4 ms·
It's amusing how these stories always include the breathless account of the genius hackers. It boiled down to a few thousand lines of code in a dll. There's onl
by ahi 3y ago
It's amusing how these stories always include the breathless account of the genius hackers. It boiled down to a few thousand lines of code in a dll. There's only so much genius you can get into a few thousand lines of code. In reality, SolarWinds did something stupid, then some of their customers connected it to the internet and didn't even firewall it. Hackers will always have success not because they're brilliant, but because there will always be some marks who didn't cross their i's and dot their t's.
- munificent 3y ago> There's only so much genius you can get into a few thousand lines of code. Einstein's paper that introduces E=mc^2 is about three pages long.
- loxias 3y agoI agree in spirit, and I also share an attitude of "if you're hacked, it's your fault." It's Not That Hard to choose to not run random binaries from the internet, and keep your ports closed. > There's only so much genius you can get into a few thousand lines of code That being said, Stuxnet? So clever. edit: Depending on the language or libraries, 1000 lines is a LOT. Cleverness is frequently in reduction or rotation, not addition. Choice of data structure, etc. c.f. the 'k' or 'j' programming languages.
- doubled112 3y ago> if you're hacked, it's your fault I'm on the fence about this. In a perfect world, I agree. In real life? "They" only need to get lucky once. I need to be perfect all the time, and it probably isn't going to happen. Don't get me wrong, it is always somebody's fault. If your is meant as in your business, I'd lean more to the agree side. Security basics are just a cost centre, right? And how are you supposed to vet a binary from a trusted vendor?