Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Nuclear weapons agency breached amid massive cyber onslaught
Politico (few on the right are covering this) ^ | December 17th, 2020 | By NATASHA BERTRAND

Posted on 12/17/2020 1:11:47 PM PST by Mariner

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-40 last
To: Mariner; Roman_War_Criminal

Wonderful.......


21 posted on 12/17/2020 2:24:33 PM PST by metmom (...fixing our eyes on Jesus, the Author and Perfecter of our faith.....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mariner

obviously some elements in the government have toys with which they can hurt themselves and the rest of us!


22 posted on 12/17/2020 2:40:56 PM PST by mo ("If you understand, no explanation is needed; if you don't understand, no explanation is possible)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PIF

Unfortunately, not true. There are very important defensive systems on the SiprNet, sigh...........


23 posted on 12/17/2020 2:42:00 PM PST by chuckr (Barack Hussein Obama - A Legend In His Own Mind)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Mariner

Cheer up! We’re putting a senile old man in charge of the nuclear codes!


24 posted on 12/17/2020 2:42:33 PM PST by MrChips ("To wisdom belongs the apprehension of eternal things." - St. Augustine I don’t think we need one,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Georgia Girl 2

It’s been widely disclosed that Russia was behind it.


25 posted on 12/17/2020 3:02:27 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Mariner

Orion is not a C&C platform, it’s used for monitoring. Most environments are monitored using SNMP or WMI. SNMP is a stupid simple protocol to compromise for signal data and is often recommended shutdown or heavily firewalled point-to-point.


26 posted on 12/17/2020 3:04:26 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mariner
The Energy Department and National Nuclear Security Administration, which maintains the U.S. nuclear weapons stockpile, have evidence that hackers accessed their networks as part of an extensive espionage operation that has affected at least half a dozen federal agencies,

But it's impossible for Democrats to have hacked the voting machines?

27 posted on 12/17/2020 3:16:46 PM PST by libertylover (Remember: Deep State hated Jesus too.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

SNMP V2 can configure every device in the network.

https://www.solarwinds.com/solutions/orion

Solar Winds graduated to the mythical “single pane of glass” with Orion.


28 posted on 12/17/2020 3:21:43 PM PST by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 26 | View Replies]

To: Paladin2

How, exactly?


29 posted on 12/17/2020 3:35:26 PM PST by Coronal
[ Post Reply | Private Reply | To 2 | View Replies]

To: rarestia

It cant be too widely disclosed if I haven’t read about it. 😊


30 posted on 12/17/2020 3:38:15 PM PST by Georgia Girl 2 (The only purpose of a pistol is to fight your way back to the rifle you should never have dropped)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Mariner

Most orgs don’t use that functionality due to risk. I’ve worked in healthcare, financial, and government industry IT auditing and every regulatory body prohibits or requires extensive curtailment of rights for SNMP due to risk. There are better C&C platforms out there that don’t require SNMP.


31 posted on 12/17/2020 3:45:10 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 28 | View Replies]

To: rarestia

Ive worked in all of those too.

As a PMP and CISSP.

The only large companies, or government agencies I’ve seen not using such functionality, when available, are those that can’t figure out how to get it properly configured, or whose legacy systems are not compatible.

And those who have smart senior engineers. Which is rare now days.

IT mgmt believes in the myth of a single pane of glass. They believe it will allow them to reduce staff significantly.

And the stupid runs deep and wide in government networks which do not have an air gap.


32 posted on 12/17/2020 4:02:37 PM PST by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 31 | View Replies]

To: Mariner

Most orgs don’t have the brain trust required to implement and maintain a proper PKI and managed identity platform, both of which are critical to secure communications in C&C infrastructure. I’m a CISSP and have been involved with PKI implementation and management for 10 years. It’s the Achilles heel of many orgs.


33 posted on 12/17/2020 4:24:10 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Mariner

I can tell you that the government severely overworks the sysadmins and security people that are responsible for government infrastructure, so much so that its easy to get spies in the door with poorly configured infrastructure where a premium is places on speed of deployment. Bonuses too.The government wont pay a premium for good people either. Another problem.


34 posted on 12/17/2020 4:30:10 PM PST by JoeRender
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Critical to make them secure, but not essential to make them work.

There ought to be a law.

Organizations with a competent “brain trust” are rare. And where they exist, you see multiple specialized platforms for configuration control. And multiple other platforms for monitoring, alerting and ticketing.

Or course, scale matters.

And that’s why we’re in business...well, except for me. I’m recently retired.

It all comes down to competent IT Management, which is more rare than a competent engineering staff. And quickly becoming extinct.


35 posted on 12/17/2020 4:33:40 PM PST by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Mariner

I’ve got 20 years or so left. I’m constantly talking to anyone who’ll listen about how security “professionals” are more focused on products than practices. We need a groundswell of support that just isn’t there. Security is tough, unforgiving work. You have to be right more than the bad guys and they’re changing strategies daily.


36 posted on 12/17/2020 4:40:53 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 35 | View Replies]

To: ProtectOurFreedom
said, "report today from ODNI"
Where did you read that?

37 posted on 12/17/2020 4:42:23 PM PST by Steve Van Doorn (*in my best Eric Cartman voice* 'I love you, guys')
[ Post Reply | Private Reply | To 16 | View Replies]

To: rarestia

“Security is tough, unforgiving work.”

You spend MOST of your time at loggerheads with those who hired you to help them. Trying to talk sense into them.

They don’t care about the rare, devastating total breach. They think it’ll never happen. And you’re just trying to run up the bill with gibberish.

It’s the damndest thing.

Well, the devastating total breach happened. And we can’t even take solace in it, or say I told you so.

This one is the hack of the century.


38 posted on 12/17/2020 4:48:15 PM PST by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 36 | View Replies]

To: chuckr

Well that used to be the case.


39 posted on 12/17/2020 4:49:52 PM PST by PIF (They came for me and mine ... now its your turn)
[ Post Reply | Private Reply | To 23 | View Replies]

To: JoeRender

“I can tell you that the government severely overworks the sysadmins and security people that are responsible for government infrastructure”

And they always have. Especially the good ones.

Same with private enterprise.


40 posted on 12/17/2020 4:51:02 PM PST by Mariner (War Criminal #18)
[ Post Reply | Private Reply | To 34 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-40 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson