Live data from Hacker News

The Story of the SolarWinds Hack

npr.org

31–40 of 139 posts

Re: The Story of the SolarWinds Hack

#31

Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195

Is there something about that available in a serious form? (not a movie, especially Youtube movie)

edit: The topic level link in the youtube description sends you straight to the list of documentation...

1. http://en.wikipedia.org/wiki/Ptech

2. https://archive.org/details/GunsNButterIndiraSinghPtechAndTh...

3. http://masshightech.bizjournals.com/masshightech/stories/200...

4. http://archive.is/RuleH

5. http://web.archive.org/web/20080905224929/http://www.theamer...

6. http://web.archive.org/web/20080820045652/http://www.total91...

7. http://web.archive.org/web/20080515202659/http://www.judicia...

8. http://web.archive.org/web/20081015113454/http://911citizens...

9. http://web.archive.org/web/20080915185702/http://counterterr...

10. http://rememberingmichael.wordpress.com/2008/03/20/in-memory...

11. http://www.abovetopsecret.com/forum/thread183761/pg1

Re: The Story of the SolarWinds Hack

#32

Earlier quoted context omitted.

Is there something about that available in a serious form? (not a movie, especially Youtube movie)

edit: The topic level link in the youtube description sends you straight to the list of documentation... 1. http://en.wikipedia.org/wiki/Ptech 2. https://archive.org/details/GunsNButterIndiraSinghPtechAndTh... 3. http://masshightech.bizjournals.com/masshightech/stories/200... 4. http://archive.is/RuleH 5. http://web.archive.org/web/20080905224929/http://www.theamer... 6. http://web.archive.org/web/20080820045652/http…

> hand-hold on an important topic

I assume that things available only as youtube video, unavailable in a text form are unimportant.

(not all things in text form are important, but it is a nice filter that basically always works)

Re: The Story of the SolarWinds Hack

#33

Earlier quoted context omitted.

edit: The topic level link in the youtube description sends you straight to the list of documentation... 1. http://en.wikipedia.org/wiki/Ptech 2. https://archive.org/details/GunsNButterIndiraSinghPtechAndTh... 3. http://masshightech.bizjournals.com/masshightech/stories/200... 4. http://archive.is/RuleH 5. http://web.archive.org/web/20080905224929/http://www.theamer... 6. http://web.archive.org/web/20080820045652/http…

> hand-hold on an important topic I assume that things available only as youtube video, unavailable in a text form are unimportant. (not all things in text form are important, but it is a nice filter that basically always works)

I think that is a very limited and closed mindset that inherently precludes a lot of first hand source information.

something about leading a horse to water I suppose

Re: The Story of the SolarWinds Hack

#34
post #14

How fortuitous is it that a months long investigation can be published right when the US announces sanctions? Great job National Radio! Like razor blades in peanut butter cups , says CrowdStrike.

> By design, the hack appeared to work only under very specific circumstances. Its victims had to download the tainted update and then actually deploy it. That was the first condition. The second was that their compromised networks needed to be connected to the Internet, so the hackers could communicate with their servers.

Yea, wow, thanks NPR. Hard hitting stuff right there. Those are “very specific circumstances” that just happen to generally apply to a huge percentage of hacks.

I normally appreciate some stories on NPR, but you’re right. This is a narrative piece.

Re: The Story of the SolarWinds Hack

#35
post #28

I agree with the parallels with aviation regulation, there needs to be something forcing a supplier's hand to solve this. The way to protect against supply chain attacks is to invest in a security-hardened build system (eg don't build releases on dev workstations, do them on build farms by build software that is the only thing able to access the release signing keys). This costs too much for most companies, so if the…

> do them on build farms by build software that is the only thing able to access the release signing keys

You're aware that this is exactly what solarwinds did, right?

Re: The Story of the SolarWinds Hack

#36

Let me introduce you to PTECH and see if you still think Solarwinds was worse. Warning, a conspiracy rabbit hole lies this way, proceed with caution, lest your view of the world be challenged. A start: https://www.youtube.com/watch?v=UuZRMpt_Tas&t=195

Is there something about that available in a serious form? (not a movie, especially Youtube movie)

> Is there something about that available in a serious form? (not a movie, especially Youtube movie)

Wall Street Journal:

https://www.wsj.com/articles/SB1039184086357188113

Wikipedia:

https://en.wikipedia.org/wiki/Ptech

Re: The Story of the SolarWinds Hack

#37
> But as CrowdStrike's decryption program chewed its way through the zeroes and ones, Meyers' heart sank. The crime scene was a bust. It had been wiped down

That's a lot of words to say, we don't know who did it. I had a quick look but couldn't find anything, why are the fingers being pointed at Russia?

Re: The Story of the SolarWinds Hack

#38

“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.

The worst nightmare of the vice president of security at SolarWinds, not of the average person.

An attack directed at your own govt is potentially a nightmare for the average individual. If the wrong information is stolen it could be used much farther down the road. Your govt may find itself at a disadvantage at a critical moment.

I'm a sense it's only not a nightmare if you aren't paying attention.

Re: The Story of the SolarWinds Hack

#39

“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.

The Biden administration just announced sanctions against the Russian government for their (presumed) responsibility for the SolarWinds attack. They're not shrugging this one off.

https://www.theverge.com/2021/4/15/22385371/russia-sanctions...

(Which is itself a bit odd. The US has argued in other contexts for "cyber norms" which would allow pure espionage operations, but put more restrictions on attacks. And so far as anyone can tell so far, SolarWinds was a pure espionage operation -- using tools that could be repurposed to do something else, but you could say that about a lot of operations in this sphere, including US operations that our government wants everyone else to shrug off. Yet here are the sanctions. I expect the "norms" push, to the extent that the current administration still wants to pursue it, will take some kind of a hit...)

Re: The Story of the SolarWinds Hack

#40
post #28

I agree with the parallels with aviation regulation, there needs to be something forcing a supplier's hand to solve this. The way to protect against supply chain attacks is to invest in a security-hardened build system (eg don't build releases on dev workstations, do them on build farms by build software that is the only thing able to access the release signing keys). This costs too much for most companies, so if the…

> do them on build farms by build software that is the only thing able to access the release signing keys You're aware that this is exactly what solarwinds did, right?

Well and then harden that obv
Post reply on HN