Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

251–260 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#251
post #226

Earlier quoted context omitted.

I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…

I'm always curious about solutions to 2, so what does unfettered mean in this instance? Audited? Someone always needs root or Domain Admin or whatever to get the company out of a mess, so do we just heavily audit those accounts and hope they aren't a enemy agent from Pepsi trying to get our secret formula?

People don't need root access all the time. You can construct a system whereby elevated access is granted as needed with the approval of another person or persons. Logged and time- or task-limited of course.

Inconvenient? Yes. But sometimes appropriate.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#253

Earlier quoted context omitted.

I am not a security professional now, but I kind of used to be (at least one aspect of it). I'll take a run at giving answers. Caveat with these answers is that it assumes security > usability > cost, and the budget is high enough to afford the answer implementations. It also assumes the organization is extremely paranoid and security-conscious, both good things in this area. None of this information is Classified or…

Just trying to understand how this would work: >1. Computer stations use two types of fingerprinting at all times, facial recognition and typing biometrics. Also, login to the system requires password or pin entered after a card is inserted, followed by a fingerprint authentication, followed by the password of the day. Critical software/data must be accessed at an air-gapped machine inside a Faraday cage. Is the air-…

The air-gapped machine might get passwords provided for the days in the coming week, or might get changed every day. Usually the first.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#254
post #157

Earlier quoted context omitted.

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost. Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with. An aircraft on the other hand is already very exp…

An aircraft carrier also has the benefit of being operated under a vastly different framework than a regular IT system: military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks. But I've seen plenty of companies implementing solid (real) security measures only to see employees looking to bypass them themselves due to the inconvenience they caused, thu…

Last I was paying attention, all the legacy aircraft carriers hadn't been upgraded from windows xp, and had no upgrade path. That's only one of the platform's many vulnerabilities. Their purpose seems to have more to do with capital extraction than warfighting.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#255
post #219

Earlier quoted context omitted.

The problem with IT security orgs is that they get to estimate the costs of not following their own recommendations. Which trend towards infinity, because... well, they want the thing they're advocating for to happen. This tends to attract toxic, political people who thrive in this sort of environment, and push out more reasonable, technical people who don't want to deal with that. At some point, you get a critical m…

I don't really see it that way. From my perspective it isn't toxicity as the driver, but a strong sense of user preservation. Many people I know in security value the customers more than they value the company itself. They're the antithesis of political - their inability to understand higher order company-level or product-level issues often hamstrings them because their goals aren't aligned with the company goals. Th…

Clarification, in my context I'm typically talking about the IT Security and employee relationship. But the dynamics you outline still hold, although my experience has been reverse (they value what they perceive as "the company" over employees).

> I would imagine companies like that are generally toxic across orgs, and not just in IT, but probably any area where investment is forced and it isn't revenue-generating

I'd agree this is probably a key contributing factor.

It's been my fortune / misfortune to work for a number of companies that qualify (healthcare, financial, insurance).

But it has also been true (in my much more limited experience) with healthier, IT-as-profit-center companies.

I'd hazard better framing (than profit/cost center) might be "incentivized to improve" vs "penalized for mistakes."

Unless it's the former, it's in no one's personal interest to go above and beyond or suggest change. So you get glacial, incremental processes, and lose people who are impatient with working that way.

As you note, I think monetizing security is a key step to establishing a healthier balance.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#256

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

How to defend against these: 1) detection 2) detection 3) detection 4) sprinklers 5) detection 6) detection unfortunately, most orgs outsource their internal detection or have no capability at all.

The company I've founded is very much about providing better detection capabilities, but I'd say this is an oversimplification.

First of all, detection is methodologically bankrupt. We have almost no one out there saying how detection should be done with consensus - only in the last 5 years have we even started to improve here.

In my opinion, detection of attackers, which is what the industry focuses on today, is a huge waste of time and resources - it's the last step in the process that I would recommend.

I would personally say that detection should be staged as:

1. System inventory (can you attribute an IP or Hostname to a device identitiy, a user, etc)

2. Policy enforcement (can you detect when policies change, or are violated?)

3. Unexpected behaviors - go to the people building systems - ask them what's expected, what isn't, and build rules for that, or even better, have them build and maintain the rules under your guidance.

4. Attacker behaviors - finally, spend some time building rules for attacker behaviors.

Most organizations skip straight to 4, and then you have a team of defenders who have no idea how the network they're supposed to detect is supposed to actually work. This is throwing away the greatest advantage defenders have - that they know where the attack will take place, and they know all of the stakeholders for those environments.

Here's the chief of the NSA Tailored Access Operations saying this at USENIX four years ago.

https://youtu.be/bDJb8WOJYdA?t=83

"If you really want to protect your network you really have to know your network"

None of this is as simple as "detection" - it means working with the policy teams, with your infrastructure teams, with your product teams, to better understand your environment.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#257

Earlier quoted context omitted.

not sure how it is mil grade if an infra allows such a password to begin with.

depends on which part of the world you are, military grade can mean different things. I would not be surprised to find hair saloons with better security practices than our military.

Hair saloon, must be a Texas thing.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#258

Earlier quoted context omitted.

Engineers work with high level abstractions and heuristics nobody really understands all the time. There are people working on R&D, and building design tools, but then again there are also people working on algorithm theory and writing kernel drivers. I don't think there is a fundamental difference, just a difference in degree. Software enables far more layers of abstraction and far quicker development cycles than ot…

You mean using experimental data rather than theory? It's still connected to the underlying science, which is the key component. It's like saying the difference between a peninsula and an island is one of degree. Yes in a sense, but one is tethered to the land. Certainly engineers can veer off into solely doing software, and there are vast numbers of people that straddle fields. But if they aren't using their fundame…

I am a mechanical engineer by trade. By "heuristics nobody really understands" I do mean just that. Some of it may be grounded in experimentation, some of it might be grounded in data sets collected by god knows whom go knows when, some of it might just be "do it this way because the graybeards/application manuals say so". So on and so forth.

I find that a lot of software people have a highly idealized notion of how the "traditional" engineering disciplines work. Generalizing strict safety procedures found in some niche industries like aerospace to other fields where they don't exist. The truth is that working under time or budget pressures and without fully understanding what you're doing is extremely prevalent outside of software too.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#259

Earlier quoted context omitted.

An aircraft carrier also has the benefit of being operated under a vastly different framework than a regular IT system: military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks. But I've seen plenty of companies implementing solid (real) security measures only to see employees looking to bypass them themselves due to the inconvenience they caused, thu…

> military vs. civilian. This means any inconvenience of using the system only matters if it leads to clear operational risks. The military are not immune to this either. Case study, the 2006 Nimrod crash in Afghanistan [0], which killed all 14 of its crew. This plane was the flying equivalent of an unsecured server whose root password was 'password'. [0] https://en.wikipedia.org/wiki/2006_Royal_Air_Force_Nimrod_cr..…

Nobody is "immune" to mistakes but the framework under which the military operates raises the bar for any kind of attack or mistake simply by forcing the personnel to more consistently adhere to stricter rules regardless of the sector (in front of a keyboard or a trigger).

And coming back to the particular Nimrod crash, the findings of the inquiry suggest a chain of issues slightly more complex than your analogy suggests. Setting a root password of "password" goes way beyond poor maintenance, it's designing the plane with a crack in the wing.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#260
post #229

Earlier quoted context omitted.

There is no comparison. Stuxnet "worked by first causing an infected Iranian IR-1 centrifuge to increase from its normal operating speed of 1,064 hertz to 1,410 hertz for 15 minutes before returning to its normal frequency. Twenty-seven days later, the worm went back into action, slowing the infected centrifuges down to a few hundred hertz for a full 50 minutes. The stresses from the excessive, then slower, speeds ca…

Stuxnet is a well understood attack from 10 years ago and its being compared with a poorly understood attack from 1 year ago. >The solar winds hack is an otherwise unremarkable trojan that spread exclusively due to the bad security measures of solarwinds. We don't have sufficient information to say what happened after the trojan landed is unsophisticated. All we have is the idea that microsoft benefits from making th…

Sure, we could learn that they did something really impressive with the solarwinds hack that we have no idea about right now, and at that time it might be reasonable to compare it to stuxnet. The same could be said of any hack. However right now there is no evidence of sophistication anywhere near that scale, and thus calling it the largest and most sophisticated attack is clearly unwarranted, at least at this time.
Post reply on HN