Live data from Hacker News

The Story of the SolarWinds Hack

npr.org

21–30 of 139 posts

Re: The Story of the SolarWinds Hack

#22
How much value SolarWinds shareholders have lost because of this? If it is not number one incentive for investors to fix, then there won’t be change in business practices. This is why GDPR in the EU has (some) teeth.

Re: The Story of the SolarWinds Hack

#23

Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195

Given that audio and video are much less likely than written works to include references and are harder to reference themselves, I think they are poor evidence of anything contentions such as a conspiracy theory.

Re: The Story of the SolarWinds Hack

#24
post #21

I‘m quite sure there are a lot of attacks like that. Most of them just never get noticed. The best backdoors are those, which are never found.

Like, say, that backdoor someone wrote an article about recently which ran from RAM and had a sophisticated self-destruct mechanism that erased all traces if anyone tried to dump its memory? I wonder how many companies had exploits like that which they either didn't notice or didn't have the sophistication to actually catch and dump.

Re: The Story of the SolarWinds Hack

#26

Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195

Is there something about that available in a serious form? (not a movie, especially Youtube movie)

Re: The Story of the SolarWinds Hack

#27
post #4

It’s nice how they equivocate over the ease of entry and their security policies: There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated…

How a Vp security can ignore a privesc risk like that is pretty inexcusable. Ever vuln falls on a risk mgmt spectrum but that’s a really nonsense answer to give. Weak PW mgmt on a FTP server that you let interns set should raise some areas of interest.

I don't think they ignored it? Says it was addressed. I think it was OK to dispel the implication that the elaborate supply chain attack was allowed in the first place by sloppy pw practices. You don't want that to be the takeaway and then other companies thinking, well our pw management practice is really good so we don't have to worry about being a victim so much

Re: The Story of the SolarWinds Hack

#28
I agree with the parallels with aviation regulation, there needs to be something forcing a supplier's hand to solve this. The way to protect against supply chain attacks is to invest in a security-hardened build system (eg don't build releases on dev workstations, do them on build farms by build software that is the only thing able to access the release signing keys). This costs too much for most companies, so if they don't have the obligation to build it, they'll do features instead.

Re: The Story of the SolarWinds Hack

#29
post #21

I‘m quite sure there are a lot of attacks like that. Most of them just never get noticed. The best backdoors are those, which are never found.

Here's an excellent article on the topic, this is a huge uproar on an everyday occurrence.

https://blog.thinkst.com/p/if-nsa-has-been-hacking-everythin...

Re: The Story of the SolarWinds Hack

#30

To me the "worst nightmare" was a story in the NYT about a hypothetical concerted attack against healthcare infrastructure, transit and more. Sadly I can't seem to find the link but it was a few years ago...

Not so hypothetical.

https://www.nytimes.com/2020/12/03/us/politics/vaccine-cyber...

That's from December. Still going on.

https://www.reuters.com/article/us-health-coronavirus-vaccin...

Post reply on HN