Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

61–70 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#61
post #55

I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems: https://web.archive.org/web/20061215050427/http://www.matasa... Agent-based endpoint management is super convenient and is mainstream in modern IT manag…

> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking a…

That would work if we knew how to ship secure software at something resembling the cadence the industry demands, but we do not. We pretend to, and we get away with it because there isn't toothy liability attached to shipping bugs. We are all here, the software people on this site, the beneficiaries of that system.

Just very simple things, like reimplementing non-performance-sensitive C software from the 1990s and 2000s in simple memory-safe languages; it can't happen, the budget to make it happen would totally disrupt P&L at large companies; repeat with every well-known risk this kind of code is exposed to. I don't think we know how to solve this problem, which is why I tend to recoil from policy proposals to "solve" it.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#62
If the password for your "military grade" secured infastructure is literally "solarwinds123", I wouldn't say it's a sophisticated attack.

It's a more complete picture of how much modern businesses value security or pentesting audits. The answer to that is exactly zero effs.

As long as businesses think there is no ROI in security, this will stay the same.

The only thing sophisticated about this was that from code to deployment there wasn't any single audit of anyone. And that's a bad joke by any security measurement.

If any intruder can stay undetected THAT long, I don't wanna know what's up with MSFTs infrastructure. Must be an open door for everyone, and probably still uses the Perl pre-release based pipeline.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#63
post #61

Earlier quoted context omitted.

> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking a…

That would work if we knew how to ship secure software at something resembling the cadence the industry demands, but we do not. We pretend to, and we get away with it because there isn't toothy liability attached to shipping bugs. We are all here, the software people on this site, the beneficiaries of that system. Just very simple things, like reimplementing non-performance-sensitive C software from the 1990s and 200…

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#64
post #30
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

Anectodally; I have been a one man army CTO for a period. I could not have managed my Windows servers without Solarwinds. It was an excellent product which did everything I could ever want.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#65
Stuxnet seems to be far more sophisticated. I mean the entire idea of jumping an air gapped network was crazy but it worked.

Since Microsoft itself was compromised via SolarWinds angle I'd take the president's statement with a grain of salt and probably less objective than it would be otherwise.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#66
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

The supply chain compromise does not appear to be sophisticated. The "post installation of compromised software" activity seems to be somewhat sophisticated.

https://www.fireeye.com/blog/threat-research/2020/12/evasive...

No high school kid is doing that.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#67
post #38

Earlier quoted context omitted.

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

Solarwinds' former VP of Security posted a blog post entitled "Do Your Vendors Take Security Seriously?" [1] while, according to reports, being totally pwned from floor to ceiling. [1] https://www.solarwindsmsp.com/blog/do-your-vendors-take-secu...

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#68

If the password for your "military grade" secured infastructure is literally "solarwinds123", I wouldn't say it's a sophisticated attack. It's a more complete picture of how much modern businesses value security or pentesting audits. The answer to that is exactly zero effs. As long as businesses think there is no ROI in security, this will stay the same. The only thing sophisticated about this was that from code to d…

Initial compromise may not have been sophisticated or hard to achieve, the post compromise may have been somewhat sophisticated judging from the attackers operational security.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#70
post #7
post #4

Convince me it’s more sophisticated than Stuxnet.

Agreed. It's amazing how they managed to infect air gapped computers. How do you even test something like that before the actual attack.

From what I've read and heard about the attack in the past, they had managed to find the supplier and had confiscated some blueprints or the actual structures (nuclear reactor?) that was used and then reverse engineered it from there with the help of nuclear scientists to find vulnerabilities in it.
Post reply on HN