5 ms·
The article makes many jumps and some false claims. Example: "Russia, we now know, used SolarWinds' hacked program to infiltrate at least 18,000 government and
by intern4tional 6y ago
The article makes many jumps and some false claims.
Example: "Russia, we now know, used SolarWinds' hacked program to infiltrate at least 18,000 government and private networks. The data within these networks, user IDs, passwords, financial records, source code, you name it, can be presumed now to be in the hands of Russian intelligence agents."
Reality from the linked source: "The breach is far broader than first believed. Initial estimates were that Russia sent its probes only into a few dozen of the 18,000 government and private networks they gained access to when they inserted code into network management software made by a Texas company named SolarWinds. But as businesses like Amazon and Microsoft that provide cloud services dig deeper for evidence, it now appears Russia exploited multiple layers of the supply chain to gain access to as many as 250 networks."
There's a big difference between 250 and 18000.
Further it claims that the source code access is significant. As noted in this thread: https://news.ycombinator.com/item?id=25599210 https://news.ycombinator.com/item?id=25599210 all major Governments have had read access to the source code for Microsoft products for years.
The hack is extremely serious and for that reason it merits accurate claims, response, and technical actions. Fearmongering like this article does to push an opinion piece is not it.
- PeterisP 6y ago18000 customers downloaded the backdoored version so the attackers got access and could have gone into any and all of these networks. As far as we know, they did move forward in 250 or so and did not proceeed with the others (presumably because of resource constraints) - but still all those 18000 networks were infiltrated by the malware, and if I was one of these 18000 companies then I would not just assume that we got skipped - so at the very least that should result in 18000 careful audits to verify if the potential intrusion happened.
- djsumdog 6y agoThere was a 10~14 day time delay before it connected to its CNC. It minimized network traffic and was probably only activated for targets deemed worthy. People with a weapon like that don't want to be detected unless there is a viable target.
- intern4tional 6y agoThe malicious version had items in place that would cause it to not activate if certain anti-malware software is present or other environmental conditions were not met (like not joined to an active directory). This reduces the number from 18k to something less (still probably huge) but 18k is the max if perfect conditions are present. As for why the attackers did not proceed, resourcing probably had nothing to do with it and more along the lines of many of those customers were not interesting. Proceeding to load further malware stages in those uninteresting customers increases the chance of getting detected and given that the attacker was targeting long term persistent access to highly valuable targets, the attacker by design more likely simply left targets without valuable information alone.
- OminousWeapons 6y agoIt's probably both. Additional exploitation of targets was typically required to reach data of interest, and at a certain point you do get resource constrained having to deal with a high number of targets. It takes time to exploit them, it takes time to ingest and parse the discovered data, and even basic things like managing all the resulting shells takes time. Based on this, as you say there were likely a high number of targets who probably were not worth the time to exploit, especially when every exploitation action increases the risk of detection and cessation of the op.
- dralley 6y ago>There's a big difference between 250 and 18000. 18,000 networks were backdoored, but the Russians only chose to actively attack ~250 of the most "interesting" targets. Avoiding detection for as long as possible was deemed more important than e.g. exfiltrating data from cancer clinics in Indiana.
- CrankyBear 6y ago250 that we know of.
- dylan604 6y agothe old rule in espianoge is that some times the source is more important than the information, where using the information from the source reveals the source which means the source is no longer useful. whether that's a spy that gets jailed/killed or a patch applied to a vuln.
- optical 6y agoIf you do not claim a state actor as the culprit you would be considered negligent, doing so removes any whiff of guilt since who could compete against a state? Claiming 'Russia hacked me' is the new dog ate my homework. Reality is that it COULD be a state actor, but there is no proof ever presented in these attacks.
- OminousWeapons 6y agoIt's cost prohibitive for a small group to pull this off unless they are financed by a large criminal org. You're talking about a small company's worth of people to design the software, QA it, stand up and monitor the infrastructure, perform the follow on exploitation, manage the shells, parse discovered data from hundreds of targets, etc. That's probably millions of dollars in salary alone. The attack pattern also makes no sense for a criminal organization with this level of access. Why wouldn't you go after resources you could trivially monetize or data you would want to know about like customer data, IP, financial resources, law enforcement, etc? Reading government emails seems like a waste of time unless you are trying to resell the intelligence to interested parties. Going after FireEye red team tools seems like a very high risk waste of time. Lastly, you're taking on American intelligence with above the wire capabilities. You're telling me a group of this size has the opsec capabilities to evade the NSA? No one made a mistake?
- mistermann 6y agoFor the sake of discussion, let's say this must be a state actor of some kind. Has there been any evidence provided that this must be Russia?
- jc01480 6y agoThe methods utilized in this compromise are consistent with methods utilized in other attributed breaches not disclosed.
- mistermann 6y ago
- frombody 6y agoThe original reports from the us government stated that only 40 organizations got a secondary payload .. now they've upped it to 250. That's a 5x increase, and is pretty substantial, especially because each of these organizations are generally large, important, and were likely specially targeted for a reason. It's also important to get this message out because so many people are out there thinking that since they weren't on the initial list, that they are safe. That is not the case. The attack was much wider than reported, and this is a huge deal because it means there are likely still breaches that have not been found yet.
- killjoywashere 6y ago> only 40 organizations got a secondary payload .. now they've upped it to 250 Yeah, the more I know about USG cyber, the more I'm convinced the delta is simply those who have gotten around to a) finding the payload, and b) actually annotated it in their reporting system.
- agotterer 6y agoThe title claims it’s worse as we learn more. I personally didn’t learn anything from that article which wasn’t announced when the breach was initially discovered. The public still knows very little. It could certainly be bad, but no one is telling us how bad.
- joe_the_user 6y agoThe largest leap is claiming Russia in particular.
- anothernewdude 6y agoI mean it's 50/50 between them and China.
- joe_the_user 6y agoYou also have regional powers putting resources into these things; Iran, Turkey, Israel, even North Korea and so-forth. All a nation needs is a few hundred smart, well organized people in a building with fast Internet and a lot of machines. Any hacking tool or approach can be stolen or emulated. If you are well organized, you leave the "finger prints" of other groups as well as their tools.
- wp381640 6y agoThis is the m.o for a lot of these blog content mills. Link to well sourced and thorough original reporting (in this case[0]) and attach some unfounded and outdated greybeard stroking opinion around it and then file your piece for that day. This article is _terrible_ - from the "security through obscurity" sections through to Microsoft not taking security seriously (ask anybody who was around in the late 90s when they had issues - they essentially pivoted the entire company around securing their products) and complete ignorance to "dumping" Orion [0] https://www.nytimes.com/2021/01/02/us/politics/russian-hacking-government.html https://www.nytimes.com/2021/01/02/us/politics/russian-hacki...