Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

221–230 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#221

Earlier quoted context omitted.

It's always a tradeoff between how much to spend on security vs how much a breach is going to cost you. But if you are going to spend it on security, spend it on things that are more likely to work, rather than on impossible things.

From a risk perspective you're advocating bundling all of your eggs in one basket - perfect fault-tolerance & prevention - whilst that is actually a system nobody has built in the history of computing. Neither detection or prevention can be perfect like nothing human-designed, but rather detection should be used to hedge yourself in situations where prevention fails.

It seems to me that they are doing the exact opposite of what you claim they are doing.

None of the mitigations that were described were aimed at preventing a breach or disaster. Instead all were designed to mitigate the damage that happens when a breach occurs.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#222
post #208

Earlier quoted context omitted.

Why do we have pain receptors then ? Nature sux as designer ?

For the same reason you don't have a backup heart

You actually do have organ backups.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#223

I've found my experience designing gearboxes for Boeing has applicability to software design. For example, the fundamental idea with airplane design is not to design components that cannot fail, as that is impossible. The idea is to design the system to be tolerant of failure . Every part in the system is not "how can we make this part never fail" but "assume it failed. How does the airplane survive?" This is a funda…

Yes, that is the correct way to approach security. Preventive measures alone are not enough to secure an organization.

In the security world we refer to this concept as "Assume Breach" and to throw in a buzz word you might hear often these days "Zero Trust".

Joking aside, Assume Breach, Zero Trust and what I call "Homefield Advantage" are the main strategies to help secure the modern workplace in my opinion.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#224

Earlier quoted context omitted.

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

Suggesting stuxnet's goal wasn't stealth is silly. It was so sophisticated at not being detected that it went under everyone's radar for 5+ years. Stuxnet behaved in exactly the same way.. neither did anything that would be detectable unless certain criteria was met and a secondary payload sent.

I would say that the sophistication of the Solarwinds breach is in the success of its scale, as opposed to the methods with which it used to successfully reached such scale.

Stuxnet was very sophisticated to hit a relatively narrow target by comparison.

So I think they are both sophisticated, but not comparing them directly.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#225
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

An attack has multiple stages. Stuxenet's attack formula was: inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment Solarwinds attack forumla seems to be: compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT). Because the initial compromise (oh a bad passwo…

>silently exfiltrate useful data/create an advanced persistent threat

The chinese successfully pulled this off at Lockheed in the early 2000s

They would get lists of employees who attended various conferences, then email them a trojan saying "hey we met at conference X - here is something for you to click on"

And employees would fall for it.

The malware would TRICKLE out data very slowly so as not to be noticed.

They did this for a LONG time.

At the time, lockheed only had 3 egress points to the internet - and they had 110,000 laptops.

Another attack vector was the same as stuxnet - airgap; attack a supplier in taiwan, infect any USB stick put into the suppliers machines, then transfer once that USB stick was put into the Lockheed machine.

When the ruse was discovered - the chinese removed the throttle and they attempted to firehose out as much data as they could before they were cut off.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#226
post #142

Earlier quoted context omitted.

what are some right answers?

I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…

I'm always curious about solutions to 2, so what does unfettered mean in this instance? Audited? Someone always needs root or Domain Admin or whatever to get the company out of a mess, so do we just heavily audit those accounts and hope they aren't a enemy agent from Pepsi trying to get our secret formula?

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#227

Earlier quoted context omitted.

From a risk perspective you're advocating bundling all of your eggs in one basket - perfect fault-tolerance & prevention - whilst that is actually a system nobody has built in the history of computing. Neither detection or prevention can be perfect like nothing human-designed, but rather detection should be used to hedge yourself in situations where prevention fails.

It seems to me that they are doing the exact opposite of what you claim they are doing. None of the mitigations that were described were aimed at preventing a breach or disaster. Instead all were designed to mitigate the damage that happens when a breach occurs.

I'm not sure what you're referring to, but my comment is to the person advocating fault-tolerant systems, segmentation and the other things as panaceas to the situation.

These are not new concepts in the security industry. In fact very much of the opposite; manifestations of them like zero trust have been one of the main buzzwords for the last ten years or so in the cyber industry.

It's a different thing sketching something on paper and how it actually works when trying to apply it into the chaotic mass corporate IT usually is. I work in this industry and talk to a lot of corporations from all over the globe about their security postures. I don't see a huge amount of companies who have the resource to pull off a well segmented environment. Truth is it is expensive, quite complex to pull off, potentially disrupts business and it's still just an internal security cost that when you present it to your boss they will ask "why are we spending all that money on firewalls then?"

Anyhow the point was that if you build your security posture on the assumption that you can successfully lock everything down and you don't need to do any monitoring internally, you're setting yourself up for that massive disruption when the stars align for the attacker and they get a free roam environment in your internals. And it happens very often, as we can see.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#228
post #11

I guess nobody gets pwned by high school kids just screwing around anymore. Every hack is now the "most sophisticated ever" by the "most technologically advanced state actor ever" to break the "most secure six-character password ever."

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

This is the case of the cobbler's children having no shoes, I think. If you're focused on your product, updating your website falls to the last priority (except for the marketing team).

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#229
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

An attack has multiple stages. Stuxenet's attack formula was: inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment Solarwinds attack forumla seems to be: compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT). Because the initial compromise (oh a bad passwo…

There is no comparison.

Stuxnet "worked by first causing an infected Iranian IR-1 centrifuge to increase from its normal operating speed of 1,064 hertz to 1,410 hertz for 15 minutes before returning to its normal frequency. Twenty-seven days later, the worm went back into action, slowing the infected centrifuges down to a few hundred hertz for a full 50 minutes. The stresses from the excessive, then slower, speeds caused the aluminium centrifugal tubes to expand, often forcing parts of the centrifuges into sufficient contact with each other to destroy the machine."

The solar winds hack is an otherwise unremarkable trojan that spread exclusively due to the bad security measures of solarwinds.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#230

Earlier quoted context omitted.

It seems to me that they are doing the exact opposite of what you claim they are doing. None of the mitigations that were described were aimed at preventing a breach or disaster. Instead all were designed to mitigate the damage that happens when a breach occurs.

I'm not sure what you're referring to, but my comment is to the person advocating fault-tolerant systems, segmentation and the other things as panaceas to the situation. These are not new concepts in the security industry. In fact very much of the opposite; manifestations of them like zero trust have been one of the main buzzwords for the last ten years or so in the cyber industry. It's a different thing sketching so…

Very nicely put. Can't agree more.
Post reply on HN