The Story of the SolarWinds Hack
1–10 of 139 posts
Re: The Story of the SolarWinds Hack
#2Is there the rare case that we shouldn't update because the update could contain a malicious payload? If the update gets served over plaintext HTTP I would treat it as suspicious and may even block it from connecting at all. I run the risk of having outdated software, but that can be addressed by storing the software in a machine that's not connected to The Internet in any way, so it can't really do anything/talk to a C2 server (if someone does decide to execute an 0day with the software or inject malicious code via a rogue update).
Re: The Story of the SolarWinds Hack
#3Re: The Story of the SolarWinds Hack
#4There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated response back thanking him for his help and saying the problem had been fixed.
When NPR asked SolarWinds' vice president of security, Brown, about this, he said that the password "had nothing to do with this event at all, it was a password to a FTP site." An FTP site is what you use to transfer files over the Internet. He said the password was shared by an intern and it was "not an account that was linked to our active directory."
Re: The Story of the SolarWinds Hack
#5“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.
Re: The Story of the SolarWinds Hack
#6It’s nice how they equivocate over the ease of entry and their security policies: There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated…
Re: The Story of the SolarWinds Hack
#7“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.
Re: The Story of the SolarWinds Hack
#8* The presence of such software making it that much more easy to hijack your “computers”
* Please “Hacker News”, no more anti-Russian neocon propaganda. Who's really to blame is the idiot that put that configuration in, in the first place.
Re: The Story of the SolarWinds Hack
#9“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.
Clandestine I think. Immediate reaction steps to this from CISA were pretty unprecedented; a govt-wide unpluggening on a Sunday night of a specific vendor doesn’t happen a lot.
Re: The Story of the SolarWinds Hack
#10Earlier quoted context omitted.
Clandestine I think. Immediate reaction steps to this from CISA were pretty unprecedented; a govt-wide unpluggening on a Sunday night of a specific vendor doesn’t happen a lot.
We can compare and contrast with the effects of NotPetya, which caused widespread obvious economic damage (e.g. Maersk shipping and Merck losses) - due to the number of affected companies, Solarwinds had the potential to be worse, but I'm not sure if you can be more destructive than that without it being obviously visible.
I don't know if it the damage was greater than NotPetya but you definitely can have something more destructive without it being immediately apparent. If you lose credit card numbers and PII from your customers you HAVE to report it to the public but there are different rules for the loss of incredibly valuable intellectual property.