Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

291–294 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#291
post #289

Earlier quoted context omitted.

> So when you don't know the difference between two things you assume there is no difference and not only disregard those better informed than you who claim otherwise, but try to tell them how simple their profession is? Are you really snapping at me rudely over a disagreement about the differences between engineering and programming? To answer your question, no. I'm saying that it's the same technical domain. > Yes,…

> To answer your question, no. I'm saying that it's the same technical domain. And I am saying that these things are radically different, and thus the only way you could classify them as the same technical domain is if you are ignorant of those differences, or define domain so broadly that everything affected by physics is the same domain. You specifically refer to engineers remaining in a narrow domain and specifica…

> Your argument had nothing to do with the difference between principles rooted in physics vs mathematics.

True. Where did mathematics come in? Math does not abstract away the fundamentals in the way that I am talking about. Whether you use messy coordinates or elegant tensors to describe a fundamental property, you are still working with the fundamental property.

Also perhaps the only way to get through to someone like you is to point out I have a doctorate in electrical engineering, and teach in a EECS department, working with both engineers and programmers daily and even helping to design the curricula (fyi, a person who specializes in databases is a real thing, we have no less than 4 grad-level classes on them, and there are no CS classes entirely on "variables" analogous to classes on statics). I have spent literally decades pondering the mindset differences between them. You should give up trying to argue me down because you won't get there by trying to twist my own words against me.

Oh and in EE we generally don't use statics. Pretty much ever. Though I did teach a dynamics class that included some one time. By the way that tongue-in-cheek reference to statics was an failed attempt at using self-deprecation to tiptoe around your oversized ego. Nice job weaponizing it.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#292
post #241
post #81

Earlier quoted context omitted.

Years ago, the company I worked at had a very big production issue which resulted in a customer's database being deleted. Of course, the customer was furious and called the CEO asking for the person responsible to be fired. Calmly, our CEO said: 'No. If there's anyone in this company who will never make that mistake again it's him.'

I've seen this sort of Zen of CEO type story a lot but it doesn't match up with reality. Someone that deletes a production DB by being careless or reckless is likely to do something similar again. Perhaps not in the exact same way, but there's infinite ways to break things. Those that stumble upon one are likely to stumble upon another.

In that case everyone making 1 mistake is 'out'. Seems "cancel culture" is leaking into ops...

I was in the room when the CEO told that (one of the nice things about small companies) and have had contact with the person responsible for a few years until he got another job. True story ;)

There were changes though: the 'two pair of eyes' principle was enforced a lot stricter from then on.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#293

Earlier quoted context omitted.

Seems that a lot of these attacks (except for this one) are just simple social engineering: an employee is phished to get into the company VPN, and from there, it's maybe a couple more simple exploits on systems that were never meant to be exposed and then it's over. You can compartmentalize employees but it's harder to do than compartmentalizing software I think.

I think that's part of what security people mean by "zero-trust security". Instead of building a giant moat and assuming that everyone who got past the moat is trusted, assume that everyone is untrusted by default, and build a capability system that's expressive enough that you can give everyone just enough capabilities that they can do their job without going through a bunch of pointless checks. In practice that mod…

Yeah, honestly, I hate the truth that this compartment-based system is the best method for security. I never have the access to do my job, and it's a constant frustration to get access. Also, it makes for really uninteresting problems to solve. Instead of using something interesting to secure our systems, like cryptography, the most effective method is just phishing tests, employee training, and web form fuzzing. Cryptographic innovation is part of the solution, but at a certain business level, it's just about training.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#294

Earlier quoted context omitted.

You make a good point. I think there are two levels of security sales, if you will. One is junior//mid level to junior//mid level, and one is CISO CIO, and they both handle different pushes that play their own, sort of non-overlapping role in company risk management. The CISO CIO thing falls right into the bucket that you're mentioning... big architectural changes need much more going for them than good salesmanship…

Look, you're talking about the exceptions. I'm talking about the rule. We are in violent agreement! A friendly kind of violent. :) > flipping "min pw complexity" I couldn't disagree more about this, but that's a particular sore point of mine. Otherwise, yeah, cloud services in general give you abilities like this. I mean, so does on-prem -- AD DS has the same (actually, far far far better) switch, but cloud is where…

Late, but I actually think more accurately we're talking about doing sec at > 200 headcount companies, vs I firmly agree with what you're saying, violently agree perhaps! But I think the scope of a smaller SaaS company means the sec team has an amount of technical and people agency that's sort of unheard of at the bulk of companies.

That's true, that's perhaps "exceptions," but a not unimportant amount of SaaS vendors are at that headcount/company profile .

Post reply on HN