmberLee](https://avatars.discourse-cdn.com/v4/letter/a/2bfe46/32.png) [@AmberLee](https://boards.straightdope.com/u/AmberLee)\
**Post date:** [December 16, 2020, 12:49am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/12 "2020-12-16T00:49:33Z")

</div>

I’m surprised there are only 11 replies so far, as I am with the limited amount of press coverage on this topic. Given the nature of the software and customers potentially affected (large national banks, utilities, telecom) I fear this may be even worse news than Covid. I REALLY hope I’m wrong, and anxiously awaiting the analysis of what was compromised. As a 20-year SDMD lurker, I was hoping for a more active discussion on this topic. I saw Microsoft has taken control of one of the domains and is in the process of assessing at least which organizations or individual accounts are compromised. I guess it’s just wait and see.

---

<div class="post-metadata">

**Author:** ![tofor](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tofor/32/13727_2.png) [@tofor](https://boards.straightdope.com/u/tofor)\
**Post date:** [December 16, 2020, 11:55am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/13 "2020-12-16T11:55:06Z")

</div>

My company uses SolarWinds products, but not within my division, so I don’t have any special insight. It has not been mentioned in any internal communications that I’ve seen, but my most local IT folks were aware of the problem before I was.

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [December 16, 2020, 4:37pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/14 "2020-12-16T16:37:20Z")

</div>

> [@AmberLee](#):
>
> I’m surprised there are only 11 replies so far, as I am with the limited amount of press coverage on this topic.

Political outrage burnout is partially to blame. It has been four straight years of “waiting for the next shoe to drop”, and with Biden’s Presidency in sight all we want is blessed boredom.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 16, 2020, 5:58pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/15 "2020-12-16T17:58:27Z")

</div>

I would think it’s big news for IT folks and also for DOD,CIA,NSA, etc folks.

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [December 16, 2020, 6:05pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/16 "2020-12-16T18:05:43Z")

</div>

I’ve always assumed that this is business as usual for most governments. I assume that the US also has similar hacks into the computer infrastructure of other countries. I’m not happy the Russians did this, but I wouldn’t be at all surprised to find out the US government is guilty of essentially the same behavior.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 17, 2020, 2:01pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/17 "2020-12-17T14:01:56Z")

</div>

the password was solarwinds123 by default

---

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [December 17, 2020, 2:14pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/18 "2020-12-17T14:14:00Z")

</div>

> [@Czarcasm](#):
>
> Political outrage burnout is partially to blame

Also, nobody really knows what damage has been done, so it’s hard for the average citizen to get outraged. Or worried.  
Now, if somebody official announces something specific, say,that the Social Security system was hacked and you won’t be getting your money next week—that would get a lot of headlines.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 17, 2020, 6:23pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/19 "2020-12-17T18:23:58Z")

</div>

a lot of gov systems are still running on ancient IBM mainframes running Cobol. I don’t know if that makes them easier or harder to crack. also plenty of big corporations are still running ancient Cobol systems too. Fidelity is one example and I’m sure there are many more. Some places dumped old stuff for Y2K but many just patched it.

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [December 17, 2020, 8:50pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/20 "2020-12-17T20:50:18Z")

</div>

> [@Bijou\_Drains](#):
>
> the password was solarwinds123 by default

_A_ password was solarwinds123 in a code dump. This is being pointed to, not necessarily as the direct cause of the problem, but as indicative of a level of security which lead to the problem.

[Next page](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023.md?page=2)
