New Now DHS..

The Department of Homeland Security is the third federal agency to have fallen victim to a major cyberespionage campaign by the Russian government, joining the Treasury and Commerce departments as targets that have been compromised, officials said Monday.
The list of victims is expected to grow and to include more private companies, said officials and others familiar with the matter, who spoke on condition of anonymity because the matter is under investigation.
The fact that the department charged with safeguarding the country from physical and cyber attack was victimized underscores the campaign’s significance and calls into question the adequacy of federal cybersecurity efforts.
DHS spokesman Alexei Woltornist said that DHS is aware of reports of a breach and is currently investigating the matter. The compromise of that agency was first reported by Reuters.
Russia has denied any role in the attacks.

New Maybe they (and especially NSA) should spend more time on defense instead of attacks
Is cybersecurity the exception to the rule that the best defense is a strong offense?

New have you met security folks? Theatre mostly
soon as I heard I shut the systems off then called the sec folks
they started whining about I didnt have paperwork to do that
"Science is the belief in the ignorance of the experts" – Richard Feynman
New There is a fix.
The Register: Backdoored SolarWinds software, linked to US govt hacks, in wide use throughout the British public sector
SolarWinds' customers are being urgently advised by the firm to upgrade to Orion Platform version 2020.2.1 HF 1 "as soon as possible to ensure the security of your environment."

"There is a cult of ignorance in the United States, and there has always been. The strain of anti-intellectualism has been a constant thread winding its way through our political and cultural life, nurtured by the false notion that democracy means that "my ignorance is just as good as your knowledge."

-- Isaac Asimov
New The true fix
Throw out all the computers and start over from scratch. Given how hackable UEFI has been shown to be, I wouldn't trust a single computer to not start phoning home even if they do a full wipe & reload.
use std::option::sig
