Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

81–90 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#81

Earlier quoted context omitted.

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.

Years ago, the company I worked at had a very big production issue which resulted in a customer's database being deleted. Of course, the customer was furious and called the CEO asking for the person responsible to be fired.

Calmly, our CEO said: 'No. If there's anyone in this company who will never make that mistake again it's him.'

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#83
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

You're completely right, this wasn't a complicated attack at all. The two most notable items here are, Solarwinds has horrible security practices and those customers who were affected by the attack, also have horrible security practices. In a correctly secured environment it wouldn't have been possible for a infected Solarwinds server to connect out to a C2C server.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#84
post #73

Earlier quoted context omitted.

Anectodally; I have been a one man army CTO for a period. I could not have managed my Windows servers without Solarwinds. It was an excellent product which did everything I could ever want.

...and something you would not ever want.

Sure. It paid hansomely for a time. Then I got the hell out. :)

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#85
post #30

Earlier quoted context omitted.

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

> nobodys really addressed the elephant in the room. I think the elephant in the room is actually a more general issue that is cross platform and independent of the product implementation. It’s 2021 and we are still ignoring the fundamental “best practice” that we’ve known about for at least 20 years. Systems should be isolated from each other unless there is an overwhelming need for them to be connected and everythi…

It's also important to have diversity. For example, on the Boeing 757 there are two computers that control the stab trim, that do the same thing. They must agree or both computers are automatically locked out.

The two computers are developed by two independent teams who are not allowed to talk to each other. Two different CPUs, two different algorithms, two different programming languages.

The idea, of course, is a design problem with one does not propagate to the other.

If one program is used in all your infrastructure, all your infrastructure is compromised when that program has a bug.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#86

Earlier quoted context omitted.

>> "Solarwinds hasnt offered any remediation or major changes in their development, leadership or code." Not accurate re: leadership. A new CEO just started in January, and their CTO was either terminated or he left just after the hack news.

LOL the whole “fall guy” thing is how companies keep doing what they’re doing while making some symbolic penance. For a software company a fuckup of this magnitude should be: all customers leave, company dies, execs never work again. Anything less is an insufficient incentive to work extremely hard to prevent this from happening.

Your method sounds good, but it makes things less safe in practice because it provides every possible incentive to hide, cover up, deny, etc., any problems.

A far better system is "no fault" where the company has incentive to be open about problems and finding solutions.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#88
post #55

I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems: https://web.archive.org/web/20061215050427/http://www.matasa... Agent-based endpoint management is super convenient and is mainstream in modern IT manag…

> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking a…

Because it creates perverse incentives to never fix the problem, lie about it, deny it, and cover it up, because fixing it means accepting liability.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#89
On "60 Minutes" they reported that the hardware in your computer is likely compromised as well, so new hardware will have to be bought.

This has a simple fix I've advocated for years.

Put the firmware for disk drives, USB sticks, embedded systems, etc., in ROM. Or at least provide a physical write-enable switch for updates.

I have no idea why people responsible for security do not demand this. I would expect them to be really sick and tired of "we have no idea if our firmware is infected or not, because we allow any piece of software to modify the firmware."

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#90

If the password for your "military grade" secured infastructure is literally "solarwinds123", I wouldn't say it's a sophisticated attack. It's a more complete picture of how much modern businesses value security or pentesting audits. The answer to that is exactly zero effs. As long as businesses think there is no ROI in security, this will stay the same. The only thing sophisticated about this was that from code to d…

not sure how it is mil grade if an infra allows such a password to begin with.
Post reply on HN