News: 1610134204

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US courts system fears SolarWinds snafu could have let state hackers poke about in sealed case documents

(2021/01/08)


The SolarWinds hack exposed sealed US court documents – which could have a serious effect on Western sanctions against state-backed hackers.

As well as the well-publicised effects on [1]FireEye and [2]Microsoft , the downstream impact of the SolarWinds supply chain attack also struck the American federal court system. Aside from the obvious embarrassment and embuggerance that caused, it also may have revealed several formerly sealed, or secret, criminal case documents.

[3]

Those documents could have revealed information about upcoming criminal charges against Russian hackers, potentially exposing titbits that could feed into a wider intelligence picture of how those people are identified.

Infosec journalist Brian Krebs [4]reported a US Courts Administrative Office statement about the impact of the Russian-backed SolarWinds hack, quoting an anonymous source as saying that the agency was "hit hard".

Referring to the US federal courts' Case Management/Electronic Case Files system (CM/ECF), the body [5]said in a statement that the SolarWinds hack had risked "compromising highly sensitive non-public documents stored on CM/ECF, particularly sealed filings," adding: "An apparent compromise of the confidentiality of the CM/ECF system due to these discovered vulnerabilities currently is under investigation."

JetBrains' build automation software eyed as possible enabler of SolarWinds hack [6]READ MORE

That's important because US federal prosecutors and security agencies targeting state-backed hackers build their cases outside the public eye, under the cover of the court sealed case documents. In ordinary criminal cases this ensures crims aren't tipped off that they're about to be arrested or searched, for example.

Ciaran Martin, [7]former head of Britain's National Cyber Security Centre , was cautious about the impact of the apparent compromise, warning that just because Russia touched the CM/ECF system didn't automatically mean documents had been stolen.

"Don't jump to conclusions just because a particular customer of SolarWinds was targeted," he told The Register . "That implies very specific consequences. Also, don't assume that just because a specific SolarWinds customer has been targeted that anything other than espionage will have occurred."

Martin, now professor of practice in the management of public organisations at the University of Oxford, explained that a lot of state-sponsored hacking work consists in essence of picking the lock, opening the door, and then trying to figure out what you've just found. This contrasts with the popular view that fiendish adversaries pick their targets with ruthless precision and then execute a surgical cyber-strike to get what they're after.

"It's always possible that a compromise could lead to work on attribution or indictments but there are a lot of steps to take before arriving confidently at a conclusion," he added.

Over the past few years the US Department of Justice has adopted a policy of [8]announcing domestic criminal charges against other countries' hackers, mostly (but [9]not always ) resulting in the names of individual Russians becoming known in the West.

While nobody really expects criminal charges against SVR (Russian Foreign Intelligence Service) hackers to result in a court trial on American soil, charging individuals serves two main purposes: it ensures they can never safely travel to (or through) a country that has a US extradition treaty; and it signals to non-aligned states what Western cyber-norms are.

[10]

Unfortunately, despite how it might look, the policy of attribution and charging has no real deterrent effect on countries that try to hack the West. ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2020/12/09/fireeye_tools_hacked/

[2] https://www.theregister.com/2021/01/04/solarwinds_malware_confirmed/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x250%7C300x252%7C300x600&tile=3&c=33X-jkA8cdCOBVn0Ve5OtmTwAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dtop%26test%3D0

[4] https://krebsonsecurity.com/2021/01/sealed-u-s-court-records-exposed-in-solarwinds-breach/

[5] https://www.uscourts.gov/news/2021/01/06/judiciary-addresses-cybersecurity-breach-extra-safeguards-protect-sensitive-court

[6] https://www.theregister.com/2021/01/07/jetbrains_solarwinds_accusation/

[7] https://www.theregister.com/2020/11/11/ciaran_martin_speech_cyber_policy/

[8] https://www.theregister.com/2018/10/05/fancy_bear_charges_seven/

[9] https://www.theregister.com/2020/07/31/eu_sanctions_hackers/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x100%7C300x250%7C300x251&tile=4&c=44X-jkA8cdCOBVn0Ve5OtmTwAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/

Ummm

Tom Paine

Could have accessed sealed cases against Russian hackers ? Yeah... yeah, there's that, too. From an espionage PoV, cases relating directly to intelligence matters would be another obvious target, ditto those against "politically exposed persons", especially those towards the top of the tree. Less obviously, all sorts of other cases could be useful for an attacker, for all manner of purposes, from blackmail, to getting better knowledge of investigator TTP (and therefore how to escape detection),.. I'm sure there are plenty of other use cases.

Whilst the "surgical strike" type attack is very rare, there's a big pressure to extract metadata ASAP to enable other analysts to ID material to exfiltrate. Trade-off between increased chance of detection if trying to exfiltrate petabytes, vs hanging around so long that they're discovered via other means (ie., the discovery of the SolarWinds trojan.) Must make for interesting discussions in whichever war rooms they have those debates.

Pre-SolarWinds....just ask Ciaran Martin.........

Anonymous Coward

Quote: "Ciaran Martin, former head of Britain's National Cyber Security Centre, was cautious..."

*

Yup......Ciaran Martin has A LOT to be cautious about!!!!

*

https://www.theguardian.com/uk-news/2018/sep/21/british-spies-hacked-into-belgacom-on-ministers-orders-claims-report

*

So........Ciaran Martin knows exactly where the bodies are buried about EXACTLY THE SAME SORT OF STUFF done in Cheltenham!!!!!!

*

....and not just the commercial secrets of Belgian chocolate!!!!!!

*

There are NO "good guys"......................they are all at the same game!!!!!!!!!!

Re: Pre-SolarWinds....just ask Ciaran Martin.........

Yet Another Anonymous coward

And how else are we to protect against a Belgian global empire of evil ?

Humor in the Court:
Q. Were you acquainted with the deceased?
A. Yes, sir.
Q. Before or after he died?