Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

141–150 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#141
post #55

I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems: https://web.archive.org/web/20061215050427/http://www.matasa... Agent-based endpoint management is super convenient and is mainstream in modern IT manag…

I think attacks like this show, that an intervention is very much needed. And if it is to disrupt the technology industry big time, that might just be needed as well. I mean you wouldn't have spared the tobacco industry, just because making them liable for lung cancer means disrupting the industry.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#142

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol

what are some right answers?

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#143

Earlier quoted context omitted.

Detection is inadequate, because detecting the open barn door after the horse left is not helpful. > Sprinklers That is "we can prevent the server room from being destroyed" thinking, rather than "how do we survive the server room being destroyed" I'm proposing.

Youre suggesting detection is only possible much after the fact, when it is possible to also do before an adversary has been able to achieve anything significant on the target. But credit where credit is due, detection is not the answer but rather early detection. Sprinklers comment was made in jest.

I bought a book some years back about how to defeat burglar alarm systems, as I wanted to make my home more resistant to burglars. The book described a sophisticated system that would detect burglar entry and then automatically phone the cops.

The defeat was to chop the phone line where it entered the house, because the telephone company puts their box on the exterior of the house. (The book was printed before cell phones.) The sophisticated $$$$ detection system, defeated by the simple swing of an axe.

Relying on detection requires a perfect detection system, which is impossible.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#144
post #121

Earlier quoted context omitted.

No, they don't. Their safety record is incredibly good, especially considering you're zipping along at 500 mph in an aluminum balloon at 30,000 feet with flaming engines and surrounded by jet fuel. They really are a triumph of engineering.

yes, but also with 100+ years of engineering, for far fewer companies/nations, and with trillions (more?) thrown at the discipline. Software engineering is, what, 50 years old, tops?

Unfortunately, sophisticated threat actors are still very hard to defend against in aviation like in software.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#145
post #142

Earlier quoted context omitted.

Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol

what are some right answers?

I'm not a security professional, but I'll spend a couple minutes and make a stab at it:

1. don't store everything on the machine(s) accessible via that root password

2. don't allow any employee unfettered access to everything

3. don't allow one piece of software to have access to everything

4. do not store backups in the server room, or even in the same building

5. buy computers that do not have USB support in any form

6. full disk encryption on laptop. Minimize sensitive data on laptop. Use smallest capacity disk drives on laptop. Don't allow any laptops to have access to secure network. Issue hardwired desktops to employees. No wifi to secure network.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#146
post #121

Earlier quoted context omitted.

yes, but also with 100+ years of engineering, for far fewer companies/nations, and with trillions (more?) thrown at the discipline. Software engineering is, what, 50 years old, tops?

Unfortunately, sophisticated threat actors are still very hard to defend against in aviation like in software.

In my day at Boeing, nobody considered that the pilot might be a bad actor. Unfortunately, that was a mistake. It turns out pilots can be bad, and now there are procedures for that.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#147
post #142

Earlier quoted context omitted.

Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol

what are some right answers?

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#148
post #142

Earlier quoted context omitted.

what are some right answers?

I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…

However, with each new thing resources needed to implement and operate go up to the point when it is not feasible - money, people, time ...

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#149

Earlier quoted context omitted.

How to defend against these: 1) detection 2) detection 3) detection 4) sprinklers 5) detection 6) detection unfortunately, most orgs outsource their internal detection or have no capability at all.

Detection is inadequate, because detecting the open barn door after the horse left is not helpful. > Sprinklers That is "we can prevent the server room from being destroyed" thinking, rather than "how do we survive the server room being destroyed" I'm proposing.

It may be helpful if you have more then 1 horse.

And you are wrong in labeling it "prevention". It is a feedback mechanism. Fast feedback is essential in almost ANY scenario. Most of the things can be fixed if detected early on.

The first thing is knowing. If you don't know something, you can't act on it. To take your battleship analogy, if I remove all torpedo sensors from the ship, how long will it last given it is compartmentized and whatnot.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#150

Earlier quoted context omitted.

I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…

However, with each new thing resources needed to implement and operate go up to the point when it is not feasible - money, people, time ...

It's always a tradeoff between how much to spend on security vs how much a breach is going to cost you. But if you are going to spend it on security, spend it on things that are more likely to work, rather than on impossible things.
Post reply on HN