Live data from Hacker News

The Story of the SolarWinds Hack

npr.org

81–90 of 139 posts

Re: The Story of the SolarWinds Hack

#81
post #71

Earlier quoted context omitted.

Yes, let's assassinate a world leader of the country with the most nukes in the world based on unfounded claims of election interference and a hack. Do you have any idea what America did in Russia in the immediate aftermath of the fall of the Soviet Union? The 1996 election in Russia which was majorly "interfered" with by Clinton: https://archive.is/R7i5u , not to mention the fact that most Russian hacking activities…

Your cited article is interesting but does not support your assertion of major interference IMO. Policy maneuvers for political purposes are the norm for all countries right or wrong.

Really? A government saying that they would ensure no "negative stories would come out", literally puppetting international institutions to pay out money - billions - for an election campaign, sent US Government agents to be embedded into the Yeltsin campaign right as he was violating every law on the books and calling in favours from the mafia and oligarchs, and very likely also used intelligence agencies to help, all of that isn't major interference?

But targeted ads are?

Re: The Story of the SolarWinds Hack

#83

> But as CrowdStrike's decryption program chewed its way through the zeroes and ones, Meyers' heart sank. The crime scene was a bust. It had been wiped down That's a lot of words to say, we don't know who did it. I had a quick look but couldn't find anything, why are the fingers being pointed at Russia?

There has been considerable coverage of this attribution: https://ciexinc.com/blog/solarwinds-articles/attribution.htm...

Re: The Story of the SolarWinds Hack

#84

Anyone know how the software update was actually compromised in the first place?

This has been a puzzle for a while, and I am not yet satisfied with the answer so far. The closest to an explanation is found here: https://ciexinc.com/blog/solarwinds-articles/initial.html.

I feel like this says "well, we are not really sure".

Re: The Story of the SolarWinds Hack

#85

This article is a case of [a lot of] Monday morning quarterback[s]. Except for Mandia, I wouldn't allow any other exec(s) to speak about this, publicly, as to the why and how. Side note: I bet Bejtlich wishes he was still in that team ;-)

The best set of articles in my opinion are these: https://ciexinc.com/blog/solarwinds-articles/zetter.html

Re: The Story of the SolarWinds Hack

#86

How much value SolarWinds shareholders have lost because of this? If it is not number one incentive for investors to fix, then there won’t be change in business practices. This is why GDPR in the EU has (some) teeth.

There is a lot of legal action about this. It isn't clear that the stock is long term affected: https://ciexinc.com/blog/solarwinds-articles/stock.html

Re: The Story of the SolarWinds Hack

#87

“A ‘Worst Nightmare’ cyberattack” that we all... just take in stride? Either the consequences are themselves clandestine, or cyberattacks aren’t as meaningful as our headlines would indicate.

The worst nightmare of the vice president of security at SolarWinds, not of the average person.

Unclear to me how worried he is. See https://www.turn-keytechnologies.com/blog/article/solarwinds... and other articles at https://ciexinc.com/blog/solarwinds-articles/culture.html.

Re: The Story of the SolarWinds Hack

#89
post #80

This is the line that got me: >And so we are fairly broadly deployed software and where we enjoy administrative privileges in customer environments. There is a lot of talk about shoring up security practices by many of the people quoted here. But something that would be hard to admit is that maybe they should not have administrative privileges in customer environments. Maybe they should not install agents on your mac…

And you would think that a bit of analysis would be done on software and the company that built it for something that you install and give it full administrative control.

Re: The Story of the SolarWinds Hack

#90
post #62

"The tradecraft was phenomenal" Indeed, consider Figure 5 here [1]. A truly diabolical mastermind. But seriously, the article looks like window dressing for common incompetence. [1] https://www.microsoft.com/security/blog/2020/12/18/analyzing...

A common way to dodge accountability is to exaggerate the size of the enemy and his cleverness and goodness he had 1000 developers working on it.

Nonetheless, there are some things that are kind of impressive. Inserting their own code into the build process without touching any file.

But the real level of skill, I think, is the operational discipline exercised by the attackers. For example, waiting two weeks before doing anything, erasing traces of what they did, and targeting very specific sites.

Post reply on HN