26 ms·
SolarWinds hackers were able to access Microsoft source code
- HenryKissinger 6y ago> Microsoft said the account did not have the ability to monitor any Microsoft code. The blog post further added it has found no evidence of access “to production services or customer data.” The article is in contradiction with the headline, isn't it?
- tmaly 6y agoIf you go back to the original CISA post December 17, 2020 they noted a different attack vector other than SolarWinds had compromised some systems.
- vm 6y agoThe reuters link posted here is click-bait junk. This section from the Microsoft blog provides better context. >We detected unusual activity with a small number of internal accounts and upon review, we discovered one account had been used to view source code in a number of source code repositories. The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made. These accounts were investigated and remediated. >At Microsoft, we have an inner source approach – the use of open source software development best practices and an open source-like culture – to making source code viewable within Microsoft. This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So viewing source code isn’t tied to elevation of risk. https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/ https://msrc-blog.microsoft.com/2020/12/31/microsoft-interna...
- webmobdev 6y ago> At Microsoft, we have an inner source approach – the use of open source software development best practices and an open source-like culture MS has an "open source" culture? I laughed and remain skeptical ...
- tmotwu 6y agoNot untrue. Internal orgs adopt a monorepo structure - the source for the majority of the infra is readable from almost any developer within the company.
- DaiPlusPlus 6y agoI figured that’s where Raymond Chen gets the bulk of his material from: looking at the perforce/sd diffs from 1997.
- deadso 6y agoThey specifically said it's _not_ open source. Hence the open source-like. To distinguish, they even have a different name for it - inner source.
- webmobdev 6y ago> To distinguish, they even have a different name for it - inner source. Yeah, I recognize MBA speak when I see it. That's why I chuckled. They were hacked and somebody saw their code. Now some guy in upper management has to spew some bullshit to protect the company's "image".
- elygre 6y agoThe term "inner source" was not coined by Microsoft. The wikipedia page [1] shows the history of the term. 1: https://en.wikipedia.org/wiki/Inner_source https://en.wikipedia.org/wiki/Inner_source
- bpye 6y agoWork at MS, that term has been used for a long time internally, certainly longer than I have worked here. It really is very useful to be able to go find the code for a product when you want to understand how something works.
- deleted 6y ago[deleted]
- goalieca 6y agoSure they don’t do security through obscurity but any pen-tester will tell you that whitebox knowledge is certainly a huge help.
- thatsamonad 6y agoThough this is bad for Microsoft, does it make the situation substantially worse from a security perspective? Assuming they’re following good practices like not storing access keys, passwords, etc, in their source control system(s), this seems like more of an IP protection issue. I could be wrong about that, though, and I’d be curious to learn and understand more.
- j_walter 6y agoExploits are much easier to find if you have pure source code and not having to reverse engineer it.
- acct776 6y agoAssuming your source isn't a fucking mess, is commented, APIs documented, etc
- rhexs 6y agoNo, it’s still much easier.
- onionisafruit 6y agoRight. One place I worked would probably benefit from attackers getting access to the source code. It would cost them weeks of productivity trying to figure it out.
- tpmx 6y agoThe core Windows source code is surprisingly readable/well written, I've heard.
- sn_master 6y agoWe are morons! http://atdt.freeshell.org/k5/story_2004_2_15_71552_7795.html http://atdt.freeshell.org/k5/story_2004_2_15_71552_7795.html
- 6y ago
- BrentOzar 6y agoHere's the updated Microsoft post that contains the admission that the hackers viewed source code: https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/ https://msrc-blog.microsoft.com/2020/12/31/microsoft-interna... Drives me crazy that Reuters could write an entire post about a Microsoft blog post, yet not link to the post itself.
- giancarlostoro 6y agoIt drives me crazy when in 2020 news articles do not link to sources.
- dvdbloc 6y agoWhy would they? Will it increase revenue if they do?
- wslack 6y agoBecause the goal of news should be to inform, especially when talking about court filings, and we as viewers should not give traffic to sites that don't do basic linking work.
- 28u34ri 6y agoThe goal of the "legacy news" is to support a paycheck. Wealthy individuals or groups will financially support these "legacy news" organizations as long as they have a say in what is put out.
- Frost1x 6y agoI believe parent was being rhetorical and or facetious. What we believe organizations should do and what they actually do in is often misaligned based on problematic underlying driving forces/goals. Profit motives have tended to overcome all other incentives in our (the US) economic structure. It may be a broader problem globally due to power and influence of the US. The same can be said about consumer motives. I probably should shop locally more often, but I may not be able to afford local rates and have to pass the costs down the line if I want to continue supply more basic underlying goals (eating, staying sheltered, etc). At some point we have to have the difficult conversations of choosing the tradeoffs we do and don't want to support, otherwise we may let flawed underlying goal structures guide us to the paths of least resistance, which may ultimately not be good for humanity (or it may be, who knows). Given a lot of current directions, I find it hard to believe our underlying system structures are great for human well being. It may have been a good run for awhile but that may be a short temporal anomaly. We may have to more throughly consider long term consequences of goals we set that may run counter to their actual intent. It's easy for some to simply ignore the underlying problems and play the game optimally for oneself. Personally, I've never been happy with that option (the option which OP sort of alludes to).
- HatchedLake721 6y agoOriginal blog post by Microsoft - https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/ https://msrc-blog.microsoft.com/2020/12/31/microsoft-interna...
- asah 6y agoclosed source = only the badguys get to see it. :-(
- vthallam 6y ago> This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So viewing source code isn’t tied to elevation of risk I don't know how much of this is true. Wouldn't it be helpful for bad actors to understand how Windows defenses work looking at the code thereby increasing the risk?
- webmobdev 6y agoYeah, the whole point of looking through the source code is to find undocumented APIs and bugs to exploit.
- monocasa 6y agoA lot of times stuff like undocumented APIs and bugs are easier to find taking apart the binary anyway. Goofy stuff tends to be obfuscated in source as engineers add so much abstraction around the goofy pieces, but it's clear in the final binary.
- webmobdev 6y ago> A lot of times stuff like undocumented APIs and bugs are easier to find taking apart the binary anyway. Is that why Microsoft, and all you people who poke at its binaries, have fixed all the bugs in MS binaries? /s
- deleted 6y ago[deleted]
- monocasa 6y agoWhy do you think the people poking around MS's binaries overwhelmingly want the bugs they find to be fixed?
- webmobdev 6y agoThe point was that if it was so easy, a lot more people would be disclosing the bugs and asking MS to fix. Not everyone hacker has a malicious intent.
- codezero 6y agoI don't know if I missed it in the article, but did they say anything explicit about write access? Seeing the source may give access to new zero days, but it would be much worse if the attackers were able to seed a large number of commits into the code that introduce subtle vulnerabilities.
- thatsamonad 6y agoSounds like the attackers did not have write access. From the original blog post: > The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made. These accounts were investigated and remediated. I would also hope that direct commits don’t go immediately to a production system without some sort of review. At my workplace we have branch protections for all “main” branches that would result in a deployment. At least one other person has to review changes and all of our automated checks have to pass before anything can even get close to running through a deployment pipeline.
- codezero 6y agoWhew, that's good to hear. I assume anyone trying to inject malicious code is going to try to do so in a way that doesn't go through normal code review channels.
- thatsamonad 6y agoTrue. However, hopefully that’s being mitigated through things like not allowing authors to review their own commits, not using the same accounts to push code changes and do deployments (i.e. having a read-only account for deployments), etc. However, if it were an admin account that were breached that would definitely make it possible to circumvent any number of protections in place.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- popup21 6y agoA blind man can see that this was a rigged election. Denial and evasion are progressive liberal personality traits.
- cogman10 6y agoI wonder if incidents like this will push MS towards open sourcing windows. IDK what their revenue looks like, but I'm guessing that selling the OS isn't as front and center as it used to be (from the way they are changing in terms of supporting things like linux). Even if they keep a pretty tight license around the source, releasing it to the public would earn a lot of good will while potentially finding and fixing security problems.
- MeinBlutIstBlau 6y agoI always thought the reason they charged for their OS was due to their anti-trust lawsuit so as to state that they weren't actively trying to dominate the market or something along those lines? Also, OEM operating systems are kind of circumventing that.
- easton 6y agoThe reason I always heard was that there’s tons of binary blobs in Windows they bought from vendors that’d have to be reimplemented (the zip library is the most notable example). Russinovich said never say never though, so I don’t know. https://www.wired.com/2015/04/microsoft-open-source-windows-definitely-possible/ https://www.wired.com/2015/04/microsoft-open-source-windows-...
- acct776 6y agoBeing open source is not correlated with charging licensing fees. It just means you can read the source.
- Jestar342 6y agoSome licenses very explicitly prohibit source distribution/publication.
- ksec 6y ago>I wonder if incidents like this will push MS towards open sourcing windows. What I am thinking as well. Unimaginable if it was 10 years ago, but modern Microsoft seems to be taking a different approach. And Apple desperately need some competition to keep Tim Cook honest.
- jeffrallen 6y agoPoor hackers. I hear Visene soothes bleeding eyes.
- stagger87 6y agoYour comment breaks several guidelines here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- juanbyrge 6y agoIs the source code buildable, or is it mainly for documentation purposes? I’m guessing the build system and tool chains required for building windows are massively complex. Are these distributed with the windows source code as well? Also I’m guessing that there are a lot of other proprietary vendor-supplied pieces that get built with Windows. What happens if these are not available?
- tozeur 6y agoInternal builds barely work with millions of dollars and man power invested. I can’t imagine anyone else outside of Msft being able to build Windows lol
- ohiovr 6y agoYou're going to love this https://tech.slashdot.org/story/20/09/30/1843232/windows-xp-leak-confirmed-after-user-compiles-the-leaked-code-into-a-working-os#comments https://tech.slashdot.org/story/20/09/30/1843232/windows-xp-...
- koreanguy 6y agomisleading clickbait title post, pathetic from microsoft "Our investigation into our own environment has found no evidence of access to production services or customer data. The investigation, which is ongoing, has also found no indications that our systems were used to attack others."
- jtchang 6y agoOn the whole this does not affect my perception of Microsoft. In fact it probably tilts it in their favor. They were able to conduct a thorough investigation and figure out the attackers had access to the source. The reality is that while it makes future attacks easier it has already been taken into account for a large majority of risk assessments. People trash Microsoft a lot but some of the people there are the best in their respective fields.
- superfrank 6y agoDo people still trash Microsoft? Maybe it's just because I'm in Seattle, but I feel like their reputation has really turned a corner in the past year or two. There's still a lot of cruft from who they used to be, but I feel like most people I know echo the sentiment that Satya has been a revolution. Things like them embracing Linux, acquiring and not ruining NPM and Github, contributing to open source projects, and all the work they've done with Dotnet Core seem to really have bought them a lot of goodwill, at least with the people I know.
- wizzwizz4 6y ago> Things like them embracing Linux Have you seen the WSL2 DirectX support?[0] They're extending it, too! [0]: https://news.ycombinator.com/item?id=23241040 https://news.ycombinator.com/item?id=23241040
- oblio 6y agoThey'll extinguish desktop Linux any day now!
- phendrenad2 6y agoIt's funny because Linux did just that to Unix. Embrace (new OS that does everything Unix does, and free!), extend (Linux has features not found in classic Unixes), extinguish (Linux is now the de facto standard, so anyone who wants to use Unix is laughed at). Microsoft gets mocked for embrace/extend/extinguish, but really, it means just do a better job than the competition. Embrace: "do what others are doing", extend: "do a better job at it, have more features than the competition", extinguish: "sell customers on those features and improvements". How anyone could be against competition, simply because it's framed in a cheesy phrase, is beyond me.
- frombody 6y agoVery curious as to the details they aren't releasing. If you read between the lines they are saying that accounts were compromised, but not through token stealing, which means the attackers got the passwords to the accounts, and likely skirted MFA requirements because they were already inside, or there were none. While there are many avenues to steal passwords once you have the foothold the attackers did, it would be interesting to know the details as to how these particular accounts were compromised.
- mc32 6y agoWith a large and sophisticated Corp like Microsoft, wouldn’t they have a Zero Trust kind of security model which means certs and MFA regardless of location, behavior, etc. Obviously a lot we can only speculate about.
- somethingwitty1 6y agoI've worked in big companies like Microsoft, so can only comment from that perspective. Due to their size, they often do not have MFA regardless of location. Many didn't even use MFA. Most have been moving there, but it was long, multi-year projects. So I wouldn't be surprised if Microsoft doesn't have MFA for everything.
- isbjorn16 6y agoMSFT employee here: I don't know of an internal service that I use that doesn't have MFA. I am not going to make a broad statement saying they don't exist, I'm just saying I haven't found one yet. It's really annoying because I rarely have my phone on me when I'm at home so I have to go track it down. I'd be so happy if they let me use a yubikey :(
- srtjstjsj 6y agoMFA was standard in industry leaders 10 years ago.
- SV_BubbleTime 6y ago
- Trisell 6y agoI predict a rash of eventual FireEye, Cisco, and other vendor zero days in the near to mid future. If you are a nation state actor what better way to find zero days then to get the source code and find the bugs to exploit. This is the only thing that makes sense that would be worth the risk of attacking companies such as FireEye and Microsoft.
- kevin_morrill 6y agoWhy would this actually be true? If it’s easier to find in source, Microsoft probably would have found it. Ever single feature there goes through multiple security reviews and there is tons of code linting. All the penetration testers I have met don’t even bother looking at source. They just start trying things they think will flummox the software.
- hguant 6y ago>They just start trying things they think will flummox the software. This works...until you go against a target that's heard of fuzzing before and has the time and money to do it to their own code. The really interesting Windows exploits require a combination of "throwing stuff that will flummox the software" and a deep level understanding of structures hidden to the average developer. Look at Yardin Shafir's really wonderful blog post about developing a kernel bug to a PoC - there's a lot of moving parts and security checks in modern windows, and having the source is a HUGE help.
- muricula 6y agoYardin Shafir's excellent blog post started with a bug found purely through fuzzing by an MS employee security researcher.
- kevinarpe 6y agoI tried Googling to find this blog post. Did you mean to write Yarden Shafir? If yes, maybe it was this blog post? https://windows-internals.com/printdemon-cve-2020-1048/ https://windows-internals.com/printdemon-cve-2020-1048/ I also found another hint about their findings in this PDF written by Yarden's co-researcher Alex Ionescu: https://www.usenix.org/system/files/woot20_slides_ionescu.pdf https://www.usenix.org/system/files/woot20_slides_ionescu.pd.... One of the slides specifically mentions the use of fuzzing tools to find these issues. If there are other, better links I don't know about, please kindly share. :)
- cs702 6y agoReading this, the question that immediately pops in my head is: Could a hack like this one go undetected for so long in a widely used free/open-source project developed in the open, such as the Linux kernel? While I have no doubt that something like this could happen to the Linux kernel source code (because security is Capital-H Hard), my perception is that something like this is less likely to happen to the Linux kernel -- and, were it to happen, it would likely be detected sooner, due to the inherent transparency of widely used open-source code.
- xen2xen1 6y agoCode was added once to Debian (IIRC) and it was detected almost immediately due to code signing.
- newacct583 6y agoThe exploit in this case had access to the build (and presumably signing) system. That wouldn't have helped. The protection against this would have been the comparatively new efforts at reproducible builds. A modified binary, in theory, could be detected by current Fedora and Ubuntu releases (not sure about Debian or other distros). I don't think we've had an attack in practice though.
- AnIdiotOnTheNet 6y agoOn the other hand, Debian broke OpenSSL generation and didn't detect it for almost 2 years. That appears to have been a legitimate mistake, but it is quite conceivable that a malicious actor gets a change merged that contains a backdoor that looks like an innocent mistake and goes undetected for a long time.
- aquaticsunset 6y agoAs others (and Microsoft) mentioned, it was read only access. The only points of concern here would be if that statement somehow was not true and they were able to add undetected changes, or if their security audit process was severely lacking. But yeah, to your point - being able to read and analyze the Linux kernel source is considered a feature, not a liability :)
- stewofkc 6y agoI think as hacks become more and more common, and as more businesses lose revenue from data breaches, more companies will adopt better privacy and data security practices. If someone "hacks" DuckDuckGo's databases, for example, they won't find any useful information. If they accessed Facebook's data storage, they would have tons of information about millions of people. As companies like Microsoft, Apple, etc. adopt stronger data security, I think the general population will shift their practices as well. This video (https://www.youtube.com/watch?v=eeBRt4qGHH8 https://www.youtube.com/watch?v=eeBRt4qGHH8) kind of made everything click for me as far as how a "hack" can impact a person beyond just the data being publicly accessible.
- netfortius 6y agoFunny usage of the MS defender for the link to the "inner source" wikipedia entry: https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FInner_source&data=04%7C01%7Crmcree%40microsoft.com%7C3c2b93314b6a4c82230608d8ada9c8dd%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637450292021293272%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=XfTuzoczzfzFR6DNm73DwrWSDpHPeMvWqTmBMFZVXzI%3D&reserved=0 https://nam06.safelinks.protection.outlook.com/?url=https%3A...
- srtjstjsj 6y agoSomething bizarre in that URL
- cheschire 6y agoSafe Links feature: https://support.microsoft.com/en-us/office/advanced-outlook-com-security-for-office-365-subscribers-882d2243-eab9-4545-a58a-b36fee4a46e2 https://support.microsoft.com/en-us/office/advanced-outlook-... https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/atp-safe-links https://docs.microsoft.com/en-us/microsoft-365/security/offi...
- sn_master 6y agoFunny thing is, MS Defender was originally written entirely in VB 6 (the 1998 one, not .Net). MS re-wrote it in C++ out of shame, mostly. https://web.archive.org/web/20150107212718/http://winsupersite.com/article/product-review/windows-defender-beta-2-review https://web.archive.org/web/20150107212718/http://winsupersi...
- pmlnr 6y agoIt's simple: open source Microsoft, then this is not an attack vector any more ;)
- gafferongames 6y ago> SolarWinds hackers were able to access Microsoft source code Are they OK? Ze googles, they do nothing
- userbinator 6y agoIf they were the ones responsible for leaking the XP source not long ago, then they deserve much thanks from the underground retrocomputing and software preservation community --- MS would've likely never opened that source themselves. In the same way that those who leak schematics and service information to enable third-party repair are also to be commended. "An enemy of an enemy is a friend."
- rychco 6y agoCompletely agree, hopefully we get an updated leak. Windows 7 would be fantastic to have out in the open.
- muricula 6y agoMS source code leaks to the public all the time. I think there was one early last year.
- icefrakker 6y agoAn enemy of an enemy is a friend is something only "useful idiots" say. An enemy of an enemy is nothing more than that. Keep on writing about how the CCP and Moscow are your buddies while they build a world where you're nothing more than a mute slave. I only wish people that write tripe like you could be shamed in person.
- natas 6y agoI'm sure they got linux's too.
- f430 6y agoThis seems like a very serious breach. Expect zero-days to run rampant the next 10 years. I don't know if to pat Microsoft on the back or give the ma scolding. If you are up against a military intelligence hell bent on discovering attack vectors produced by the private commercial industry then this is a losing battle-whoever has infinite resources win. In this case the governments of the world can print unlimited money and has to access to the top of the creme, we are talking 0.0001% of the population working on discovering the next zero day vulnerability. How does a for profit corporation go up against an adversary with infinite resources?
- deleted 6y ago[deleted]
- smichel17 6y ago> How does a for profit corporation go up against an adversary with infinite resources? The largest corporations are wealthier than some nations. Governments do not have unlimited resources. When national security depends on corporate security, governments can subsidize it with some other parts of their own "infinite resources". Not saying I disagree with your point overall, but this rhetoric rubs me the wrong way.
- f430 6y ago> Governments do not have unlimited resources. Who owns the money printers? Is it microsoft or is it the governments recognized by the USGOV? Who has control over the monetary supply? Is it microsoft or is it the governments who control respective central bank? Who has control over deciding whether microsoft is a monopoly or not? Again, its not the corporation. Sure you can have corporations richer than most developing nations but that has no relevance on the policy/power balance between government and a corporation. Even if all of the corporations in America formed a coalition, it is the government which has monpoly over violence that can decide out of whim if you are suddenly against them or with them. Why would basic facts rub you the wrong way? Do you believe that corporations can control the military, police and paramilitary forces in the Western world?
- tomcam 6y agoPractically speaking, being a bad guy with access to Microsoft source code for a short time has very little impact or real-world relevance. They do thousands of updates a day, the build processes are lengthy and poorly documented, the overall direction of the code is subject to myriad political groups inside the company, and they're making massive improvements in multiple branches that will render that snapshot irrelevant within minutes. The "best" market for any such code would be... what... China? Other than the possibility of figuring out potential hacks who could make use of the code in in its sheer mass? By the time you figure out something clever your version of the code is hopelessly out of date.
- mlyle 6y agoVulnerabilities have lurked for years and even decades in the Windows codebase. I'd not be so certain that having a snapshot today wouldn't help you find exploits for a long time.
- SV_BubbleTime 6y agoYea, how long was OpenSSL’s heartbleed an issue? And that was open source that was supposed to have millions of eyeballs on it. I agree, I don’t really buy that MS rewriting everything hourly and there is nothing to get from source.
- h3cate 6y agoThere are lots of updates to the Linux source code yet there's still quite a bit based on work done in the 80s
- rychco 6y agoI would love to have access to NT source code, hopefully it leaks. The most recent leaks are way out of date and have basically been exhausted of their usefulness.
- fadeleus 6y agoHo
- shallowthought 6y agoOf course, it absolutely HAS to be a nation-state. There's just no way anybody not being paid millions of dollars could possibly break their ironclad blah blah whatever you get it
- corona-research 6y agoMS SUX
- OpticalWindows 6y agoNobody has a choice but to trust microsoft. Amazing.
- LockAndLol 6y agoIf they had also inserted themselves into the update chain, things would've been a little worse.
- iam-TJ 6y agoMany comment threads here discussing the (in)ability of an attacker to modify the source-code that Microsoft builds from, or use it to more easily discover vulnerabilities. What I've not seen anyone discuss is the potential for an attacker to take the source-code of a single Windows core component (a system DLL for example), add in a backdoor, build it and then distribute the binary via a compromise such as the SolarWinds update mechanism. In other words, insert a modified core Windows DLL into some other popular Windows driver or application package updater published and signed via a 'trusted' channel other than Microsoft itself.
- NickGerleman 6y agoCode signing makes that pretty tricky. System DLLs will have integrity checks against msft certs.
- SCHiM 6y agoNot all of them. msimg32.dll has no certificate and many system processes attempt to load that. There are more dlls in system32 if you look. Neither does Wldap32.dll, which gets loaded into lsass and is part of the knowndlls...
- a-dub 6y agothe only interesting part of this whole debacle in my mind is that it highlights what was already fairly obvious. the security of a given environment is only as secure as its weakest link. the entire supply chain for every bit of code that is installed on a machine is a potential vector. if that code happens to run at privilege (like administration software) that vector is shorter. (and that's only if you're considering software) when you think about it, it's staggering. i suspect we'll be seeing a lot more attention on reproducible and cryptographically secure build environments, similar to the gitian stuff in bitcoin land.
- heresie-dabord 6y ago> the only interesting part of this whole debacle... security [...] is only as secure as its weakest link I agree that it is a staggering debacle; I disagree that the weakest link is the only point of interest. SolarWinds did not vet its build process and outputs; no antivirus, no government entity, no so-called intelligence agency, no mighty software corporation caught the compromise... for more than six months. The set of characteristics of this compromise is notable and there are many sobering conclusions. Also mentioned in this other, brief HN discussion. https://news.ycombinator.com/item?id=25580673 https://news.ycombinator.com/item?id=25580673
- Stierlitz 6y agoWhat's the logic of using the same remote monitoring software on "computers" used by the intelligence community.
- 8bitsrule 6y agoThere's a very old homily that applies exactly to this flaming debacle: don't put all your eggs in one basket. WP says that SolarWinds "had about 300,000 customers as of December 2020, including nearly all Fortune 500 companies and numerous federal agencies." Everyone who thought that was a good idea, for whatever reasons - given the history of security - obviously screwed up badly. When -so many people- go -so wrong-, the problem is clearly bigger than the loss of 'too many secrets'.