4 ms·
Doesn't a service like moveit just blur the lines between cloud and on premises? I mean how exactly did they find these 400 orgs fast enough, was it a centraliz
by fatfingerd 3y ago
Doesn't a service like moveit just blur the lines between cloud and on premises? I mean how exactly did they find these 400 orgs fast enough, was it a centralized command center?
You lost me entirely on the second paragraph. Some kind of militia attitude or trusting private armies probably means you are getting well beyond normal civilian behavior. You buy locks, you compare lock manufacturers, if you aren't the easiest of targets or the most valuable you represent a waste of time.
- _8j50 3y agoThey scanned the internet, they were testing their exploit for 1-2yrs before "d-day". > you are getting well beyond normal civilian behavior That is precisely my point, the threat actors are not civilians, so you can't defend them with the resources you have as a civilian. > if you aren't the easiest of targets or the most valuable you represent a waste of time. The internet changed power dynamics so that anyone on it can try to break the lock of your front door, including nation state sponsored theives. The lock in this case was more like a vault door keeping companies' secrets. Cloud vs self-host does not change who will target you, the difference is an in-house vault vs fort knox.
- fatfingerd 3y ago> That is precisely my point, the threat actors are not civilians, so you can't defend them with the resources you have as a civilian But this is leading to a crazy generalization. Microsoft can't defend itself as a civilian with a physical presence all over the globe that hires thousands of workers. Nonetheless, the sequence from solarwinds to this breach represents a terrific amount of China's focus.. Tearing through old data to find an expired key, probably also encrypted, and combining it with an active config error for it is a bit more than scanning for a standard attack against a class of old routers. If your data is pooled without e2e encryption it is in the middle of a capture the flag game and will be owned. For Microsoft to make a cloud that doesn't have to be secure from the most sophisticated resources of China they would have to stop assembling all that data so that it would have to be assembled with the boring and endless botnet scans on hundreds of thousands of different end points. Attackers will always get better at automating distributed scans but it is always a small percentage game that isn't as great as owning 3 clouds that each have equally good copies of about a third of this data.