Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

201–210 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#201
post #157

Earlier quoted context omitted.

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

An aircraft carrier also has the benefit of being operated under a vastly different framework than a regular IT system: military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks. But I've seen plenty of companies implementing solid (real) security measures only to see employees looking to bypass them themselves due to the inconvenience they caused, thu…

> military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks.

The military are not immune to this either. Case study, the 2006 Nimrod crash in Afghanistan [0], which killed all 14 of its crew. This plane was the flying equivalent of an unsecured server whose root password was 'password'.

[0] https://en.wikipedia.org/wiki/2006_Royal_Air_Force_Nimrod_cr...

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#202
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

> compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. Which makes me think: A bad actor could create a really good open source library or package, wait for everyone to use it and then introduce malware into it. Or they could "accidentally" add a security vulnerability and exploit it. "There is another theory which states that this has already happened."

> A bad actor could create a really good open source library or package, wait for everyone to use it and then introduce malware into it.

This often happens with Chrome browser extensions that change hands and the new owner then injects malware or crypto mining or keylogging etc. into the newly acquired extension.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#203

I've found my experience designing gearboxes for Boeing has applicability to software design. For example, the fundamental idea with airplane design is not to design components that cannot fail, as that is impossible. The idea is to design the system to be tolerant of failure . Every part in the system is not "how can we make this part never fail" but "assume it failed. How does the airplane survive?" This is a funda…

This is not really a helpful mnemonic -- security breaches are adversarial. Boeing airliners are not designed to keep flying to the intended destination if the cockpit is breached by hijackers.

Battleships and spy networks are about as adversarial as it gets. Even airliners give some consideration toward not being too easy to hijack or bring down. For instance the hardened cockpit doors added after 9/11.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#204
Just some thoughts, I can be wrong, and I probably have much less in-depth knowledge of the attack.

To call it the largest & most sophisticated ever seen sounds like ignoring some that others have mentioned here, and the fact that we don't know what others have not been publicized yet, including things like this (https://www.schneier.com/blog/archives/2021/02/chinese-suppl... where we don't know everything, there can be debate; but given means, motive, and opportunity, I think at least keeping our eyes open and attempting to adopt wise practices based on realistic trust levels and long-term track records, could be a good idea.

Plus I question the credibility of MS on security or anything they say, given their long track record, and when compared to others (like maybe OpenBSD), and things like this as just one very recent example: https://www.schneier.com/blog/archives/2021/02/on-vulnerabil... ...?

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#205
It's not the most sophisticated, thats a bad usage of terms, however, it is most likely one of the largest of it's type and severity just on pure scale.

My take is that this is mostly on the heads of all the many gov orgs (I'm ignoring corporate land right now), who have become so dominated by gui-ninjas with stockholm syndrome for MS and other black-box closed source systems that they honestly just don't think about the underlying system fundamentals at all. Not only have I contracted and seen some of these systems first hand (and the bad management that engineers them), but I have a family member is is the head of IT for a state gov org, and I've heard about how lackluster the response has been internally. There is just a response to update systems. No fundamental reconsideration of sourcing practices, no fundamental reconsideration of security practices, just lazy hope that it doesn't affect them. I highly suspect most of these orgs are completely compromised already on the tech side (and other ways too, cough Epstein cough), and because of lack of accountability, nobody really gives a fuck.

Then at the very high levels at the federal level, those "leaders" don't care because they are playing the classic good ol boy backscratching contract and bid game, and they get their cut, so they could care less that a few years down the road something like all of OPM is compromised. Congress, the one entity that should be in a position to start passing legislation to address these issues, is instead completely compromised on both sides of the isle by the same kind of realpolitik, where K-street writes the legislation along with a few staffers they will hire later for their "help", congresspeople don't even read the bills, but vote according to donation dollars and influence gained. The whole system is completely disconnected from reality, and the number one thing that is lacking is the largest four letter word in DC or in any government org...

Accountability.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#206
post #157

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

> These hypothetical scenarios are not anchored with the language that most businesses will understand: cost.

If a CEO or other high level management doesn't have a sense of how to answer those questions, they have no business running a company in the 21st century.

There are plenty of stories of ransomware literally holding a corporation's entire business hostage. Software security is an existential threat for pretty much every business these days.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#207
post #157

Earlier quoted context omitted.

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

> These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. I've argued this to well-placed people in two Fortune 250 companies. At the first place, the conversation led to a cleanup up the IT policies, so that they were more consistent and reasonable, but they still weren't grounded in reality. The reaction at the second place has caused me to realize that IT securit…

The hardest thing to come to grips with in security is that you are dealing with large(ish) groups of people.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#208

Earlier quoted context omitted.

> Most That's still focusing on making components that will not fail, rather than a system that can tolerate failure.

Why do we have pain receptors then ? Nature sux as designer ?

For the same reason you don't have a backup heart

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#209
post #157

Earlier quoted context omitted.

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

An aircraft carrier also has the benefit of being operated under a vastly different framework than a regular IT system: military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks. But I've seen plenty of companies implementing solid (real) security measures only to see employees looking to bypass them themselves due to the inconvenience they caused, thu…

> But I've seen plenty of companies implementing solid (real) security measures only to see employees looking to bypass them themselves due to the inconvenience they caused, thus leaving doors open for attack.

The New York Times had an article recently discussing how measures to prevent Covid have to take human nature into account in order to be effective. In other words, people only have so much capacity for adhering to strict measures, so it's important to stress the really important factors (avoid prolonged indoor exposure with large groups of people) and to allow for some relatively low risk behaviors (outdoor exercise with appropriate social distancing). Also cited HIV and teen pregnancy as similar public health problems (saying "don't have sex ever" vs "limit sex to these less risky behaviors").

So, coming back to security, I think any effective security policy will have to allow employees to get their work done efficiently without undue strain. Avoid "security theatre" while still mitigating against the most severe threats through training, compartmentalization, etc. Otherwise, you risk people going around the security measures so they can actually get their work done.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#210
post #61

Earlier quoted context omitted.

That would work if we knew how to ship secure software at something resembling the cadence the industry demands, but we do not. We pretend to, and we get away with it because there isn't toothy liability attached to shipping bugs. We are all here, the software people on this site, the beneficiaries of that system. Just very simple things, like reimplementing non-performance-sensitive C software from the 1990s and 200…

What if the government directly paid the cost of reimplementing that old c software? If the market is failing here as it seems to be then perhaps the government should step in.

government paid $55 mil to create a simple vaccination website which doesnt work. do you think government can pull this off?
Post reply on HN