3 ms·
Claming the hackers would have been able to compromise SolarWinds even with good security pratices does not absolve the company of having actual good security.
by OptionX 6y ago
Claming the hackers would have been able to compromise SolarWinds even with good security pratices does not absolve the company of having actual good security.
I know there are people that can pick a lock. Still gonna have them on my doors anyway.
- tptacek 6y agoThe article notes that none its analysis absolves SolarWinds, and repeatedly goes out of its way to knife them.
- grugq 6y agoMy problem is not with SolarWind but with the analysis that keeps raising the password as the one and only problem. “If only they had good password hygiene then the company would’ve been totally safe against the Russian intelligence services!” That is just not how things work. To go further. The password was on GitHub from 2017 to November 2019. The first test build to see if they could backdoor things was in October 2019. If the password was the problem, why wasn’t SolarWind hacked in 2017 or 18? The only explanation is that it wasn’t an operation that existed back then. It wasn’t a target for the SVR at that point in time, or they weren’t able to service it with their operational capacity. But regardless, the critical factor here is that the RIS started this operation, not that the password was bad or available on GitHub. (Or whatever the issue is with the password.) Let’s discuss whether the operational concept (CONOP) of hacking a civilian target to get into the supply chain and hit other targets is acceptable in cyber espionage. It seems to be acceptable because that is a methodology that everyone uses. My point has not been that you just can’t win against Ho Chi Minh, or that SolarWind was particularly negligent (or not, their security posture was abysmal but also irrelevant)... my point is that we should focus on what actually matters — the CONOP. Because if the US sanctions Russia for this operation then the US is locking itself and it’s allies into a position when this CONOP is off the table. If that is what everyone agrees with, fine. But it’s the real discussion to have. Not what sort of security SolarWind did or (realistically) did not have.
- Dma54rhs 6y agoWhy is it not possible that they didn't discover it or pay attention? Or what makes you think if someone gets pushed to github it gets immediately used? I'm sure it gets scanned and indexed by all sort of actors fast but they must work with incredible amount of information.
- jakelazaroff 6y agoI think the point is that if you accidentally leave your door unlocked, you can’t truthfully say “well, if I didn’t do that the burglars couldn’t have gotten in” while you also have ground floor windows.
- joe_the_user 6y agoIf we're using the door analogies... it seems like the solar winds attack came because someone figured out how to sneak-in the "doggie door" (hacked the auto-update function, maybe call it the "delivery door" like homes had 50 years). And problem wasn't so much that this happened (cause indeed, shit happen). The problem was all these key enterprises (Microsoft, government agencies, etc, etc) had "doggies doors" when really they should have only had the most secure doors themselves. And sadly, unlike the retail situation, where a bank can decide they want only a secure door to their vault, today's enterprises have basically decided the benefits of giving multiple access to other enterprises trumps the security costs, since they never pay the costs of bad security anyway.