11 ms·
JetBrain's TeamCity May Be Entry Point for U.S. Hack
- ChefboyOG 6y ago@mods - I changed the title from the original "Russian Software Company May Be Entry Point for U.S. Hack" to be more clear, as "Russian Software Company" felt vague and linkbait-y to me. Apologies if this violates the "No editorialized titles" policy.
- polka_haunts_us 6y agoIs JetBrains even Russian? I thought they were Czech.
- avsbst 6y agoThe title and lede state they are "Russian-Owned" and a Czech company. Perhaps NYT edited title after publishing or original poster misread the title. Russian-Owned Software Company May Be Entry Point for Huge U.S. Hacking Russian hackers may have piggybacked on a tool developed by JetBrains, which is based in the Czech Republic, to gain access to federal government and private sector systems in the United States.
- sam_lowry_ 6y ago"Russian-owned" is still largely misleading. The company is owned by Russian speakers that lived and studied in Russia before starting JetBrains. Most (if not all) of them have two citizenships by now, one is Russian. The company is not owned by the Russian state and has never been.
- st1ck 6y agoIn Europe, words like Russian or Czech typically mean ethnicity. Even if you live there for 20 years, learn the language and get citizenship, people likely won't call you Czech. Maybe you can be called Czechian (if it's a real word) or Praguer since those don't imply ethnicity. I don't live in Czechia though, so take this with a grain of salt. > The company is not owned by the Russian state and has never been. This is true however, and NYT did (predictably) poor job here. Unless there is any indication that JetBrains were involved in the hack, mentioning "Russian-owned" in the title is misleading.
- flashmozzg 6y ago>In Europe, words like Russian or Czech typically mean ethnicity. Well, then, suddenly all those fines on some obscure Russian (alright, alright, half-Russian) company called Google all make sense now! Just another part of the sanctions!
- vngzs 6y agoThe title has been edited at least twice since it was published. The original title: > Russian Software Company May Be Entry Point for Huge U.S. Hack Which was changed to: > Russian-Owned Software Company May Be Entry Point for Huge U.S. Hacking Then later changed to: > Widely Used Software Company May Be Entry Point for Huge U.S. Hacking
- dijksterhuis 6y agoTitle has subsequently changed (possibly again): > Widely Used Software Company May Be Entry Point for Huge U.S. Hacking Seems the reporter got a fair bit of flack from folks on twitter.
- deleted 6y ago[deleted]
- amdolan 6y agoRussian founders began the company in Prague and opened a Saint Petersburg office soon afterwards.
- sam_lowry_ 6y agoMost of the software developers are still in Saint-Petersburg, Russia. Russian founders opened a Czech company because being Russian, they could not easily reach world markets.
- lemming 6y agoActually, I believe the reason was simply that the founders were living in Prague at the time they founded the company.
- sbelskie 6y agoI’m worried this going to turn out to be an unsecured TC instance after the article makes it sound like the underlying software was compromised.
- jen20 6y agoGiven "solarwinds123" this seems like a perfectly reasonable default assumption at this point.
- edoceo 6y agoOh, I thought you were joking but, no. https://www.extremetech.com/computing/318430-security-researcher-solarwinds123-password-left-firm-vulnerable-in-2019 https://www.extremetech.com/computing/318430-security-resear...
- thorax 6y agoHere's what we need to be thinking instead of getting defensive or extra-optimistic: If high-end security firms and fairly diligent government agencies were infiltrated, why would we think that smaller dev toolchain organisations not founded as security organisations will somehow be less likely to be targeted and become a vector for introducing supply chain attacks. Sophisticated attackers will go after any soft underbelly or pore they can find, and there's no reason not to believe they'd put significant effort into quietly abusing Jetbrains security just like they did with Solarwinds. I'm less worried about the "Russian" red scare mention other than it may give non-US organizations a few more opportunities to inject badness that we can't get visibility on. Bottom-line is that it would be the holy grail and are we treating it as the high priority target it is? Having worked for dev tool companies in the past, I know they are a lot more worried about innovation than about their own internal processes.
- foepys 6y ago> SolarWinds confirmed Wednesday that it used TeamCity software to assist with the development of its software and was investigating the software as part of its investigation. The company said it had yet to confirm a definitive link between JetBrains and the breach and compromise of its own software. This is a very big "may". Reads like they are simply basing these allegations on the Russian founders part.
- swyx 6y agoit is unbelievable the irresponsibility of the NYT to not provide more substantive evidence before going to print with this "may be", particularly with this title. The reputational hit alone will cost Jetbrains millions including across unrelated products (which they encourage by fluffing out this piece with Jetbrains' customer list without regard as to whether or not they use TeamCity).
- Ericson2314 6y agoServes Jetbrains right for being privately held and not an investment vehicle open to global capital. /s
- keraf 6y agoMost people familiar with JetBrains (like software and system engineers) will likely read through the lines and simply ignore this article, given the good reputation of the company. The worrying part is that this type of article is destined for the less techy reader like the higher ups approving software purchases. The lack of evidence feels like they got fingers pointed at them just for being... Russian?
- andoriyu 6y agoWould people who make decisions to use JetBrains products be smart enough to even read beyond title?
- diebeforei485 6y agoWSJ is also saying that investigators are looking into JetBrains and TeamCity in particular. It's not just NYT. They may not have formally asked JetBrains for assistance with their investigation yet, but that doesn't mean they aren't being investigated.
- quaffapint 6y agoThey probably already had access to the network and just used TeamCity since that was SolarWinds build process. Or someone really misconfigured things to allow external access.
- gamesbrainiac 6y agoOfficial Response from JB: https://blog.jetbrains.com/blog/2021/01/06/statement-on-the-story-from-the-new-york-times-regarding-jetbrains-and-solarwinds/ https://blog.jetbrains.com/blog/2021/01/06/statement-on-the-...
- vngzs 6y agoReading between the lines, does this mean the attack may have simply been an on-prem install that was compromised, rather than every TeamCity install ever, or JetBrains' official SaaS version? Any developer tools company worth their salt should be dogfooding their own build system, so they likely build IDEs with this tool. In the worst case, IntelliJ/GoLand/etc could be compromised as a result. This would be unlikely to mean there's malicious source code floating around, but it could mean lots of privileged access to software companies' networks. If the attacks are as targeted as the NY Times article makes it out to be, discovering the full extent of the damage may take quite some time ...
- ArchOversight 6y agoIt is very likely that a CI/CD tool was improperly configured. As a former pen tester/red teamer, your favorite CI/CD tool is also my favorite way to gain access to a large footprint within the org.
- mmglr 6y agoWhat are some good tips to minimize the attack surface of my CI/CD tool?
- refulgentis 6y agodont let it run code
- ArchOversight 6y agoActually not a bad idea :P
- parhamn 6y agoThere were tweets by the author of this article suggesting more nefarious involvement here. Doesn’t seem to be much substantiation though. [1] https://twitter.com/nicoleperlroth/status/1346909580219936769 https://twitter.com/nicoleperlroth/status/134690958021993676...
- keyle 6y agoGod reading that garbage upsets me. "Cyberysecurity Reporter", not a very good one at that.
- MrRiddle 6y agoObscure software company?!
- swyx 6y agoshe is writing for a general audience, please lets not get upset about that one and focus on actual lack of evidence.
- MrRiddle 6y agoShe’s setting up a scene for a play. Just from those couple line I’m writting whole thing off as same neocon Russian witch hunt we saw in recent years. Obscure company? Ain’t that some bullshit.
- edoceo 6y agoI'm with you on that, those words serve to diminish the work and reputation of JetBrains even before the ~average reader understand who they are and what they do. Like "some idiot, edoceo" seeds that I'm a fool vs "my CTO, edoceo" (of course the truth is in the middle)
- IncRnd 6y agoRead her next tweet, which was clearly part of a sequence of tweets. She wrote, "JetBrains is not a household name but is used by 79/ Fortune 100." Jetbrains is an obscure software company for most people, despite a number of people using their software daily.
- MrRiddle 6y agoSeems like business as usual, with old administration coming back, let the Russian witch hunt resume.
- lol768 6y agoIs there any published technical evidence to look at which actually implicates JetBrains? CVE or a POC? Publication of the poisoned build of the CI software? Indicators of compromise?
- uncledave 6y agoI suspect TC may have been leveraged but it doesn’t mean it’s responsible for every horrible misconfiguration that can occur. Case in point, I have used TC to gain AD administrative privileges before because the idiot who set it up ran a build agent as a domain admin so it could get access to a locked down signing cert. I just created a new build to add me to the right group and ran it on that agent. These things are really trivial to find and exploit. Also the build agents will obtain and run almost any untrusted software and leave it on disk quite happily for when a later build comes along.
- dr_faustus 6y agoSounds like SolarWinds hired a good PR agency with the goal to deflect blame and make it sound like a big conspiracy. JetBrains being a Czech/Russian company makes it the perfect scape goat. As was pointed out, "solarwinds123" hints at very bad security practices which makes some unpatched system or weak password the much likelier scenario. It might well be that the intruders then manipulated the SolarWinds TeamCity config. Would have done the same with Jenkins...
- ahepp 6y agoOn a semirelated note, what's with all the articles claiming the attack represents an extreme level of sophistication? It sounds like the execution was skilled, but I haven't heard anything yet that seems technically novel or extraordinary. Maybe I haven't read the right articles, but it sounds like solarwinds got pwned, and all these big targets loaded the malware onto their own networks... Again, skillful execution, but it's not like they cracked an encryption algorithm or even did known-but-still-awesome exploits like rowhammer/spectre
- ballenf 6y agoIf Amazon's research is correct that 250 companies were targeted, that indicates just as a matter of a scale there had to be significant resources behind the effort. I'd call that sophisticated even if just in terms of organizational efforts. Additionally, doing this and not getting caught for 6 months or whatever takes significant discipline from every single person involved. You don't see that level of size, discipline and organization outside a handful of top companies.
- nitrogen 6y agoI haven't been following this story very closely. Was each and every organization individually targeted after the SolarWinds compromise was in place, or was it sort of opportunistic and automated, where the SolarWinds compromise phoned home and most of the 250 orgs just got automated/scripted escalation and exfiltration, and only a few orgs got personal attention?
- jrs235 6y agoI heard reports that the mismatched file download/installer hash was known and never fixed for MONTHS, if true, points to incompetency at SolarWinds.
- twistedpair 6y agoDoesn't SolarWinds have offices in Eastern Europe? Perhaps some Russians work in those offices? Jump to conclusions mat?
- Hickfang 6y agoI call cyber BS on that story!
- tpmx 6y agohttps://archive.is/5ArdN https://archive.is/5ArdN
- koreanguy 6y agoperfect scapegoat, the most interesting thing about this is that not many know a AI actually was trained to hack subnets with known exploits on hosts, you have a AI with vega backend living in Saas cloud crunching looking every possible leak within the host . this hack was not from Russia :) but from Sweden
- twistedpair 6y agoWhat evidence do they have, or is it process of elimination, like source code built normal binaries locally, but malicious binaries when built in CI? Hope they have some VM images of the CI boxes for forensic analysis. Really hoping I don't have to go back to Eclipse.
- swiley 6y ago>Don't worry about downloading these closed dev tools with piles of transitive dependencies. It's totally ok, we trust the vendor. At this point I trust armature software developers more than commercial ones.
- guru4consulting 6y agoyeah.. and next breaking news - Microsoft and Google also may be entry points for U.S. Hack because Solarwinds used both Windows laptops and Android mobile phones. I wish tech reporting is written by technical folks, or at least proof read by tech experts.
- pfranz 6y ago> I wish tech reporting is written by technical folks, or at least proof read by tech experts. This comes up for journalism of every single industry. “Briefly stated, the Gell-Mann Amnesia effect is as follows. You open the newspaper to an article on some subject you know well. In Murray's case, physics. In mine, show business. You read the article and see the journalist has absolutely no understanding of either the facts or the issues. Often, the article is so wrong it actually presents the story backward—reversing cause and effect. I call these the "wet streets cause rain" stories. Paper's full of them. In any case, you read with exasperation or amusement the multiple errors in a story, and then turn the page to national or international affairs, and read as if the rest of the newspaper was somehow more accurate about Palestine than the baloney you just read. You turn the page, and forget what you know.” ― Michael Crichton
- deleted 6y ago[deleted]
- Rebelgecko 6y agoDoes it seem odd to anyone else that the article begins with a big Russian flag? That seems to be implying some sort of official Russian involvement. To me it seems much more likely that Solarwinds just left the username and password as admin:admin, and any detail about Jetbrains are kinda irrelevant
- emptyparadise 6y agoPeople will click on the article more this way.
- throwawaybutwhy 6y agoWhy isn't NYT perma-banned on HN? This is much much worse than ZeroHedge. Disclosure: I own a bunch of JetBrains products and love them (even though sometimes there's a lag during typing).
- nucatus 6y agoThe teamcity application is a java application that can be easily analyzed for security threats. Nothing stops you from decompiling it and check the code. This story looks very much like a scapegoat for SolarWinds' poor security practices.
- RhodesianHunter 6y agoA scapegoat via the New York Times citing a government investigation? That seems rather roundabout
- fortpoint 6y agoHas anyone noticed that the JetBrains certs are showing up as untrusted when you start Intellij or when you visit JetBrains.com ?
- konart 6y agoNope. Everything is green for me.
- tilolebo 6y agoBreaking news: electronic components made by Chinese companies may have been used on the servers running the Russian software used as entry point for the U.S Hack...