Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

51–60 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#51
post #4

Convince me it’s more sophisticated than Stuxnet.

At it's core, Stuxnet is basic. Stuxnet didn't do what that Blugarians did. Stuxnet was not polymorphic.

The delivery was the really impressive part of stuxnet, IMO. Which wasn't technical at all.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#52
post #31

Earlier quoted context omitted.

The attack is unique in its usage of the supply chain. The malware is not 'sophisticated' in the same way stuxnet is because it has different goals. This actors goals align with stealth above all else, which is evident in both the design of the malware and the choice of the supply chain delivery vehicle. Also realize that the network comminication scheme used attempts to blend in with the legitimate SolarWinds softwa…

Stuxnet was also a supply chain attack. The first infections were at Foolad Technic and Behpajooh, a pair of privately owned engineering firms. The malware keeps a "breadcrumb" trail of each machine it infects, and based on investigations by Symantec [1] it was determined that every Stuxnet sample from Natanz originated from outside suppliers. 1. https://tinyurl.com/1eswo98i

Related to Stuxnet, I'd say the Equation Group's presence on hard drive firmware was/is the most sophisticated supply chain attack ever: https://en.wikipedia.org/wiki/Equation_Group#Firmware

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#53

Earlier quoted context omitted.

I checked again and their website still looks like something made by an AI using a template. https://www.solarwinds.com/ We’re Geekbuilt.® Developed by network and systems engineers who know what it takes to manage today's dynamic IT environments, SolarWinds has a deep connection to the IT community. The result? IT management products that are effective, accessible, and easy to use.

> their website still looks like something made by an AI using a template. This is every website of any company selling to enterprise customers. It's incredibly frustrating as a reader. I imagine anytime someone actually answers the question "Yes, but what do you do ?", they get fired.

They are vague because they want you to leave your contact details. Then a sales person will call you and gladly tell you everything you want to know and spam you with newsletters and marketing materials until eternity. That's B2B for you.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#55
I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems:

https://web.archive.org/web/20061215050427/http://www.matasa...

Agent-based endpoint management is super convenient and is mainstream in modern IT management. But nobody grows up wanting to write the communications software for enterprise server inventory software, so the code quality on these products, which are ubiquitous, is awful. But 99% of enterprise buyers aren't even slightly motivated by software security when making purchasing decisions, and everyone knows it, so vendors buy fig-leaf audits from vendors who will sell public-facing documents for 2p1w engagements, and IT purchasers, whose performance reviews are based on completing projects and not protecting their companies from $500,000 purchase orders for what is effectively malware, accept those bogus reviews and get on with their lives.

Nothing is going to change about this, because nothing is going to alter the incentives. Reporters like Nicole Perlroth will try to blame it on ex-NSA hired guns (as if you needed the exploit chains NSA buys to break any of these systems), but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time.

Best get used to it, is I guess my point. I mean that sincerely, not as a sort of appeal to right the ship; the ship is already upside down.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#56
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

An attack has multiple stages. Stuxenet's attack formula was: inflitrate an airgapped network -> silently spread within -> silently destroy complex unique equipment Solarwinds attack forumla seems to be: compromise central infrastructure -> silently spread to customers via compromised updates -> silently exfiltrate useful data/create an advanced persistent threat (APT). Because the initial compromise (oh a bad passwo…

> the initial attack vector was a USB stick in a parking lot

That's not fair. It should sound like this: "the initial attack vector was a Windows 0day requiring 0 clicks, delivered by a USB stick in a parking lot."

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#57
post #6

Largest impact, sure. But architecturally it was a relatively simple formula - compromise a widely used package and sleep on it until it was pervasive enough to be a valuable hack. I disagree with this being the most sophisticated though. Unless I'm missing something about this hack, the Stuxnet[1] architecture, complexity, and long term planning feel far more sophisticated than the SolarWinds hack. [1] https://en.wi…

[deleted]

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#58
Were any multilayer capability based secure operating systems compromised? No...

Were any in use at all? No

So, nothing really sophisticated... just exploiting the bad design of existing operating systems.

This will continue for the foreseeable future.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#59
post #55

I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems: https://web.archive.org/web/20061215050427/http://www.matasa... Agent-based endpoint management is super convenient and is mainstream in modern IT manag…

> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time

Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking anyone's budget. No?

Post reply on HN