Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

91–100 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#91
post #26

A16Z podcast coverage of the topic: https://a16z.simplecast.com/episodes/solarwinds-anatomy-of-h...

I just listened to this. Normally I like the A16Z podcast but this one was way below the normal standard. Just because they were organised, tested the exploit before they released it over a wider area it must have been a nation state?

It is as if a group of mates who codes a hack like this for a hobby/interest are disorganised have no experience in delivering software? Such ignorance for a self confessed expert. Scary.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#93

On "60 Minutes" they reported that the hardware in your computer is likely compromised as well, so new hardware will have to be bought. This has a simple fix I've advocated for years. Put the firmware for disk drives, USB sticks, embedded systems, etc., in ROM. Or at least provide a physical write-enable switch for updates. I have no idea why people responsible for security do not demand this. I would expect them to…

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#94

Earlier quoted context omitted.

> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking a…

Because it creates perverse incentives to never fix the problem, lie about it, deny it, and cover it up, because fixing it means accepting liability.

Or just distribute your source with the binary, and opt into the no liability regime.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#95

On "60 Minutes" they reported that the hardware in your computer is likely compromised as well, so new hardware will have to be bought. This has a simple fix I've advocated for years. Put the firmware for disk drives, USB sticks, embedded systems, etc., in ROM. Or at least provide a physical write-enable switch for updates. I have no idea why people responsible for security do not demand this. I would expect them to…

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#96

If the password for your "military grade" secured infastructure is literally "solarwinds123", I wouldn't say it's a sophisticated attack. It's a more complete picture of how much modern businesses value security or pentesting audits. The answer to that is exactly zero effs. As long as businesses think there is no ROI in security, this will stay the same. The only thing sophisticated about this was that from code to d…

not sure how it is mil grade if an infra allows such a password to begin with.

depends on which part of the world you are, military grade can mean different things.

I would not be surprised to find hair saloons with better security practices than our military.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#97
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

SolarWinds is the most sophisticated hack by Russian/China/Nirth Korea. Stuxnet was the most sophisticated hack by the US/Israel.

The US does not need to hack SolarWinds because they probably could use a court order for the same outcome to distribute rigged binaries for political enemies.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#98
post #30

Earlier quoted context omitted.

Absolutely agree. Solarwinds focuses a disproportionate amount of effort in ensuring it shows up favorably in Gartner magazine reviews and trade publications. As a monitoring platform its a monolithic, expensive, slow and rather dated monitoring solution. Agile does not come to mind, and you certainly wouldnt use it for anything approaching "observability." But the concerted marketing effort pays dividends. Solarwind…

> nobodys really addressed the elephant in the room. I think the elephant in the room is actually a more general issue that is cross platform and independent of the product implementation. It’s 2021 and we are still ignoring the fundamental “best practice” that we’ve known about for at least 20 years. Systems should be isolated from each other unless there is an overwhelming need for them to be connected and everythi…

>> Systems should be isolated from each other unless there is an overwhelming need for them to be connected and everything

And we should have checks built into the build pipelines and checksum the files that go into the build. We have Merkle trees for a long time. I think, it would be possible to detect injected code.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#99
Not the most sophisticated one in terms of technology, but probably the hack with the widest impact, orchestrated and planned successfully by a hostile nation with a huge set of people.

The US is going to see impact of this attack for years/decades to come, and it will cost them a shitload of manyears and money to mitigate the risks caused by this.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#100
post #7
post #4

Convince me it’s more sophisticated than Stuxnet.

Agreed. It's amazing how they managed to infect air gapped computers. How do you even test something like that before the actual attack.

from what I understand, they have the same controller that was being used in the centrifuges on their desk to develop the payload the rest was just a way to get to the controllers of the centrifuge which was rather standard.
Post reply on HN