Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

31–40 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#31
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

Stuxnet was also a supply chain attack. The first infections were at Foolad Technic and Behpajooh, a pair of privately owned engineering firms.

The malware keeps a "breadcrumb" trail of each machine it infects, and based on investigations by Symantec [1] it was determined that every Stuxnet sample from Natanz originated from outside suppliers.

1. https://tinyurl.com/1eswo98i

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#32
I feel like this Solarwinds breach was a low effort, extremely high reward move, sort of like how Russia only had to spend 100k on ads in 2016 to get a massive reach on Facebook. I wouldn't think say this is the most sophisticated attack, this sounds more like they are embarrassed they were hacked for a year before they realized it and have to save face

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#33
post #4

Convince me it’s more sophisticated than Stuxnet.

https://en.wikipedia.org/wiki/2020_United_States_federal_gov...

On December 8, 2020, the cybersecurity firm FireEye announced that red team tools had been stolen from it by what it believed to be a state-sponsored attacker.[106][107][108] FireEye was believed to be a target of the SVR, Russia's Foreign Intelligence Service.[27][109] FireEye says that it discovered the SolarWinds supply chain attack in the course of investigating FireEye's own breach and tool theft.[110][111]

After discovering that attack, FireEye reported it to the U.S. National Security Agency (NSA), a federal agency responsible for helping to defend the U.S. from cyberattacks.[1] The NSA is not known to have been aware of the attack before being notified by FireEye.[1] The NSA uses SolarWinds software itself.[1]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#35
post #4

Convince me it’s more sophisticated than Stuxnet.

It's not a zero sum game. It is interesting in that it marks the first _wide spread_ attack on a supply chain via cyber space. The malware's DNS signaling protocol is pretty neat, which you can look at here: https://www.fireeye.com/blog/threat-research/2020/12/sunburs...

The headline is "most sophisticated ever" not "totally boring". SolarWinds can both be a very interesting thing and the headline can also be hyperbole.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#36
> “I think from a software engineering perspective, it’s probably fair to say that this is the largest and most sophisticated attack the world has ever seen,” Smith said.

The word “seen” is doing a lot of work there.

(Think, probably, and fair, are doing some too.)

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#37
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

An attack has multiple stages. Stuxenet's attack formula was:

  inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment
Solarwinds attack forumla seems to be:

  compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT).
Because the initial compromise (oh a bad password, oh, a compromised remote code execution (RCE) engine) was not sophisticated this doesn't look sophisticated, but even stuxnet wasn't "sophisticated" in that sense, the initial attack vector was a USB stick in a parking lot, there's nothing sophisticated about that either. There is probably a lot of sophistication behind staying silent and the exfiltrating of data that we don't know about, even the silent exploration of multiple internal networks seems like a fairly non-trivial task to scale, especially to 18,000 potential targets, if more than a handful of them have been successfully compromised in a hard to resolve way, I would call that sophisticated.

The APT/Exfiltration work is much more close to the sophistication of the virus that attacked the centrifuges than the bad password. For all we know the hack could have levereaged information gained via kaspersky, telegram, or whatever other software to do sophisticated things much the same way we asked Siemens for their help.

We don't have enough information to make an assessment yet.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#38
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

Solarwinds' former VP of Security posted a blog post entitled "Do Your Vendors Take Security Seriously?" [1] while, according to reports, being totally pwned from floor to ceiling.

[1] https://www.solarwindsmsp.com/blog/do-your-vendors-take-secu...

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#40

I thought they got access through an update sever with a weak password? Was the attack otherwise sophisticated and just relied on an easy entry point? So the breaking in was easy, but the plan to steal once inside was sophisticated?

The whole weak password thing was simply a funnily timed thing some guy found. It had absolutely nothing to do with the malicious update, which was the source of this supply chain attack. For some reason a bunch of people online decided that two things happening around the same time means they are related. They are not

No, “a bunch of people online” decided that if you have jarring security practices in one avenue, it’s totally unsurprising if it turns out that you have other doors wide open too. Which is a completely reasonable assumption.
Post reply on HN