4 ms·
Sounds like SolarWinds hired a good PR agency with the goal to deflect blame and make it sound like a big conspiracy. JetBrains being a Czech/Russian company ma
by dr_faustus 6y ago
Sounds like SolarWinds hired a good PR agency with the goal to deflect blame and make it sound like a big conspiracy. JetBrains being a Czech/Russian company makes it the perfect scape goat. As was pointed out, "solarwinds123" hints at very bad security practices which makes some unpatched system or weak password the much likelier scenario. It might well be that the intruders then manipulated the SolarWinds TeamCity config. Would have done the same with Jenkins...
- ahepp 6y agoOn a semirelated note, what's with all the articles claiming the attack represents an extreme level of sophistication? It sounds like the execution was skilled, but I haven't heard anything yet that seems technically novel or extraordinary. Maybe I haven't read the right articles, but it sounds like solarwinds got pwned, and all these big targets loaded the malware onto their own networks... Again, skillful execution, but it's not like they cracked an encryption algorithm or even did known-but-still-awesome exploits like rowhammer/spectre
- ballenf 6y agoIf Amazon's research is correct that 250 companies were targeted, that indicates just as a matter of a scale there had to be significant resources behind the effort. I'd call that sophisticated even if just in terms of organizational efforts. Additionally, doing this and not getting caught for 6 months or whatever takes significant discipline from every single person involved. You don't see that level of size, discipline and organization outside a handful of top companies.
- nitrogen 6y agoI haven't been following this story very closely. Was each and every organization individually targeted after the SolarWinds compromise was in place, or was it sort of opportunistic and automated, where the SolarWinds compromise phoned home and most of the 250 orgs just got automated/scripted escalation and exfiltration, and only a few orgs got personal attention?
- SAI_Peregrinus 6y agoSomething like 18,000 orgs got compromised IIRC, but the 250 are the ones where they chose to actually activate secondary payloads. So 250 got personal attention.
- Sattanics 6y agoMost likely attack on open port, then they sent automated some social engereening stuff, and while looking at it later they've found some fish to fry. Sorry for my English here, too complicated times from Finnish speaker.
- hn_throwaway_99 6y agoThere are 2 separate things going on, which often get conflated: 1. The actual malicious payload that was installed on the compromised networks was very sophisticated. It was discussed in the HN post when the news first went live, but the payload went to great and pretty ingenious lengths to hide its tracks and prevent detection. I remember a bunch of HN comments along the lines of "Wow, how did the companies ever even find that?!" 2. How SolarWinds was originally breached hasn't been released, and while the "solarwinds123" password is an unrelated issue, it does point to a pretty shocking lack of security culture at SolarWinds. I'm going to put my chips down on the original breach being quite simple and mundane, but SolarWinds will go (and has already gone) to great lengths to emphasize the sophistication of the attackers to try to deflect blame.
- zinekeller 6y agoI wouldn't be really shocked if this would turn out an Equifax-style attack (company negligence due to outdated software and lax security policies resulting to big advantages) combined with supply-chain attack (for customers of SolarWinds).
- SAI_Peregrinus 6y agoAnd given that the malware version was signed using SolarWinds' keys, it's likely the attackers just built and deployed their compromised versions using the regular TeamCity CI servers. No need to exfiltrate the signing keys if you can get control of the CI/CD system. It's less likely to be logged, it has the same effect, and such servers regularly contact the outside world to download dependencies. And if the admin password to the CI/CD was "Solarwinds456!" or similar (as seems in character, if possibly overestimating their intelligence by adding "special characters") it wouldn't matter what CI/CD software they'd used.
- deleted 6y ago[deleted]
- ryandvm 6y agoExactly. As a developer that has used the CI&D infrastructure to finagle some things I didn't quite have permission to do, it doesn't surprise me that CI&D is a good way to escalate permission after the initial hack. It is non-trivial to write secure deployment scripts/configs and ensure that access keys and credentials can't be leaked to anyone with dev access.