Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

71–80 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#71

Earlier quoted context omitted.

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.

Sorry, I can’t agree with you here. What you’re saying is basically company’s dissolution of it is hacked. If this indeed becomes the case the companies will indeed kill to keep their secrets.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#72
post #56

Earlier quoted context omitted.

An attack has multiple stages. Stuxenet's attack formula was: inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment Solarwinds attack forumla seems to be: compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT). Because the initial compromise (oh a bad passwo…

> the initial attack vector was a USB stick in a parking lot That's not fair. It should sound like this: "the initial attack vector was a Windows 0day requiring 0 clicks, delivered by a USB stick in a parking lot."

People are saying that the solarwinds hack is not sophisticated because it is just a supply chain attack on a vendor with woefully insufficient security. I agree, that is not a very sophisticated sounding attack. What does appear to be potentially quite sophisticated is the post compromise activity.

https://arstechnica.com/information-technology/2020/12/18000...

“Our analysis indicates that these compromises are not self-propagating; each of the attacks require meticulous planning and manual interaction. Our ongoing investigation uncovered this campaign, and we are sharing this information consistent with our standard practice.”

https://www.fireeye.com/blog/threat-research/2020/12/evasive...

You are saying my comparison is not fair because the USB stick actually had a 0 day which implies sophistication, but the supply chain build server was producing code and was also acting as a 0 day, in fact the actual payload appears to be significantly technically complex and custom.

Where do you draw the line between sophisticated and not?

  USB in parking lot -> 0day -> horizontal movement 0days -> vertical movement 0days -> Payload delivery.
  Bad admin credentials -> compromised build system -> supply chain 0day -> horizontal/vertical movement -> exfiltration of sensitive data.
Are we comparing:

  [USB in parking lot -> 0day] to [Bad admin credentials -> compromised build system -> supply chain 0day] or
  [USB in parking lot -> 0day] to [Bad admin credentials -> compromised build system] or
  [USB in parking lot] to [Bad admin credentials -> compromised build system]
We don't know the extent and complexity of [horizontal/vertical movement -> exfiltration of sensitive data] in the solarwinds saga and therefore we have insufficient information to determine its sophistication or not. Meanwhile the vast majority of the people in this post have completely written off technical sophistication that occurs directly after the solarwinds software updates.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#73
post #30

Earlier quoted context omitted.

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

Anectodally; I have been a one man army CTO for a period. I could not have managed my Windows servers without Solarwinds. It was an excellent product which did everything I could ever want.

...and something you would not ever want.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#75

Earlier quoted context omitted.

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.

And if you ever ignore a red light, pay your taxes late or do anything other than your absolute best to be an upstanding citizen you should be put into prison for the rest of your life.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#78
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

"how many engineers have probably worked on these attacks. And the answer we came to was, well, certainly more than 1,000,"

A thousand engineers is a huge project. You have no better knowledge than Microsoft about the attack.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#79
post #30
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

> nobodys really addressed the elephant in the room.

I think the elephant in the room is actually a more general issue that is cross platform and independent of the product implementation.

It’s 2021 and we are still ignoring the fundamental “best practice” that we’ve known about for at least 20 years.

Systems should be isolated from each other unless there is an overwhelming need for them to be connected and everything should run with the least privilege.

Centralised credential vaults and binary artefact repositories are an obvious example.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#80
post #65

Stuxnet seems to be far more sophisticated. I mean the entire idea of jumping an air gapped network was crazy but it worked. Since Microsoft itself was compromised via SolarWinds angle I'd take the president's statement with a grain of salt and probably less objective than it would be otherwise.

I thought MSFT was compromised due a netlogon exploit not Solarwinds. They hacked office365 which got them into Solarwinds.
Post reply on HN