Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

281–290 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#281
post #40

Earlier quoted context omitted.

The whole weak password thing was simply a funnily timed thing some guy found. It had absolutely nothing to do with the malicious update, which was the source of this supply chain attack. For some reason a bunch of people online decided that two things happening around the same time means they are related. They are not

No, “a bunch of people online” decided that if you have jarring security practices in one avenue, it’s totally unsurprising if it turns out that you have other doors wide open too. Which is a completely reasonable assumption.

It can definitely be said that this may be an indicator of a larger security issue at the company. But assuming that issue is the cause for the backdoor, yes that is a leap, and an unfounded one. Correlation != Causation, and it's always unreasonable to assume otherwise.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#282

Earlier quoted context omitted.

You can expect single detection system to fail, so you need to make it redundant. For example impossibly loud siren. Like you said before, any solution is a mix of 2 paradigms.

Another method of defeating a sophisticated burglar alarm system is taking an axe to the power cable to the building. How many people have a battery hooked up to the siren?

Pretty much every residential system and every commercial system has a battery backup.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#283
post #157

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

Fantastic answer.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#284

Earlier quoted context omitted.

depends on which part of the world you are, military grade can mean different things. I would not be surprised to find hair saloons with better security practices than our military.

Hair saloon, must be a Texas thing.

na, it a Balkan thing :)

Pretty sure texans would not like to be caled balkans, even though balkan culture is somewhat similar to texan

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#285

Earlier quoted context omitted.

4. install sprinklers (!) Yes, water based sprinklers are not the best choice for inside the server-room proper. But that doesn't mean you can't have other automated fire suppression systems. In the days of yore Halon systems were mostly used for this particular application. Halon has some issues though and has mostly been banned / replaced with cleaner alternatives. These days you see things like FM-200 used for fir…

I totally am sold on fire sprinklers. They're installed in my house. Yeah, they'll wreck the room they come on in, but will save the rest of the house. I also read that, in the US, nobody ever died from fire in a building where there were sprinklers that were not disabled. Even counting 9-11, as the plane crash cut the water pipes. But still, relying on sprinklers to save your IT business is a bad idea. Offsite backu…

But still, relying on sprinklers to save your IT business is a bad idea. Offsite backups are needed.

Yep, totally agreed. Resiliency comes from having offsite backups, cold/warm standby sites, testing your backups and ability to switch to the DR site, etc. The sprinklers are mainly about saving human lives.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#286

Earlier quoted context omitted.

Yeah I mean this is called Zero Trust Architecture/defense in depth, and it's a popular thing. The budget and architecture changes are not popular, though. I partially blame this the security community as well (of which I'm a part of). The common tendency to think exclusively in risk controls and absolutist statements on secure vs. insecure means the incremental improvements needed to hit eventual ZTA are difficult t…

> In short, security teams suck at intra-company sales sometimes. I've been at this a long time. My POV is that this is true, but doesn't matter. The leadership almost never actually cares about security. It's the correct choice for most orgs. https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr... Even the most impacted companies only take a hit in the medium term (1 yr) at best. https://investorplace.com/20…

You make a good point.

I think there are two levels of security sales, if you will. One is junior//mid level to junior//mid level, and one is CISOCIO, and they both handle different pushes that play their own, sort of non-overlapping role in company risk management.

The CISOCIO thing falls right into the bucket that you're mentioning... big architectural changes need much more going for them than good salesmanship from security. If there's not a major benefit for the enterprise in non-sec areas by doing changes like ZTA, or a lot of precedent at this point about a SIEM/SOC just being something one has, it's an uphill battle.

That said, a lot of these breaches, like the Equifax admin:admin, isn't so much a "for the stock price, this is a net positive we'll run the risk for" type of decision that security loses. A lot of this is just patiently needling/selling to dev and IT teams about finally rotating a pw to something complex, for instance. That happens successfully.... attackers try another IP door on the internet and perhaps Equifax doesn't happen (using the theory that Equifax wasn't from an APT, which is of course a different situation). Of course insane change management boards exist, but in many cases it's just that easy of a fix.

My theory is even more relevant when you look at SaaS vendors, like SolarWinds, as really driving govt's innovation edge and by extension being the vector into the environments. In those cases, the security team's political capital is even stronger, as smaller companies mean much more cross-org influence is possible. Sometimes, it's just flipping "min pw complexity" as a radio button in AWS's IAM console, and no one is the wiser. When so many attacks source to these very easy wins to fix, that's where the salesmanship is lacking (or can really help) for sec.

To your point about "12 months and everyone forgets," that's not the case for the SaaS vendors working in a crowded space providing generic products. While the pool of possible vendors is shrunk by like how many SaaS vendors bother to pass FEDRAMP, and/or you stack on contractual inertia, there is still a pool. SolarWinds doesn't really provide that exceptionally unique of a product, and they got the entire Fed Govt pwned. That'll be >12 month impact for them. If it's not, I owe you a beer. This is even more pronounced of a motivator across the legion of SaaS vendors who have their first handful of serious clients, but a sec incident w/o a seriously embedded platform blows them up.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#287
post #265

Earlier quoted context omitted.

I would say that the sophistication of the Solarwinds breach is in the success of its scale, as opposed to the methods with which it used to successfully reached such scale. Stuxnet was very sophisticated to hit a relatively narrow target by comparison. So I think they are both sophisticated, but not comparing them directly.

Stuxnet infected close to 200,000 machines, over half in Iran, before being detected. It was so extremely stealthy and well designed that it could spread widely and avoid detection while making its way to the intended targets.

I didn't know that part - that incredible.

I would love to know how many machines got hit by SOlarwinds - however, its not about the machines - its about the value of the data it slurped... So even if it was one exchange server, with 10,000 treasury/nsa/whatever accounts, that one machines intel value is quite high.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#288

Earlier quoted context omitted.

> In short, security teams suck at intra-company sales sometimes. I've been at this a long time. My POV is that this is true, but doesn't matter. The leadership almost never actually cares about security. It's the correct choice for most orgs. https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr... Even the most impacted companies only take a hit in the medium term (1 yr) at best. https://investorplace.com/20…

You make a good point. I think there are two levels of security sales, if you will. One is junior//mid level to junior//mid level, and one is CISO CIO, and they both handle different pushes that play their own, sort of non-overlapping role in company risk management. The CISO CIO thing falls right into the bucket that you're mentioning... big architectural changes need much more going for them than good salesmanship…

Look, you're talking about the exceptions. I'm talking about the rule. We are in violent agreement! A friendly kind of violent. :)

> flipping "min pw complexity"

I couldn't disagree more about this, but that's a particular sore point of mine. Otherwise, yeah, cloud services in general give you abilities like this. I mean, so does on-prem -- AD DS has the same (actually, far far far better) switch, but cloud is where the action is.

> selling to dev and IT teams about finally rotating a pw to something complex [...] just that easy of a fix.

Yes, and that isn't selling failure so much as security incompetence from the top. If you have a solid core, it's easy to throw switches when you see a blemish on the surface. If the core is rotten, that surface defect is not going away, even if you do catch it and even if you do fix it! The security team is only as good as the leadership.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#289
post #268

Earlier quoted context omitted.

So when you don't know the difference between two things you assume there is no difference and not only disregard those better informed than you who claim otherwise, but try to tell them how simple their profession is? Neither the tv mounts nor the testing machine were remotely close to statics class. For the seismic TV mounts, I had to make an economical laser cut sheet metal assembly which could be assembled in a f…

> So when you don't know the difference between two things you assume there is no difference and not only disregard those better informed than you who claim otherwise, but try to tell them how simple their profession is? Are you really snapping at me rudely over a disagreement about the differences between engineering and programming? To answer your question, no. I'm saying that it's the same technical domain. > Yes,…

> To answer your question, no. I'm saying that it's the same technical domain.

And I am saying that these things are radically different, and thus the only way you could classify them as the same technical domain is if you are ignorant of those differences, or define domain so broadly that everything affected by physics is the same domain. You specifically refer to engineers remaining in a narrow domain and specifically gave an example of bridges and transmission lines as distinct domains, and it would be oxymoronic to talk about a narrow broad domain. You not only admitted that you have no idea what you're talking about, you used the fact that you were ignorant as evidence in support of your claim.

Going back to the example, both things employ statics. Statics is the most basic tool of engineering - it is the analysis of forces on something which isn't accelerating. There is no way to completely avoid statics for anything that physically exists. Statics is to engineering as wood is to carpenters. It is equally absurd to say that two engineering tasks are in the same domain because they both use statics as it is that two carpentry tasks are in the same domain because they both involve wood. The engineers designing bridges and transmission lines both employ statics, as do those designing kidney dialysis filters and rocket engine combustion chambers and acoustic panels and laser cutters, all six of which could very well be done by the same engineer (I've personally been employed to do five of the above so far in my career).

Your original claim, which I argued against, was:

> The engineer generally stays with a set of fundamental domain principles their entire career (e.g. sticks with bridges as opposed to transmission lines) while programmers tend to stay at the top layers while the technologies below the surface change radically.

Your argument had nothing to do with the difference between principles rooted in physics vs mathematics. You were saying that programmers use high level, general abstractions while engineers make more limited use of abstractions and remain highly specialized. I am saying that engineers work on a wide variety of problems over their careers, involving radically different physical principles, and that they abstract away many of the details of these various narrow domains so that they can work on the top level.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#290
post #252

Earlier quoted context omitted.

If you have a second heart, please report to area 51 immediately

That would be Krogan, not me. There are animals with multiple hearts. People can be made to have 2 hearts too, but let me not go into that. But we have bunch of non-heart redundancy.

Yeah, if you ignore the various single points of failure in our circulatory, digestive and nervous systems there are plenty of redundancies.

There is no intelligence behind our design. Your body takes its current form because no mutation which would change it has yet led to a statistically greater chance of you passing on your genes. That nature designed you to have pain receptors is no more an argument for their utility than it is for the peacock's feathers.

Post reply on HN