12 ms·
Microsoft says it found malicious software in its systems
- yborg 6y agoMicrosoft has now categorically denied it. "We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth. Perlroth said the company stood by a statement it issued on Sunday saying it had no indication of a vulnerability in any Microsoft product or cloud service in its investigations of the hacking campaign."
- dragonwriter 6y ago> Microsoft has now categorically denied it. No, they haven't > "We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth. That's not a categorical denial of being penetrated, it's a denial of having information about being penetrated.
- stelfer 6y agoIt's a strong statement but it definitely leaves the door open. Given that there's so much at stake I can't imagine a different statement. On the other hand, if you read the CISA alert[1], it's clear that (1) many industrial targets were compromised, given the ubiquity of the Orion product and the amount of time that transpired; and (2) the attackers had their merry f'ing way with MS products like AD. So at this point I think it would be more surprising if they were not compromised than if they were. [1]https://us-cert.cisa.gov/ncas/alerts/aa20-352a https://us-cert.cisa.gov/ncas/alerts/aa20-352a
- AnimalMuppet 6y agoAre you saying that the attacker's skill with AD indicates that they were able to plant code in AD? Steal the source and learn vulnerabilities from it? Or just that, given that MS uses AD, they were vulnerable too?
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- leereeves 6y agoIf Microsoft's statement is honest, it certainly raises doubts about this story. What "people familiar with the matter" know more than Microsoft themselves? Even if the information was discovered during a government or private investigation of the hacks that didn't include Microsoft, the investigators likely would have notified Microsoft immediately.
- Godel_unicode 6y agoGiven the SEC implications of an officer of the company lying about something that could materially affect share prices, you can certainly believe that Microsoft thinks his statements are true. Literally anyone can tell a journalist that they're "familiar with the matter". Given reuters track record on security coupled with the lack of update about Microsoft's public statement, I'm inclined to be pretty skeptical about the quality of those sources.
- Red_Leaves_Flyy 6y ago>SEC implications Don't apply to matters of national security. Seeing as solar winds supplied every branch of government and just about every company that matters in the U.S., I would imagine that there are a lot of people under gag orders, or prohibited from talking about classified Intel with people that don't have clearance. To be safe, it'd be wise to not have company officers who also hold clearances.
- Godel_unicode 6y agoDo you have a citation for that? I'm not aware of anything about having a clearance which indemnifies you for fraud.
- Red_Leaves_Flyy 6y agoI am not a lawyer and merely [poorly] paraphrasing what I've heard in discussion about this legal quandary. The problem as I see it is that in order for a judge to not immediately dismiss a case the aggrieved party needs to have some evidence that these statements were made falsely. Considering the CISA opsec guidelines, there should not be a corporate paper trail detailing officials knowledge, so where and how do you get evidence that can be admitted to court? Witnesses would presumably be under similar NATSEC restrictions, have questionable custody of the evidence, or worse, they can only provide hearsay.
- justapassenger 6y agoThat’s the strongest truthful statement any company can give you. You can never be 100% sure you aren’t hacked. You can only be sure, that as far as you know, no one hacked you.
- kccqzy 6y agoWhen Bloomberg implicated Apple in The Big Hack, Apple gave way stronger denials. So did Amazon. > Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.
- justapassenger 6y agoExactly - Apple never said "we weren't hacked, 100% sure". They said, that all the data they have shows no evidence, plus pointed out some BS in the story.
- Red_Leaves_Flyy 6y agoInteresting that they only mention server. What about their employee devices, networking hardware, and every other internet connected thing? Not saying I buy this theory, but that denial leaves a lot of technically correct room to lie through their teeth.
- caminocorner 6y agoThats because the entirety of Bloomberg's nonsense focused on a supposed server. So there wasn't any need to disown employee devices, mobile phones, iot, etc
- dragonwriter 6y ago> That’s the strongest truthful statement any company can give you. Oh, I agree that no company will ever make a categorical denial of something like this; I just don't think that justifies promoting a lesser denial into a categorical one.
- mhh__ 6y agoThat's still a non-denial denial, right? "We never said we weren't breached, we just said we had no indication of being breached [...]" (Not that you can really give any more information in a public forum)
- bostonvaulter2 6y agoOr even we have no indication of this specific breach that you are talking about.
- gmueckl 6y agoThat statement doesn't even say whether they were actually checking. It's easy to have no knowledge when you aren't looking. I don't think the statement was meant that way, but it just shows how defensive the wording is.
- jyrkesh 6y agoI believe Brad Smith was chief of legal counsel before he was president. It would make sense for him to be very careful with his words here
- tiahura 6y agoMicrosoft has now confirmed it? Microsoft found code related to that cyber-attack “in our environment, which we isolated and removed,” https://www.msn.com/en-us/news/technology/microsoft-says-its-systems-were-exposed-to-solarwinds-hack/ar-BB1c1zIn https://www.msn.com/en-us/news/technology/microsoft-says-its...
- junyoon 6y agomight be time to buy Amazon shares
- AnimalMuppet 6y agoThat sounds like you're assuming that Amazon didn't get hit. I'm not sure that I think that to be a safe assumption.
- nonce42 6y agoMicrosoft's statement confirms that they had malicious software in their environment: “Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.” https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberattacks-cybersecurity-solarwinds-fireeye/ https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...
- blhack 6y agoHow will this even begin to be remediated (the broader hack that is coming to light right now)? It seems like malicious actors had unrestricted access to almost every major computer system in the US Government, and now possibly microsoft itself as well? How are these people ever going to be able to trust any of this equipment ever again? This just seems unbelievably catastrophic.
- mr_overalls 6y agoIt could be incredibly expensive to clean up. Remediation and recovery for most threats involves OS/app reinstallation, perhaps restoring from backups and images. However, if your threat is a sophisticated state actor based out of Russia, it's hard to rule out that they're got hooks in your server's firmware, that they've corrupted your backups as well, etc, etc. One wonders how Russia could exploit the systems they've penetrated. Brick every gov't system on Jan 20th? Shut down SCADA systems? It's a cybersecurity nightmare.
- panarky 6y agoThey've been inside since March, so any pre-breach backups and images are probably too old to restore.
- mrtnmcc 6y agoLast stable release was r2016.
- x86_64Ubuntu 6y agoI think he's talking about the hackers having been inside the victimized systems.
- unclekev 6y ago> Remediation and recovery for most threats involves OS/app reinstallation Except for all those SolarWinds admins arguing that doing a simple scan and infected binary removal is enough and then moving on and anything more is "overreacting" I feel sorry for all these people who are stuck working with such inflexible risk assessment/ITIL processes who are now trying to justify not taking any action because "SolarWinds said everything is ok"
- moocowtruck 6y agohopefully private repos on github are safe
- deleted 6y ago[deleted]
- nuker 6y agoNo repo should have secrets of any kind, no keys, no passwords.
- belltaco 6y agoTrue, but just static analysis of private source code is likely to discover several vulnerabilities, forget about experts looking for them in the source code. How many companies even do security based static code analysis using state of the art tools?
- nominated1 6y agoThis kind of reasoning is why many of us avoid closed source software.
- mhh__ 6y agoAnd why having the confidence to open source your code is good for your customers. At very least it's pressure not to fix that bug tomorrow rather than after lunch.
- moocowtruck 6y agonot only that but internal projects that one can glean information from just by knowing or seeing their existence and how they are constructed. or for yet unreleased things.. I'm surprised the few comments in this thread don't consider these sorts of things
- moocowtruck 6y agobut what does that have to do with me not wanting hackers to know what type of projects power my company, or unreleased things we're building? a whole slew of things that i would not want people seeing...thats why the repo is _private_
- marcosdumay 6y agoAnd, of course, unrestricted access to Microsoft leads to unrestricted access to nearly any company on the world. I need some popcorn.
- swiley 6y agoThe continued popularity of windows on corporate machines (especially dev machines) is the greatest evidence that the software market is completely incapable of judging software.
- marcosdumay 6y agoI think this Solar Wind scandal (with all the "our file doesn't match the checksum? Just install anyway" competency level) is greater... But anyway, the largest problem isn't even Windows, it's AD. Every corporate bases its entire access control in a baroque undocumented extension of a bad protocol with its security frozen at late 2000's years (upgraded by force a decade ago, because 90's security was too ugly). It's just insane.
- deleted 6y ago[deleted]
- nethunters 6y agoThe most scariest part from this is Homeland Security saying that Solarwinds wasn't the only vector used by the APT.
- tru3_power 6y agoLink to this?
- chrononaut 6y agoI assume they are referring to the CISA report today: > The SolarWinds Orion supply chain compromise is not the only initial infection vector this APT actor leveraged. https://us-cert.cisa.gov/ncas/alerts/aa20-352a https://us-cert.cisa.gov/ncas/alerts/aa20-352a
- tru3_power 6y agoYup, it was also mentioned in the article itself. I misread it originally. My bad, and thank you
- octoberfranklin 6y agohttps://news.ycombinator.com/item?id=25463034 https://news.ycombinator.com/item?id=25463034
- seibelj 6y agoAnd backdoors in everything is a good idea? This is beyond hilarious. The silver lining is that argument is 100% dead in the water going forwards.
- senectus1 6y agoPoliticians are really good at cherry picking their arguments.
- ClumsyPilot 6y agoI really hope it is, but I wouldn't hold my breath
- Shared404 6y agoIt's dead to anyone who even kind of knows their stuff... So not much change.
- _trampeltier 6y agoNot just backdoors, even just blob firmwares are scary enought.
- octoberfranklin 6y agoSpeaking of those "other infection vectors"... https://news.ycombinator.com/item?id=25462894 https://news.ycombinator.com/item?id=25462894
- raziel2701 6y agoI really doubt it, all these hacks come and fade from the news cycle and nothing happens. The more I think about it the more I am convinced that until there's a large body of crime that the news cycle can point to and be outraged about, nothing substantial will be done. The hack occurred and nobody knows if anything was taken or if it was just information that was collected. It will take months for a conclusive investigation. So far negligence in cybersecurity hasn't resulted in anything spectacularly failing like a giant explosion or a building collapsing and hundreds or thousands of people dying. Until something horrific like that happens there won't be pressure or political will to exert the appropriate measures that responsible governance should put in place.
- chrononaut 6y agoIt is always events like these that make me ponder if the Internet will devolve into regional Internets, which still wouldn't necessarily prevent or stop any determined attacker from performing these types of attacks. So perhaps it's never.
- natchy 6y agoI think you could have both, one national network and another global network.
- gumby 6y agoIts like a firewall at the edge of your network: doesn't really protect you as any attacker that can get to the other side has free reign. You need defense in depth. By the way, a piece of pedantry apropos a recent HN article: "...the Internet will devolve into regional internets." I.e. there is one Internet that connects to essentially everything; regional networks can practice internet working but aren't the proper noun "Internet"
- Shared404 6y agoI'm being pedantic, and I apologize in advance. > internet working Wouldn't it be inter-networking/internetworking or internet networking?
- gumby 6y agoI typed that on my phone and it auto"corrected" to add a space in internetworking. I'll leave the error in place and just post this comment instead even though I still have time to edit it.
- Shared404 6y agoFair enough. Like I said, I was being needlessly pedantic and it still communicated just fine.
- octoberfranklin 6y ago
- seanwilson 6y ago[Edit: Question was answered in article]
- Godel_unicode 6y agoGiven that lots of people are reporting very similar compromises, traced back to a confirmed supply chain compromise, with similar TTPs and a uniformly very high level of tradecraft sophistication, I'd say the former. And that statement is how.
- markus_zhang 6y agoI wonder when we will hear the news that all major clouds have been breached and data has been leaking for months/years...would be interesting to see. My wet dream is that people ditch the cloud to hold their own infrastructures.
- avandvrnot 6y agoMy wet dream is to heat the freezing homes of poverty stricken elderly people in the UK using the byproduct heat from the ultimate distributed cloud.
- jansan 6y agoAdd the energy used to mine bitcoin and you can turn the homes of the elderly people into saunas.
- HenryKissinger 6y agoIf you're a cybersecurity consultant, you can practically dictate your salary at this point. What's $3,000/hour to the government or a Fortune 500 to recover from a cyberattack like this? There must be a lot of all nighters behind the scenes.
- jonstewart 6y agoNot actually true. Many companies now buy cyberinsurance, and so the underwriters are now using their clout to putting pricing pressure on consultants. And, with some possible exceptions in the DIB, it’s not really clear that this hack by a nation state has really caused any loss to victim organizations. Without loss, the insurance claims will be low/nonexistent, and the companies will try to get by on the cheap. Uncle Sam will need to do better but Uncle Sam has lots of contractors and doesn’t pay full fare.
- snissn 6y agoMy company was forced to buy cyber insurance by almost all our big vendors to work with them. It's definitely the norm
- delfinom 6y agoThe joke is insurance companies aren't dumb and write in a billion exceptions to paying out just like any other insurance policy.
- Red_Leaves_Flyy 6y ago
- shiado 6y agoDoes anybody have any details on the Russia attribution? Not looking to start political flame bait here just curious what details are out there.
- judge2020 6y agoBased on what i've seen, the official statement is the only indication that it was an adversary https://www.solarwinds.com/securityadvisory#:~:text=.%20We%E2%80%99ve%20been%20advised%20that%20the,verified%20the%20identity%20of%20the%20attacker https://www.solarwinds.com/securityadvisory#:~:text=.%20We%E.... > We’ve been advised that the nature of this attack indicates that it may have been conducted by an outside nation state, but SolarWinds has not verified the identity of the attacker.
- naikrovek 6y agoVery curious why people are so strongly resisting the idea that russia is a prime suspect in this.
- tarmon 6y agoI think people are just curious to see some actual evidence that points to Russia. I don't think it is unlikely, I just haven't read anything that clearly indicates a specific nation state.
- gbrown 6y agoI’m usually the last person to defend our intelligence agencies. In aggregate, it seems like they’re more interested in undermining digital security than supporting it. With that being said, this sort of information would definitely risk compromising “materials and methods”.
- dboreham 6y agoIn this case we have a US government intent on being nice to Russia, so if they're saying it was Russia it probably was?
- 6y ago
- CyanLite4 6y agoI’m hesitant to blame anyone before we understand the full scope. “Breached into Microsoft” could mean they hacked into a guest public WiFi access point.
- Shared404 6y ago> Still, another person familiar with the matter said the Department of Homeland Security (DHS) does not believe Microsoft was a key avenue of fresh infection. Thoughts on this? It seems unlikely to me that someone who compromises literally the enterprise desktop OS manufacturer isn't going to take advantage of the situation.
- betwixthewires 6y agoIf they're financially motivated opportunists, sure. But this thing looks like a targeted attack with a deliberate set of goals.
- sjg007 6y agoI am not surprised, it's a dirty little secret in the software industry that we employ a lot of Russian and other potentially vulnerable Eastern European software contractors. Not to blame anyone specifically, I mean the threat could equally come from India or China. Or even a direct hack. It could also be an insider threat from an American as well. Since software development is a complicated profession, it takes a lot of intelligent oversight to ensure that critical paths are secure; especially as we migrate to cloud and site wide solutions.
- 99_00 6y agoChinese citizens are legally required to spy if asked. Don't know about the other countries citizens. https://www.canada.ca/en/security-intelligence-service/corporate/publications/china-and-the-age-of-strategic-rivalry/chinas-intelligence-law-and-the-countrys-future-intelligence-competitions.html https://www.canada.ca/en/security-intelligence-service/corpo...
- sjg007 6y agoI think we are all legally required to spy if asked.
- imwillofficial 6y agoNo.
- deleted 6y ago[deleted]
- _underfl0w_ 6y ago"asked" is probably a friendly oversimplification...
- 99_00 6y agoI've never heard of such a thing happening in Canada or the US.
- foxhop 6y agoI'm buying FEYE stock.
- pastrami_panda 6y agoExpand your reasoning please. Fire eye was compromised as well, which doesn't bode well for their trust. Also there's no opportunity for "buying the dip" currently as FEYE performance have been poor throughout the past several years?
- foxhop 6y agoFEYE is the only org who noticed the hackers in their network and likely are the group helping other orgs figure out how to recover their networks. FEYE was the honeypot that triggered the warning to the rest of the world.
- pastrami_panda 6y agoThanks for clarifying! Edit: does sound promising but hard to tell, seems like everyone is trying save face in this debacle
- testplzignore 6y agoThis comment aged well.
- AareyBaba 6y agoStatement from Microsoft President here on security https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberattacks-cybersecurity-solarwinds-fireeye/ https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat... "One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation using text messages and encrypted messaging apps." "a second evolving threat, namely the growing privatization of cybersecurity attacks through a new generation of private companies, akin to 21st-century mercenaries." "As humanity raced to develop vaccines, Microsoft security teams detected three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19." "One indicator of the current situation is reflected in the federal government’s insistence on restricting through its contracts our ability to let even one part of the federal government know what other part has been attacked. Instead of encouraging a “need to share,” this turns information sharing into a breach of contract. It literally has turned the 9/11 Commission’s recommendations upside down."
- varispeed 6y ago> and spread targeted disinformation using text messages and encrypted messaging apps Given there are moves to make sure end to end encrypted messengers have backdoors for authorities, isn't this kind of infomation prepared to seed association of encrypted messaging with something bad, so that in the future when there is a talk about making these apps either illegal or making sure they employ backdoors, people wouldn't be outraged?
- ackbar03 6y agocyber mercenaries. Sounds cool. On a more serious note though, it certainly appears this is how its going. APT41 turned out to be some private company in chengdu and APT39 I think it was some outfit in vietnam. Its pretty interesting (cool?) to think that some of these global cyber-threats are essentially just a handful of people in some non-descript office somewhere.
- ASalazarMX 6y agoIf this doesn't lend to home office and flexible hours, I don't know what will. Get access, pass it on to HQ for exploration. If it's valuable, office hacker gets to be employee of the month.
- yters 6y agoThe more lockdown the more lucrative big hacks become.
- dgudkov 6y ago>The U.S. National Security Agency issued a rare “cybersecurity advisory” Thursday detailing how certain Microsoft Azure cloud services may have been compromised by hackers I believe there is common overestimation of security of cloud providers. Microsoft Azure was just breached and that's only what we know. There might be breaches at other cloud providers we're not aware of. Centralization creates an exponentially growing incentive for bad actors. Decentralization has been given up too soon.
- ohuf 6y agoHere's the link to the NSA Cyber Advisory mentioned in the article: https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2434988/russian-state-sponsored-malicious-cyber-actors-exploit-known-vulnerability-in-v/ https://www.nsa.gov/News-Features/Feature-Stories/Article-Vi...
- hellodang 6y agoMicrosoft is working on the big government cloud solution defense contract, JEDI. Certainly a prime target for state actors.
- maest 6y agoWhat is the actual evidence that the hack was done by Cozy Bear/APT29/Russia? I keep seeing this information repeated all over the place, but no mention of how that is actually known.
- Red_Leaves_Flyy 6y agoWhat are you looking for, a confession? This is information shared by people involved in investigating and remediating this attack, if the investigators share the smoking guns they show their hand to the attacker. There are what, three countries capable of an attack of this magnitude? China, Russia, and Israel? I wouldn't rule out a clandestine non-governmental operation, but that is unprecedented at this scale.
- maest 6y ago> What are you looking for, a confession? I'm looking for evidence that would make me believe the attackers were indeed Russian-backed. So far we've seen no evidence, which means we have to take what the government sayhs at face value, and I'm sure I don't need to spell out why that's problematic. Just because it's hard to find/provide evidence doesn't mean we blindly have to accept what we're told.
- Red_Leaves_Flyy 6y agoI'm not arguing that you accept attribution blindly. That being said, asking for attribution with evidence right now is absurd. No one, except the attackers, knows the full depth or breadth of the attack. To make a positive id at this moment, and explain how investigators are attributing responsibility is reckless. Asking for evidence behind attribution at this time is essentially flamebait. If you doubt the attribution it may be better to question the record of those making these accusations and what they stand to gain by making them.
- AnimalMuppet 6y agoMaybe Iran. Maybe North Korea. Oh yeah, and the US is definitely capable. I'm not sure they would do this in their own nest, though.
- coldcode 6y agoGoes to show that you are only as secure as your weakest dependency. Allow and trust software into your organization built by a system protected by an obvious single factor password (which you didn't know about or ask) and no matter what else you did you are screwed. I worked at a healthcare company that stored its production credentials (with no login auditing) in a plain text file accessible by half the employees and contractors and when I complained that this was dumb (and violated HIPAA) was told "we passed our audits and we trust our employees".
- steve76 6y agoI have a great way to fix this. Grab the first person you see off the street, and cut their face off. Dry it. Tan it. And sew it into wallets, belts, book covers, and shoes as gifts to the ever growing number of authoritarians who dare command economies and tell everyone what to do from far far away. It's okay because authoritarianism and tyranny is not government. It's not even being a crook or a bully. A malignant tumor that learned how to type is the best I can describe it. Destroy with as much motivation as wiping out polio. It's one thing for international marxists to do this. It's another thing for the cannibals of Borneo, or Supermax inmates to do this. Blame them regardless. They opened the door. We've lead them well into the technology frontier. Time to shoot their scouts, and let the wild devour them.
- desktopninja 6y agoI wonder how much social engineering played a part in this?