Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

41–50 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#41
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

I don't feel that's really a counter-argument to it being less sophisticated. Sure SolarWinds might be a better match for its makers goals, but sophistication is not the same thing as fitting its purpose.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#42
post #30
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code."

Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#43
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

> compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack.

Which makes me think: A bad actor could create a really good open source library or package, wait for everyone to use it and then introduce malware into it. Or they could "accidentally" add a security vulnerability and exploit it.

"There is another theory which states that this has already happened."

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#45
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

> their website still looks like something made by an AI using a template.

This is every website of any company selling to enterprise customers. It's incredibly frustrating as a reader.

I imagine anytime someone actually answers the question "Yes, but what do you do?", they get fired.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#46
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

> compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. Which makes me think: A bad actor could create a really good open source library or package, wait for everyone to use it and then introduce malware into it. Or they could "accidentally" add a security vulnerability and exploit it. "There is another theory which states that this has already happened."

While this is true, it’s probably MUCH easier to just exploit existing packages in some fashion.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#48
post #26

A16Z podcast coverage of the topic: https://a16z.simplecast.com/episodes/solarwinds-anatomy-of-h...

I listen to Scott Locklin. It appear to me A16Z more sophisticated threat to world than Russians even CIA combined.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#49
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

Suggesting stuxnet's goal wasn't stealth is silly.

It was so sophisticated at not being detected that it went under everyone's radar for 5+ years.

Stuxnet behaved in exactly the same way.. neither did anything that would be detectable unless certain criteria was met and a secondary payload sent.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#50
post #30

Earlier quoted context omitted.

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.
Post reply on HN