Live data from Hacker News

The Story of the SolarWinds Hack

npr.org

111–120 of 139 posts

Re: The Story of the SolarWinds Hack

#111

Earlier quoted context omitted.

I fear that you're being downvoted for pointing out the even bigger threat of our national media's exceedingly more dangerous acts of propaganda, presumably because readers either don't recognize it or are wilfully blind to it because it reflects their own biases. The SolarWinds hack was a devastating attack on our sovereignty. And so is the other.

The SolarWinds hack in addition to election interference should easily be seen as an attack worthy of taking out Putin IMO.

Because the Russia link is so strong? Dude, everything you read about Russia in the American press is garbage. From the article:

"They cleaned the crime scene so thoroughly investigators can't prove definitively who was behind it."

That's literally in the article but it doesn't stop them writing the whole thing as if it's utterly proven beyond doubt who was behind it.

Re: The Story of the SolarWinds Hack

#112
post #55

Network monitoring software is a key part of the backroom operations we never see. [...] By its very nature, it touches everything — which is why hacking it was genius. This is frustrating to read, since plenty of people did in fact warn that these kinds of systems were easy targets.

Yea.. not sure I'd call it genius. Think if you ask anyone that is a little knowledgeable about what would be the juiciest target for a nation state to hack, a large portion of people would have said something like SolarWinds. It seems like SolarWinds should have known better themselves as well. There is no way that their upper management didn't know that they would be an amazing target for a hack. Supply chain attac…

> the juiciest target for a nation state to hack

Not even just for a nation state, it's the perfect target for anybody looking to gain reputation/large scale access to very interesting systems.

Hacking the keys to the kingdom from the people who are supposed to protect the kingdom from hacks.

In terms of "pwnage level" it can't get much "better" than that.

Re: The Story of the SolarWinds Hack

#113
post #4

It’s nice how they equivocate over the ease of entry and their security policies: There was another unsettling report about passwords. A security researcher in Bangalore, India, named Vinoth Kumar told NPR that he had found the password to a server with SolarWinds apps and tools on a public message board and the password was: "solarwinds123." Kumar said he sent a message to SolarWinds in November and got an automated…

> An FTP site is what you use to transfer files over the Internet.

Afaik that was the updatesever and the password originally came from a public Github repo where is was stored in plaintext since at least June 2018 [0]

[0] https://www.theregister.com/2020/12/16/solarwinds_github_pas...

Re: The Story of the SolarWinds Hack

#114

Earlier quoted context omitted.

How a Vp security can ignore a privesc risk like that is pretty inexcusable. Ever vuln falls on a risk mgmt spectrum but that’s a really nonsense answer to give. Weak PW mgmt on a FTP server that you let interns set should raise some areas of interest.

You don't get this kind of attack because you had an exposed FTP server. The attack implanted malicious code into their code, learning the tooling, process and responsibilities of the personal. They then reversed engineered the protocol and used it in their backdoor to look basically the same as regular communications. The issue is that we blindly trust 3rd party software that is used by hundreds of companies. this m…

> You don't get this kind of attack because you had an exposed FTP server.

Leaking the extremely weak login credentials to your updateserver, trough a public Github repo, is not exactly a glowing endorsement of how serious security seems to have been taken at Solwarwinds.

With stuff like that being a thing, who knows where else they cut corners/got lazy.

> this makes SolarWinds a prime target, one that is worth the efforts taken in this case.

A prime target, yet apparently could still not be bothered to put in some minimum effort to protect themselves.

Re: The Story of the SolarWinds Hack

#115
post #103

I think the most important thing the SolarWinds hack has revealed is that the massive pile of paperwork that has to be filled out, full of security controls, to accredit system for government systems, is fairly useless. It's the digital equivalent of the Great Wall of China. Designed by bureaucrats, impressive in size, a massive effort, and ultimately not going to stop the Mongols anyways. Security paperwork is not s…

They didn’t prevent this specific hack so they are completely useless?

They didn’t say “completely useless,” they said “fairly useless.”

If you look at this case even briefly, you should come to the conclusion that the “security paperwork” is fairly useless.

An FTP server compromised because of a terrible password policy? No suspicious activity alerts of any kind? Executives who (based on their comments) are clearly ignorant of what makes software actually secure?

What is the paperwork able to prevent, if it can’t prevent such fundamental problems?

Re: The Story of the SolarWinds Hack

#116

Anyone know how the software update was actually compromised in the first place?

Tim Brown VP Security of Solarwinds said: “We check code out of source code control, have a TeamCity environment to kick off the build, and here the attacker looked for Orion to be built and swapped a file. It was a transient virtual machine and that’s hard to detect,” he said.

https://itwire.com/security/solarwinds-speaks-out,-and-softw...

So it sounds like the VM host they were running builds upon was compromised - or maybe JetBrains was compromised?

JetBrains claims there is no evidence they were compromised https://blog.jetbrains.com/blog/2021/01/07/an-update-on-sola...

Re: The Story of the SolarWinds Hack

#117
post #109

Earlier quoted context omitted.

Really? A government saying that they would ensure no "negative stories would come out", literally puppetting international institutions to pay out money - billions - for an election campaign, sent US Government agents to be embedded into the Yeltsin campaign right as he was violating every law on the books and calling in favours from the mafia and oligarchs, and very likely also used intelligence agencies to help, a…

I have a family member affected by those "targeted ads" and can tell you this is hardly comparable to news agencies writing favorably or not about someone. Some people are seriously fucked up because of this. Just look what happened on January 6th.

For the record, I think that both are elections interference. But there's a far cry behind publishing fake news and advertising it to some demographics and fuelling IMF money into campaigns by the billions and embedding foreign advisors into a criminal election campaign.

Re: The Story of the SolarWinds Hack

#118
post #90
post #62

"The tradecraft was phenomenal" Indeed, consider Figure 5 here [1]. A truly diabolical mastermind. But seriously, the article looks like window dressing for common incompetence. [1] https://www.microsoft.com/security/blog/2020/12/18/analyzing...

A common way to dodge accountability is to exaggerate the size of the enemy and his cleverness and goodness he had 1000 developers working on it. Nonetheless, there are some things that are kind of impressive. Inserting their own code into the build process without touching any file. But the real level of skill, I think, is the operational discipline exercised by the attackers. For example, waiting two weeks before d…

Security is not my line of work, but back in the days I spent a while exploring the field (I especially enjoyed reverse engineering / subverting software ).

Why is this 'operational discipline' remarkable? I'd expect this to be common sense (including waiting for two weeks) , especially if I was a state actor and had spent a whole bunch of money on it? Or do you mean that the vast majority of hacking operations don't even bother to do this?

Re: The Story of the SolarWinds Hack

#119

Earlier quoted context omitted.

They didn’t prevent this specific hack so they are completely useless?

They didn’t say “completely useless,” they said “fairly useless.” If you look at this case even briefly, you should come to the conclusion that the “security paperwork” is fairly useless. An FTP server compromised because of a terrible password policy? No suspicious activity alerts of any kind? Executives who (based on their comments) are clearly ignorant of what makes software actually secure? What is the paperwork…

Exactly. It's wonderful that there's a few thousand controls for things like password length. But things that cause massive security nightmares like "does the CTO care about security?" or "has a pentest team reviewed and audited the source?" are so fundamental and should be triggered as any new system touches more and more systems.

"Does this software touch literally every other system on the network?" should be a question that triggers a much more rigorous and deeply technical evaluation and review.

But the current processes don't work that way, they purely paperwork drills that often demonstrably make systems less safe.

Re: The Story of the SolarWinds Hack

#120
post #90

Earlier quoted context omitted.

A common way to dodge accountability is to exaggerate the size of the enemy and his cleverness and goodness he had 1000 developers working on it. Nonetheless, there are some things that are kind of impressive. Inserting their own code into the build process without touching any file. But the real level of skill, I think, is the operational discipline exercised by the attackers. For example, waiting two weeks before d…

Security is not my line of work, but back in the days I spent a while exploring the field (I especially enjoyed reverse engineering / subverting software ). Why is this 'operational discipline' remarkable? I'd expect this to be common sense (including waiting for two weeks) , especially if I was a state actor and had spent a whole bunch of money on it? Or do you mean that the vast majority of hacking operations don't…

Contrast that with the smash and grab of the exchange vulnerability that followed.

Yes, many operations make some kind of error that gives the whole thing away

Post reply on HN