Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

21–30 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#21
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds software. If you design a stuxnet like malware and deploy it to 18k+ companies it will be found, because exploiting zero days left and right is super noisey. This malware was minimal. It's cool in a different way

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#23
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

I checked again and their website still looks like something made by an AI using a template.

https://www.solarwinds.com/

We’re Geekbuilt.®

Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community.

The result? IT management products that are effective, accessible, and easy to use.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#24

I find it curious that they would quote an executive on this. I doubt any of them have gotten their hands dirty on real code in years. Microsoft alone employs thousands of people more qualified to speak on the subject.

The executive is also an attorney, clearly relevant technical expertise wasn't how they chose someone to go on 60 monutes

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#25
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

"Accessible" is a good word. Almost invites speculation as to whom they're accessible. More fitting than "secure", anyway.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#27
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

it’s also interesting a value prop of solar winds is traffic monitoring

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#28
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

Well the incentives arent there to blame those meddling kids and their dog.

Security companies benefit from having adversaries be big and scary

Hacked companies benefit from adversaries being big and scary. Nobody blames you if you get hacked by the russians. Getting hacked by teenagers looks bad.

Edit: that said, i feel like i should add, i personally dont feel, based on what we know, that this particular attack was a bunch of kids.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#30
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability."

But the concerted marketing effort pays dividends. Solarwinds is almost the only choice for government. For potential attackers its a big red arrow. Exploit a rent-seeking company that writes mediocre software and exists mostly to cash in on "best practice" lock-in with government contracts.

as far as i know nobodys really addressed the elephant in the room. Solarwinds is still a preferred government purchase for monitoring. every company that was affected by it still uses it (or at least hasnt publically refuted it) and no government official has come forward to admit they will discontinue it. Solarwinds hasnt offered any remediation or major changes in their development, leadership or code. just patch, rinse, and repeat and try not to pay too much attention to the issue.

Post reply on HN