Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

271–280 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#271

Earlier quoted context omitted.

It seems to me that they are doing the exact opposite of what you claim they are doing. None of the mitigations that were described were aimed at preventing a breach or disaster. Instead all were designed to mitigate the damage that happens when a breach occurs.

I'm not sure what you're referring to, but my comment is to the person advocating fault-tolerant systems, segmentation and the other things as panaceas to the situation. These are not new concepts in the security industry. In fact very much of the opposite; manifestations of them like zero trust have been one of the main buzzwords for the last ten years or so in the cyber industry. It's a different thing sketching so…

I did not suggest not doing monitoring internally, I suggested not relying on internal monitors. Because the SolarWinds hack had gone undetected on the security company's own servers and ran rampant for (weeks?) before it was detected.

As reported on "60 Minutes" yesterday.

The security company did not compartmentalize their own system. They relied on monitoring, which failed.

Furthermore, it was said on the segment that firmware on the hardware can be infected, so reinstalling the system software won't get rid of it. The obvious solution to that is to put the firmware in ROMs, so it cannot be electrically reprogrammed. But nobody does that.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#272

Earlier quoted context omitted.

I bought a book some years back about how to defeat burglar alarm systems, as I wanted to make my home more resistant to burglars. The book described a sophisticated system that would detect burglar entry and then automatically phone the cops. The defeat was to chop the phone line where it entered the house, because the telephone company puts their box on the exterior of the house. (The book was printed before cell p…

You can expect single detection system to fail, so you need to make it redundant. For example impossibly loud siren. Like you said before, any solution is a mix of 2 paradigms.

Another method of defeating a sophisticated burglar alarm system is taking an axe to the power cable to the building.

How many people have a battery hooked up to the siren?

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#273

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

I am not a security professional now, but I kind of used to be (at least one aspect of it). I'll take a run at giving answers. Caveat with these answers is that it assumes security > usability > cost, and the budget is high enough to afford the answer implementations. It also assumes the organization is extremely paranoid and security-conscious, both good things in this area. None of this information is Classified or…

> Fire the CEO unless they were mugged

People don't learn from mistakes if that's the response. They'll also hide their mistakes, making things worse. You want a CEO to report the loss ASAP, not cover it up. Having a "no fault" culture encourages people to quickly report mistakes.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#274

Earlier quoted context omitted.

What if the government directly paid the cost of reimplementing that old c software? If the market is failing here as it seems to be then perhaps the government should step in.

government paid $55 mil to create a simple vaccination website which doesnt work. do you think government can pull this off?

Yep. Making good software is much easier than doing anything related to healthcare.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#275

Earlier quoted context omitted.

This is not really a helpful mnemonic -- security breaches are adversarial. Boeing airliners are not designed to keep flying to the intended destination if the cockpit is breached by hijackers.

Battleships and spy networks are about as adversarial as it gets. Even airliners give some consideration toward not being too easy to hijack or bring down. For instance the hardened cockpit doors added after 9/11.

Airliners now also give consideration to the pilots being bad actors, due to a couple incidents where a pilot decided to crash the airplane.

There's also effort at making the airplane survive malicious cargo.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#276

I've found my experience designing gearboxes for Boeing has applicability to software design. For example, the fundamental idea with airplane design is not to design components that cannot fail, as that is impossible. The idea is to design the system to be tolerant of failure . Every part in the system is not "how can we make this part never fail" but "assume it failed. How does the airplane survive?" This is a funda…

This is also taken into account in software engineering. Most software have defense in depth against single point of failure, they can recover or cope with wrong input. But you cannot compare them because the context is different: software is less regulated than aviation so while anyone can write of very bad software in 5min and sell it, this is not possible for a plane. And not everyone can pilot a plane, while ther…

> no safety feature on a plane can prevent the pilot from crashing it willingly.

This is no longer true. There are procedures where no crewmember is allowed to be alone in the cockpit.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#277
post #252

Earlier quoted context omitted.

You actually do have organ backups.

If you have a second heart, please report to area 51 immediately

That would be Krogan, not me. There are animals with multiple hearts. People can be made to have 2 hearts too, but let me not go into that.

But we have bunch of non-heart redundancy.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#278

I've found my experience designing gearboxes for Boeing has applicability to software design. For example, the fundamental idea with airplane design is not to design components that cannot fail, as that is impossible. The idea is to design the system to be tolerant of failure . Every part in the system is not "how can we make this part never fail" but "assume it failed. How does the airplane survive?" This is a funda…

I served aboard a nuclear submarine as a reactor technician. The term for what you describe in the nuclear industry is "fail safe"

Yes. But I wish to point out that the Fukishima disaster happened because one failure caused a cascading sequence of failures that destroyed the plant.

The design failure was "assume the seawall would not be breached". But it was, which destroyed the backup electric generators, and the rest followed from that.

A better design would assume the seawall is overtopped, and so would have put the generators on a platform. Simple, cheap, and effective.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#279
post #163

Earlier quoted context omitted.

In my day at Boeing, nobody considered that the pilot might be a bad actor. Unfortunately, that was a mistake. It turns out pilots can be bad, and now there are procedures for that.

Funny that Boeing are capable of considering that , but not a single sensor failing and how that might impact a system designed to hide the actual aerodynamics of the plane. Boeing really aren't a good example for anything besides negligence and how to game regulators.

I'm not going to make any excuses for MCAS's reliance on a single sensor.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#280
post #268

Earlier quoted context omitted.

Your field may look vast to you but from where I'm sitting I couldn't even tell you what is different about the principles needed for tv mounts versus helicopter flexbeams. Both sound like statics class to me, presumably decades after you took it, still being used in your work. Fine the bridge guy may be able to build other structures. Though I suspect it will get increasingly difficult for them to get past the job i…

So when you don't know the difference between two things you assume there is no difference and not only disregard those better informed than you who claim otherwise, but try to tell them how simple their profession is? Neither the tv mounts nor the testing machine were remotely close to statics class. For the seismic TV mounts, I had to make an economical laser cut sheet metal assembly which could be assembled in a f…

> So when you don't know the difference between two things you assume there is no difference and not only disregard those better informed than you who claim otherwise, but try to tell them how simple their profession is?

Are you really snapping at me rudely over a disagreement about the differences between engineering and programming? To answer your question, no. I'm saying that it's the same technical domain.

> Yes, an engineer must understand fundamental principles, but that is true of any profession. How can you set up a database without knowing the fundamentals of how a database works?

Excellent point. Because it's at the heart of my reasoning too. Identify those fundamentals and you can apply my argument. In my prior post I noted the fundamentals in engineering are specifically physical principles. In the case of databases they are not, instead they are completely at an abstract level.

Post reply on HN