The best backdoors are those, which are never found.
The Story of the SolarWinds Hack
21–30 of 139 posts
Re: The Story of the SolarWinds Hack
#22Re: The Story of the SolarWinds Hack
#23Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195
Re: The Story of the SolarWinds Hack
#24I‘m quite sure there are a lot of attacks like that. Most of them just never get noticed. The best backdoors are those, which are never found.
Re: The Story of the SolarWinds Hack
#25Re: The Story of the SolarWinds Hack
#26Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195
Re: The Story of the SolarWinds Hack
#27It’s nice how they equivocate over the ease of entry and their security policies: There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated…
How a Vp security can ignore a privesc risk like that is pretty inexcusable. Ever vuln falls on a risk mgmt spectrum but that’s a really nonsense answer to give. Weak PW mgmt on a FTP server that you let interns set should raise some areas of interest.
Re: The Story of the SolarWinds Hack
#28Re: The Story of the SolarWinds Hack
#29I‘m quite sure there are a lot of attacks like that. Most of them just never get noticed. The best backdoors are those, which are never found.
https://blog.thinkst.com/p/if-nsa-has-been-hacking-everythin...
Re: The Story of the SolarWinds Hack
#30To me the "worst nightmare" was a story in the NYT about a hypothetical concerted attack against healthcare infrastructure, transit and more. Sadly I can't seem to find the link but it was a few years ago...
https://www.nytimes.com/2020/12/03/us/politics/vaccine-cyber...
That's from December. Still going on.
https://www.reuters.com/article/us-health-coronavirus-vaccin...