Live data from Hacker News

The Story of the SolarWinds Hack

npr.org

91–100 of 139 posts

Re: The Story of the SolarWinds Hack

#91
post #66

Earlier quoted context omitted.

Which they did. The problem of hardening your build infrastructure against someone who has admin access for months is... non-trivial. This boils down to the question of should average companies be including the Russian intelligence services in their threat model? To paraphrase James Mickens great USENIX paper, if your threat model includes the SVR, you're going to be SVR'd upon.

First, you do not need to be the Russian intelligence services to pull off this attack. Given prevailing trends in the vulnerabilities market this sort of attack would cost at most $1M to pull of which puts it within the capabilities of maybe ~50,000,000 individuals worldwide let alone organizations. If the SVR is anything like the CIA they are probably running at least 1,000 programs of similar scale simultaneously,…

I'm not convinced about the arguments of cost. There are a whole lot of presumptions in that chain of reasoning. The initial vector seems to not require any high-prices vulnerabilities, but simple authorization by pass, e.g., bypassing 2FA. Which could well have been a root account. From there, get the keys that Duo depends on, then you own the whole thing.

I have always argued that doing what I call "defense by presumed motive". The logic would have been "ok, UNC2452 wants to access DHS hacker's email. I'll go after SolarWinds". Better spend your energy on basic security principles.

Re: The Story of the SolarWinds Hack

#92
post #72
post #55

Network monitoring software is a key part of the backroom operations we never see. [...] By its very nature, it touches everything — which is why hacking it was genius. This is frustrating to read, since plenty of people did in fact warn that these kinds of systems were easy targets.

I was just playing with Grafana a few days ago, their cloud version. When you install agent, it opens up ports with unprotected metrics on a public IP. Opens up ports on your production without info about it whatsoever, because it is in theory a push agent. Why would you do that? Support response: "Regarding your second message about port 12345 on the Grafana Agent -- the HTTP server only exposes the Agent's internal…

Not sure what your comment about docker containers is trying to say. In docker you need to specify port mappings before ports are exposed outside the container, so this wouldn't happen without you explicitly knowing. Containers are by default untrusted and access to network and filesystem is mediated. In fact, if you linked to a docker container I'd have less qualms running than a binary.

Re: The Story of the SolarWinds Hack

#93

The article vaguely describes the build system being compromised. Have any details been published to indicate what build systems they were running and what the exploits were there?

There is a lot of discussion about that: https://ciexinc.com/blog/solarwinds-articles/drilldown.html

Re: The Story of the SolarWinds Hack

#94
post #14

How fortuitous is it that a months long investigation can be published right when the US announces sanctions? Great job National Radio! Like razor blades in peanut butter cups , says CrowdStrike.

There have been deeper dives and better explanations than this NPR article: https://ciexinc.com/blog/solarwinds-articles/zetter.html

Major investigations were completed months ago.

Re: The Story of the SolarWinds Hack

#95
post #57
post #24

Earlier quoted context omitted.

Like, say, that backdoor someone wrote an article about recently which ran from RAM and had a sophisticated self-destruct mechanism that erased all traces if anyone tried to dump its memory? I wonder how many companies had exploits like that which they either didn't notice or didn't have the sophistication to actually catch and dump.

There are defences for this: If one controls/monitors for every app in system for network access, as soon as any unusually network access are triggered, it is investigated and block. In my home windows setup, only windows defender, firefox and chrome are allowed out going internet access in regular base. Everything else are blocked. Windows update are only allowed when I in the mood for it (~once a year). Anyone can…

Only pulling security updates once a year probably puts you at higher risk than you're protecting against by firewalling outbound traffic.

Re: The Story of the SolarWinds Hack

#96
post #55

Network monitoring software is a key part of the backroom operations we never see. [...] By its very nature, it touches everything — which is why hacking it was genius. This is frustrating to read, since plenty of people did in fact warn that these kinds of systems were easy targets.

Yea.. not sure I'd call it genius. Think if you ask anyone that is a little knowledgeable about what would be the juiciest target for a nation state to hack, a large portion of people would have said something like SolarWinds. It seems like SolarWinds should have known better themselves as well. There is no way that their upper management didn't know that they would be an amazing target for a hack. Supply chain attac…

> There is no way that their upper management didn't know that they would be an amazing target for a hack

Presumes facts not in evidence.

From the nyt article https://www.nytimes.com/2021/02/23/opinion/solarwinds-hack.h... "The market loves to reward corporations for risk-taking when those risks are largely borne by other parties, like taxpayers."

See articles https://ciexinc.com/blog/solarwinds-articles/culture.html

Notice the report to SolarWinds: https://arcticsecurity.com/guides/2021/02/12/solarwinds-goin...

What does that tell you about their culture?

Re: The Story of the SolarWinds Hack

#97
post #89
post #80

This is the line that got me: >And so we are fairly broadly deployed software and where we enjoy administrative privileges in customer environments. There is a lot of talk about shoring up security practices by many of the people quoted here. But something that would be hard to admit is that maybe they should not have administrative privileges in customer environments. Maybe they should not install agents on your mac…

And you would think that a bit of analysis would be done on software and the company that built it for something that you install and give it full administrative control.

But... then that would reveal how the software functions leading to possible copying, which cant be permitted

Re: The Story of the SolarWinds Hack

#98
post #96

Earlier quoted context omitted.

Yea.. not sure I'd call it genius. Think if you ask anyone that is a little knowledgeable about what would be the juiciest target for a nation state to hack, a large portion of people would have said something like SolarWinds. It seems like SolarWinds should have known better themselves as well. There is no way that their upper management didn't know that they would be an amazing target for a hack. Supply chain attac…

> There is no way that their upper management didn't know that they would be an amazing target for a hack Presumes facts not in evidence. From the nyt article https://www.nytimes.com/2021/02/23/opinion/solarwinds-hack.h... "The market loves to reward corporations for risk-taking when those risks are largely borne by other parties, like taxpayers." See articles https://ciexinc.com/blog/solarwinds-articles/culture.html…

> Presumes facts not in evidence.

Yep, agreed. Its hard for me to believe that they didn't know they were rolling the dice on security, but just my intuition.

Re: The Story of the SolarWinds Hack

#100
post #96

Earlier quoted context omitted.

> There is no way that their upper management didn't know that they would be an amazing target for a hack Presumes facts not in evidence. From the nyt article https://www.nytimes.com/2021/02/23/opinion/solarwinds-hack.h... "The market loves to reward corporations for risk-taking when those risks are largely borne by other parties, like taxpayers." See articles https://ciexinc.com/blog/solarwinds-articles/culture.html…

> Presumes facts not in evidence. Yep, agreed. Its hard for me to believe that they didn't know they were rolling the dice on security, but just my intuition.

It appears to be stronger than that: In the article https://www.bloomberg.com/news/articles/2020-12-21/solarwind... (pro tip: open in firefox and clear cookies)

"A former security adviser at the IT monitoring and network management company SolarWinds Corp. said he warned management of cybersecurity risks and laid out a plan to improve it that was ultimately ignored.

In a 23-page PowerPoint presentation reviewed by Bloomberg News, Ian Thornton-Trump recommended to company executives in 2017 that SolarWinds appoint a senior director of cybersecurity, and said he told them that “the survival of the company depends on an internal commitment to security.”

The following month, he terminated his relationship with the company, saying he believed its leadership wasn’t interested in making changes that would have “meaningful impact.”"

Post reply on HN