Earlier quoted context omitted.
>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.
LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.
SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
71–80 of 294 posts
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#72Earlier quoted context omitted.
An attack has multiple stages. Stuxenet's attack formula was: inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment Solarwinds attack forumla seems to be: compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT). Because the initial compromise (oh a bad passwo…
> the initial attack vector was a USB stick in a parking lot That's not fair. It should sound like this: "the initial attack vector was a Windows 0day requiring 0 clicks, delivered by a USB stick in a parking lot."
https://arstechnica.com/information-technology/2020/12/18000...
“Our analysis indicates that these compromises are not self-propagating; each of the attacks require meticulous planning and manual interaction. Our ongoing investigation uncovered this campaign, and we are sharing this information consistent with our standard practice.”
https://www.fireeye.com/blog/threat-research/2020/12/evasive...
You are saying my comparison is not fair because the USB stick actually had a 0 day which implies sophistication, but the supply chain build server was producing code and was also acting as a 0 day, in fact the actual payload appears to be significantly technically complex and custom.
Where do you draw the line between sophisticated and not?
USB in parking lot -> 0day -> horizontal movement 0days -> vertical movement 0days -> Payload delivery.
Bad admin credentials -> compromised build system -> supply chain 0day -> horizontal/vertical movement -> exfiltration of sensitive data.
Are we comparing: [USB in parking lot -> 0day] to [Bad admin credentials -> compromised build system -> supply chain 0day] or
[USB in parking lot -> 0day] to [Bad admin credentials -> compromised build system] or
[USB in parking lot] to [Bad admin credentials -> compromised build system]
We don't know the extent and complexity of [horizontal/vertical movement -> exfiltration of sensitive data] in the solarwinds saga and therefore we have insufficient information to determine its sophistication or not. Meanwhile the vast majority of the people in this post have completely written off technical sophistication that occurs directly after the solarwinds software updates.Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#73Earlier quoted context omitted.
Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…
Anectodally; I have been a one man army CTO for a period. I could not have managed my Windows servers without Solarwinds. It was an excellent product which did everything I could ever want.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#74Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#75Earlier quoted context omitted.
>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.
LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#76Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#77Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#78Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…
A thousand engineers is a huge project. You have no better knowledge than Microsoft about the attack.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#79Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…
Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…
I think the elephant in the room is actually a more general issue that is cross platform and independent of the product implementation.
It’s 2021 and we are still ignoring the fundamental “best practice” that we’ve known about for at least 20 years.
Systems should be isolated from each other unless there is an overwhelming need for them to be connected and everything should run with the least privilege.
Centralised credential vaults and binary artefact repositories are an obvious example.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#80Stuxnet seems to be far more sophisticated. I mean the entire idea of jumping an air gapped network was crazy but it worked. Since Microsoft itself was compromised via SolarWinds angle I'd take the president's statement with a grain of salt and probably less objective than it would be otherwise.