# Russians hack many US government systems

**URL:** <https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 14, 2020, 1:46pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023 "2020-12-14T13:46:37Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [December 17, 2020, 8:53pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/21 "2020-12-17T20:53:06Z")

</div>

> [@chappachula](#):
>
> Now, if somebody official announces something specific,

Or someone specific. This may be as bad as Snowden, but there is no Snowden to point at and hate.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [December 17, 2020, 8:53pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/22 "2020-12-17T20:53:43Z")

</div>

a lot of cheap places don’t upgrade unless they are forced to. Which leads to a lot of 70s tech still running all over the US. Way back I used VAX systems and they had default passwords for new systems that some places did not change.

I assume heads will roll at solarwinds probably including the CEO

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [December 17, 2020, 9:04pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/23 "2020-12-17T21:04:51Z")

</div>

> [@Bijou\_Drains](#):
>
> a lot of cheap places don’t upgrade unless they are forced to.

Hell, it was just a few years ago that Congress let us upgrade from Windows NT!

> [@Bijou\_Drains](#):
>
> Which leads to a lot of 70s tech still running all over the US

In the “ghosts of Christmas parties” thread, I mentioned the worldwide membership organization I used to work for. At the time, they had a Seventies mainframe which was accessed via dumb terminals encased in wood.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 17, 2020, 9:22pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/24 "2020-12-17T21:22:02Z")

</div>

How about…

> **[Nuclear weapons agency breached amid massive cyber onslaught](https://www.politico.com/amp/news/2020/12/17/nuclear-agency-hacked-officials-inform-congress-447855)**
>
> Hackers accessed systems at the National Nuclear Security Administration, which maintains the U.S. nuclear weapons stockpile.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 17, 2020, 9:23pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/25 "2020-12-17T21:23:32Z")

</div>

Also…

> **[Hack against US is 'grave' threat, cybersecurity agency says](https://apnews.com/article/technology-malware-hacking-russia-software-b3f993fb7bc9390302f0df26ecb6c10e)**
>
> WASHINGTON (AP) — Federal authorities expressed increased alarm Thursday about a long-undetected intrusion into U...

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 17, 2020, 10:01pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/26 "2020-12-17T22:01:06Z")

</div>

This isn’t going to be much comfort, but the fact that 18,000+ organizations got penetrated doesn’t really increase your exposure. That’s way too many targets to exploit. I would guess that 90% of those never got touched (either at all, or after initial reconnaissance).

Whether you are immediately affected or not depends on your proximity to the actor’s intent. If this was a nation-state adversary, they’re not interested in your bank account (with the possible exception of North Korea). There’s too much actual high-quality espionage target material in the attack space to piddle around with most citizens’ mundane cyber footprint.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 18, 2020, 12:19am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/27 "2020-12-18T00:19:58Z")

</div>

With the pandemic, the hacking, and Trump’s last days upon us, I do not think America has been this vulnerable since 1777.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 18, 2020, 6:07pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/28 "2020-12-18T18:07:43Z")

</div>

How it started:

[![Google Photos](https://lh3.googleusercontent.com/IBYLdbxqtmVypHr1zk91kZHjWhmjBtaoM45i7jgGEwqOBD6T6Am9EHKCAuSaqJlJF5pK_kPhGPqH5BO1tfw7Bhlw2WbAycjT8ZrUwV-x0EpRHYRdoJN-rfcKaV_hOuonU39F8bOXGw=w600-h315-p-k "New item by John Thornton") ](https://photos.app.goo.gl/fcfK68NY9DzW62378)

How it’s going:

[![Google Photos](https://lh3.googleusercontent.com/HejrXNA0z_ycut0K-eICFJmRM0AhGe7dOWcs-RXaWnRcZ1iqa27eqR-q8Ap2x1eaGiYklOCOGOcPodTbF0zhB4HsB82LtpuHbyMrbHYM9mKnYmAKZ8ZoWdqAjm-9b34p0wZR6p_PYw=w600-h315-p-k "New item by John Thornton") ](https://photos.app.goo.gl/gCK64JniD9yMeH7c9)

---

<div class="post-metadata">

**Author:** ![wguy123](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wguy123/32/3161_2.png) [@wguy123](https://boards.straightdope.com/u/wguy123)\
**Post date:** [December 18, 2020, 6:23pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/29 "2020-12-18T18:23:24Z")

</div>

That tweet didn’t age well. Not that any of his do age well.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [December 18, 2020, 6:46pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/30 "2020-12-18T18:46:32Z")

</div>

I’m saving my outrage for until we find out what the hack actually did. This could just mean that Russia has access to the same sort of network traffic information that Solarwind was providing to their customers, and Russia knowing how many bytes of data are transferred between, say, the Pentagon and various overseas bases isn’t really something to worry about. It could mean that Russia has access to what all of those bytes were… which still isn’t something to worry much about, so long as good encryption was used (though somewhat worrisome, because I’m less than completely confident that the DoD is using good encryption). It could mean that they’ve got plaintext of all of those communications, which is somewhat worrisome. And it could mean that they have trojans inserted into all of the navigation and fire control systems of every US vehicle and weapons emplacement, capable of complete takeover of those systems. Or a bunch of other possible threats in between.

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 18, 2020, 7:02pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/31 "2020-12-18T19:02:51Z")

</div>

There definitely seems to have been a _lot_ of ‘If I did what Hillary did with her emails, I would have been fired/imprisoned/busted in rank’ people who would give long-winded explanations of why her emails were so bad who now are mysteriously absent regarding this hack.

I would appreciate their descriptions of how they would get fired if they allowed this to happen, complete with long-winded technical and legal reasons. Might prove entertaining, even helpful and informative!

---

<div class="post-metadata">

**Author:** ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)\
**Post date:** [December 19, 2020, 10:36pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/32 "2020-12-19T22:36:27Z")

</div>

> [@AmberLee](#):
>
> I’m surprised there are only 11 replies so far, as I am with the limited amount of press coverage on this topic.

The OPM was hacked by the Chinese for more than a year in 2014-15, resulting in the release of background check / security clearance information (i.e., blackmail material) for four million federal employees, and personal information for another maybe 15 million Americans listed as contacts. It barely registered a blip here or in the public at large. China arrested a few people but faced no sanctions.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 6:51am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/33 "2020-12-20T06:51:04Z")

</div>

> [@Chronos](#):
>
> I’m saving my outrage for until we find out what the hack actually did.

Indeed, the details on what “Sunburst” was capable of are scarce on the ground. However, given that they were able to compromise the update server, and that the payload was described as a backdoor, and it’s been documented as stealing signing certificates; I’m assuming that it could download and install/run arbitrary code. With the large number of remote exploits for Active Directory servers in the last year, I’m not hopeful for it being easily contained. I’m a Unix guy, but the potential for this particular toehold into Windows systems within the exploits patched for them in last few months makes my brain melt. I’m so glad I’m not personally involved with anything regarding dealing with this hack (nope, not even an email case related to it), but I feel for the folks who are dealing with it.

This is bad, and it probably has nothing to do with Trump. I’d like to blame the son of a bitch for everything, but this can’t really be laid at his feet unless he was running Solarwinds. When an adversary in cybersecurity has an exploit, it’s exceedingly rare for them to wait to use it. For example, this ran from March to June, and then it was apparently not infecting people anymore. For the intruder, it’s never known how long their foothold will work, so they usually strike as soon as they know they can.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 20, 2020, 7:11am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/34 "2020-12-20T07:11:21Z")

</div>

> [@scabpicker](#):
>
> This is bad, and it probably has nothing to do with Trump.

True, but Trump’s reaction to it is predictable…

… how dare anybody blame his good buddy Putin!

… on the other hand, maybe they hacked the voting machines!

😁 &nbsp;

> **[Trump downplays government hack after Pompeo blames it on Russia](https://www.theguardian.com/us-news/2020/dec/19/mike-pompeo-we-can-say-pretty-clearly-russia-behind-hack-us-agencies)**
>
> Secretary of state is first in administration to point to Russia but Trump attacks media over reports

> “The Cyber Hack is far greater in the Fake News Media than in actuality,” Trump tweeted on Saturday morning. “I have been fully briefed and everything is well under control. Russia, Russia, Russia is the priority chant when anything happens because [US media] is, for mostly financial reasons, petrified of discussing the possibility that it may be China (it may!)”

> “There could also have been a hit on our ridiculous voting machines during the election,” Trump wrote, “which is now obvious that I won big, making it an even more corrupted embarrassment for the USA.”

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [December 20, 2020, 8:14am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/35 "2020-12-20T08:14:15Z")

</div>

> [@scabpicker](#):
>
> it probably has nothing to do with Trump

He’s running the country, for fucks sake. Of course he’s responsible. He’s doesn’t duck responsibility by choosing to watch TV instead of reading security briefings, by putting corrupt toadies in charge of key government functions instead of competent people. And specifically:

> **[Trump moved cyber security budget to pay for his wall before major hacking...](https://www.independent.co.uk/news/world/americas/us-politics/trump-cybersecurity-fbi-russian-hackers-b1776007.html)**
>
> ‘We have a president diverting money, billions of it, to build a wall,’ says former FBI deputy

[https://www.reuters.com/article/us-usa-immigration-funds/trump-administration-taps-disaster-cyber-funds-to-cover-immigration-idUSKCN1VH2F7](https://www.reuters.com/article/us-usa-immigration-funds/trump-administration-taps-disaster-cyber-funds-to-cover-immigration-idUSKCN1VH2F7)

> **[White House Eliminates Cybersecurity Coordinator Role (Published 2018)](https://www.nytimes.com/2018/05/15/technology/white-house-cybersecurity.html)**
>
> The coordinator organized the defense of government computer networks and critical infrastructure.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 3:50pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/36 "2020-12-20T15:50:52Z")

</div>

> [@GreenWyvern](#):
>
> True, but Trump’s reaction to it is predictable…

Yeah, he’s a 24x7 fucktard, and his response is guaranteed to be useless. He may make the results worse, but this was still going to happen no matter who was president.

> [@Riemann](#):
>
> He’s running the country, for fucks sake. Of course he’s responsible.

And if you have any evidence that budget would have been used to move those agencies off of Solarwinds, then it might have something to do with this hack. As far as I can tell, that’s not the case, and not using Solarwinds’ Orion was the only way to avoid this hack.

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [December 20, 2020, 4:00pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/37 "2020-12-20T16:00:01Z")

</div>

> [@scabpicker](#):
>
> And if you have any evidence that budget would have been used to move those agencies off of Solarwinds, then it might have something to do with this hack. As far as I can tell, that’s not the case, and not using Solarwinds’ Orion was the only way to avoid this hack.

Sure, there’s no way that a president who’s in Putin’s pocket and has been siphoning funding and talent away from cybersecurity has any plausible relationship to a massive cybersecurity breach to Russia.

How on earth can you think it’s reasonable to assume that people and resources _that were not there because of Trump_ could not possibly have prevented or at least ameliorated this? Your suggestion that I have some additional burden of proof beyond clear evidence that Trump was actively diverting resources away from cybersecurity is preposterous.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 4:06pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/38 "2020-12-20T16:06:41Z")

</div>

> [@Riemann](#):
>
> How on earth can you think it’s reasonable to assume that people and resources _that were not there because of Trump_ could not possibly have prevented or at least ameliorated this?

Because they simply weren’t planning on moving off the popular piece of software, no matter what the budget. Up until then, it had been relatively trustworthy. It wasn’t like removing Solarwinds from your network was a standard security or hardening practice that you’d follow if you only had the budget to do so.

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [December 20, 2020, 4:24pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/39 "2020-12-20T16:24:55Z")

</div>

> [@scabpicker](#):
>
> Because they simply weren’t planning on moving off the popular piece of software, no matter what the budget. Up until then, it had been relatively trustworthy. It wasn’t like removing Solarwinds from your network was a standard security or hardening practice that you’d follow if you only had the budget to do so.

So however many smart people had hypothetically been devoted to cybersecurity over the past few years while Trump was instead gutting it, none of them could conceivably have spotted any potential problem here or done anything about it?

By your reasoning, presumably you’d advocate that we may as well just shut down the entire cybersecurity division and save the money - because going forward why would you expect it to be any different? There’s nothing anyone could possibly do to improve the situation.

Your position is utterly ridiculous.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 20, 2020, 4:35pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/40 "2020-12-20T16:35:04Z")

</div>

> [@scabpicker](#):
>
> Because they simply weren’t planning on moving off the popular piece of software, no matter what the budget.

The issue never was, is, or will be moving off SolarWinds. That’s a very strange thing to think. The issue is only finding the security vulnerability and fixing it.

If there had been more people looking for vulnerabilities and security breaches they might have found the problem sooner, and fixed it before so many systems were compromised.

[Previous page](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023.md?page=1)

[Next page](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023.md?page=3)
