back
183 comments
Statement from Microsoft President here on security

https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...

"One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation using text messages and encrypted messaging apps."

"a second evolving threat, namely the growing privatization of cybersecurity attacks through a new generation of private companies, akin to 21st-century mercenaries."

"As humanity raced to develop vaccines, Microsoft security teams detected three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19."

"One indicator of the current situation is reflected in the federal government’s insistence on restricting through its contracts our ability to let even one part of the federal government know what other part has been attacked. Instead of encouraging a “need to share,” this turns information sharing into a breach of contract. It literally has turned the 9/11 Commission’s recommendations upside down."

> and spread targeted disinformation using text messages and encrypted messaging apps

Given there are moves to make sure end to end encrypted messengers have backdoors for authorities, isn't this kind of infomation prepared to seed association of encrypted messaging with something bad, so that in the future when there is a talk about making these apps either illegal or making sure they employ backdoors, people wouldn't be outraged?

cyber mercenaries. Sounds cool.

On a more serious note though, it certainly appears this is how its going. APT41 turned out to be some private company in chengdu and APT39 I think it was some outfit in vietnam. Its pretty interesting (cool?) to think that some of these global cyber-threats are essentially just a handful of people in some non-descript office somewhere.

How will this even begin to be remediated (the broader hack that is coming to light right now)?

It seems like malicious actors had unrestricted access to almost every major computer system in the US Government, and now possibly microsoft itself as well?

How are these people ever going to be able to trust any of this equipment ever again? This just seems unbelievably catastrophic.

Also, the rest of us use products they’ve designed to be basically unsecurable against them. The feudal model of security only works if the overlords are trustworthy and competent. We’ve known they aren’t trustworthy for a long time, but this shows the other side of the coin.
It could be incredibly expensive to clean up.

Remediation and recovery for most threats involves OS/app reinstallation, perhaps restoring from backups and images. However, if your threat is a sophisticated state actor based out of Russia, it's hard to rule out that they're got hooks in your server's firmware, that they've corrupted your backups as well, etc, etc.

One wonders how Russia could exploit the systems they've penetrated. Brick every gov't system on Jan 20th? Shut down SCADA systems? It's a cybersecurity nightmare.

As per the article, they used microsoft's cloud services i.e. azure for their attack, instead of breaking into microsoft's infra.
Incident response procedures exist to address this as does forensic analysis. But each org might fail at eradication (hardest phase of IR) and get reinfected. It is hard but doable imo
I'm waiting for someone to say blockchain
This is somewhat routine actually. Microsoft, and most other major tech companies, have been “hacked” many times.

Note that being hacked isn’t a binary state. What matters is what they were able to obtain. It could range from full compromise of the C-suite and domain admin, to phishing some marketing employee with no access to anything interesting. If anything, you should be afraid of companies who haven’t been hacked. It most likely means they’re either irrelevant, or they have been hacked and don’t know it yet.

This isn’t even the first time they’ve been hacked by Russians. It’s honestly not a big deal.

Open the code to public auditing. It's the only way.

A million eyes will make short work of the cleanup.

Microsoft has now categorically denied it.

"We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth. Perlroth said the company stood by a statement it issued on Sunday saying it had no indication of a vulnerability in any Microsoft product or cloud service in its investigations of the hacking campaign."

> Microsoft has now categorically denied it.

No, they haven't

> "We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth.

That's not a categorical denial of being penetrated, it's a denial of having information about being penetrated.

Microsoft's statement confirms that they had malicious software in their environment:

“Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.”

https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...

Microsoft has now confirmed it?

Microsoft found code related to that cyber-attack “in our environment, which we isolated and removed,”

https://www.msn.com/en-us/news/technology/microsoft-says-its...

>The U.S. National Security Agency issued a rare “cybersecurity advisory” Thursday detailing how certain Microsoft Azure cloud services may have been compromised by hackers

I believe there is common overestimation of security of cloud providers. Microsoft Azure was just breached and that's only what we know. There might be breaches at other cloud providers we're not aware of.

Centralization creates an exponentially growing incentive for bad actors. Decentralization has been given up too soon.

It is always events like these that make me ponder if the Internet will devolve into regional Internets, which still wouldn't necessarily prevent or stop any determined attacker from performing these types of attacks. So perhaps it's never.
Its like a firewall at the edge of your network: doesn't really protect you as any attacker that can get to the other side has free reign. You need defense in depth.

By the way, a piece of pedantry apropos a recent HN article: "...the Internet will devolve into regional internets." I.e. there is one Internet that connects to essentially everything; regional networks can practice internet working but aren't the proper noun "Internet"

I think that's the answer.

In order for a country to cut itself off effectively enough, it has to be (a) huge enough to replicate any service its citizens might want that is found elsewhere and (b) authoritarian enough to crush/jail/imprison/ostracize them for circumventing it.

So far even Russia hasn't managed both. I don't think any country but China can pull it off, so we're looking at worst case a Real Internet and a ChinaNet. The only other countries that will succeed will be backwater countries dooming themselves to perpetual backwater status (I can name a few but won't).

I think you could have both, one national network and another global network.
Does anybody have any details on the Russia attribution? Not looking to start political flame bait here just curious what details are out there.
Based on what i've seen, the official statement is the only indication that it was an adversary

https://www.solarwinds.com/securityadvisory#:~:text=.%20We%E....

> We’ve been advised that the nature of this attack indicates that it may have been conducted by an outside nation state, but SolarWinds has not verified the identity of the attacker.

Very curious why people are so strongly resisting the idea that russia is a prime suspect in this.
Searched for ‘solarwinds russia’, common phrases:

Probable Suspected Alleged Linked Unnamed Probably Highly Likely

I think that sums it up, there are none.

> Does anybody have any details on the Russia attribution?

FireEye (who discovered the SolarWinds breach when investigating their own breach) have said they are currently unable to attribute it[1]:

"While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor [FireEye subsidary VP Carmakal] said"

However US Subcommittee on CyberSecurity member Senator Richard Blumenthal said about it:

"Stunning. Today’s classified briefing on Russia’s cyberattack left me deeply alarmed, in fact downright scared. Americans deserve to know what's going on. Declassify what’s known & unknown"[2]

Having done some work in this field, attribution is definitely possible and fairly reliable with enough data, but releasing that data is usually not done because it shows what data sources you have access to.

I'd be relatively confident that there is classified sources showing it is at least probable[3] that the source is Russian if subcommittee members are tweeting that.

Edit: FireEye/Mandiant has a good primer on how they do their tracking of unknown groups. Attribution is similar: https://www.fireeye.com/blog/products-and-services/2020/12/h...

> Not looking to start political flame bait here just curious what details are out there.

Just wait until you see what happens to this reply. But <shrug>.

[1] https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...

[2] https://twitter.com/SenBlumenthal/status/1338972186535727105

[3] Probable in the "words of estimative probability" sense. https://en.wikipedia.org/wiki/Words_of_estimative_probabilit... and https://www.cia.gov/library/center-for-the-study-of-intellig...

I wonder when we will hear the news that all major clouds have been breached and data has been leaking for months/years...would be interesting to see. My wet dream is that people ditch the cloud to hold their own infrastructures.
My wet dream is to heat the freezing homes of poverty stricken elderly people in the UK using the byproduct heat from the ultimate distributed cloud.
And, of course, unrestricted access to Microsoft leads to unrestricted access to nearly any company on the world.

I need some popcorn.

The continued popularity of windows on corporate machines (especially dev machines) is the greatest evidence that the software market is completely incapable of judging software.
The most scariest part from this is Homeland Security saying that Solarwinds wasn't the only vector used by the APT.
Link to this?
I’m hesitant to blame anyone before we understand the full scope. “Breached into Microsoft” could mean they hacked into a guest public WiFi access point.
And backdoors in everything is a good idea? This is beyond hilarious. The silver lining is that argument is 100% dead in the water going forwards.
If you're a cybersecurity consultant, you can practically dictate your salary at this point. What's $3,000/hour to the government or a Fortune 500 to recover from a cyberattack like this?

There must be a lot of all nighters behind the scenes.

Goes to show that you are only as secure as your weakest dependency. Allow and trust software into your organization built by a system protected by an obvious single factor password (which you didn't know about or ask) and no matter what else you did you are screwed.

I worked at a healthcare company that stored its production credentials (with no login auditing) in a plain text file accessible by half the employees and contractors and when I complained that this was dumb (and violated HIPAA) was told "we passed our audits and we trust our employees".

I am not surprised, it's a dirty little secret in the software industry that we employ a lot of Russian and other potentially vulnerable Eastern European software contractors. Not to blame anyone specifically, I mean the threat could equally come from India or China. Or even a direct hack. It could also be an insider threat from an American as well. Since software development is a complicated profession, it takes a lot of intelligent oversight to ensure that critical paths are secure; especially as we migrate to cloud and site wide solutions.
What is the actual evidence that the hack was done by Cozy Bear/APT29/Russia?

I keep seeing this information repeated all over the place, but no mention of how that is actually known.

Here's the link to the NSA Cyber Advisory mentioned in the article: https://www.nsa.gov/News-Features/Feature-Stories/Article-Vi...
Microsoft is working on the big government cloud solution defense contract, JEDI. Certainly a prime target for state actors.
I'm buying FEYE stock.
The more lockdown the more lucrative big hacks become.
hopefully private repos on github are safe
> Still, another person familiar with the matter said the Department of Homeland Security (DHS) does not believe Microsoft was a key avenue of fresh infection.

Thoughts on this? It seems unlikely to me that someone who compromises literally the enterprise desktop OS manufacturer isn't going to take advantage of the situation.

I wonder how much social engineering played a part in this?
[Edit: Question was answered in article]