https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...
"One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation using text messages and encrypted messaging apps."
"a second evolving threat, namely the growing privatization of cybersecurity attacks through a new generation of private companies, akin to 21st-century mercenaries."
"As humanity raced to develop vaccines, Microsoft security teams detected three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19."
"One indicator of the current situation is reflected in the federal government’s insistence on restricting through its contracts our ability to let even one part of the federal government know what other part has been attacked. Instead of encouraging a “need to share,” this turns information sharing into a breach of contract. It literally has turned the 9/11 Commission’s recommendations upside down."
Given there are moves to make sure end to end encrypted messengers have backdoors for authorities, isn't this kind of infomation prepared to seed association of encrypted messaging with something bad, so that in the future when there is a talk about making these apps either illegal or making sure they employ backdoors, people wouldn't be outraged?
On a more serious note though, it certainly appears this is how its going. APT41 turned out to be some private company in chengdu and APT39 I think it was some outfit in vietnam. Its pretty interesting (cool?) to think that some of these global cyber-threats are essentially just a handful of people in some non-descript office somewhere.
It seems like malicious actors had unrestricted access to almost every major computer system in the US Government, and now possibly microsoft itself as well?
How are these people ever going to be able to trust any of this equipment ever again? This just seems unbelievably catastrophic.
Remediation and recovery for most threats involves OS/app reinstallation, perhaps restoring from backups and images. However, if your threat is a sophisticated state actor based out of Russia, it's hard to rule out that they're got hooks in your server's firmware, that they've corrupted your backups as well, etc, etc.
One wonders how Russia could exploit the systems they've penetrated. Brick every gov't system on Jan 20th? Shut down SCADA systems? It's a cybersecurity nightmare.
Microsoft won't be the last company ..
Note that being hacked isn’t a binary state. What matters is what they were able to obtain. It could range from full compromise of the C-suite and domain admin, to phishing some marketing employee with no access to anything interesting. If anything, you should be afraid of companies who haven’t been hacked. It most likely means they’re either irrelevant, or they have been hacked and don’t know it yet.
This isn’t even the first time they’ve been hacked by Russians. It’s honestly not a big deal.
A million eyes will make short work of the cleanup.
"We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth. Perlroth said the company stood by a statement it issued on Sunday saying it had no indication of a vulnerability in any Microsoft product or cloud service in its investigations of the hacking campaign."
No, they haven't
> "We have no indication of this," company President Brad Smith told New York Times reporter Nicole Perlroth.
That's not a categorical denial of being penetrated, it's a denial of having information about being penetrated.
“Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.”
https://blogs.microsoft.com/on-the-issues/2020/12/17/cyberat...
Microsoft found code related to that cyber-attack “in our environment, which we isolated and removed,”
https://www.msn.com/en-us/news/technology/microsoft-says-its...
I believe there is common overestimation of security of cloud providers. Microsoft Azure was just breached and that's only what we know. There might be breaches at other cloud providers we're not aware of.
Centralization creates an exponentially growing incentive for bad actors. Decentralization has been given up too soon.
By the way, a piece of pedantry apropos a recent HN article: "...the Internet will devolve into regional internets." I.e. there is one Internet that connects to essentially everything; regional networks can practice internet working but aren't the proper noun "Internet"
In order for a country to cut itself off effectively enough, it has to be (a) huge enough to replicate any service its citizens might want that is found elsewhere and (b) authoritarian enough to crush/jail/imprison/ostracize them for circumventing it.
So far even Russia hasn't managed both. I don't think any country but China can pull it off, so we're looking at worst case a Real Internet and a ChinaNet. The only other countries that will succeed will be backwater countries dooming themselves to perpetual backwater status (I can name a few but won't).
https://www.solarwinds.com/securityadvisory#:~:text=.%20We%E....
> We’ve been advised that the nature of this attack indicates that it may have been conducted by an outside nation state, but SolarWinds has not verified the identity of the attacker.
Probable Suspected Alleged Linked Unnamed Probably Highly Likely
I think that sums it up, there are none.
FireEye (who discovered the SolarWinds breach when investigating their own breach) have said they are currently unable to attribute it[1]:
"While some have attributed the attack to a state-sponsored Russian group known as APT 29, or Cozy Bear, FireEye had not yet seen sufficient evidence to name the actor [FireEye subsidary VP Carmakal] said"
However US Subcommittee on CyberSecurity member Senator Richard Blumenthal said about it:
"Stunning. Today’s classified briefing on Russia’s cyberattack left me deeply alarmed, in fact downright scared. Americans deserve to know what's going on. Declassify what’s known & unknown"[2]
Having done some work in this field, attribution is definitely possible and fairly reliable with enough data, but releasing that data is usually not done because it shows what data sources you have access to.
I'd be relatively confident that there is classified sources showing it is at least probable[3] that the source is Russian if subcommittee members are tweeting that.
Edit: FireEye/Mandiant has a good primer on how they do their tracking of unknown groups. Attribution is similar: https://www.fireeye.com/blog/products-and-services/2020/12/h...
> Not looking to start political flame bait here just curious what details are out there.
Just wait until you see what happens to this reply. But <shrug>.
[1] https://www.bloomberg.com/news/articles/2020-12-15/fireeye-s...
[2] https://twitter.com/SenBlumenthal/status/1338972186535727105
[3] Probable in the "words of estimative probability" sense. https://en.wikipedia.org/wiki/Words_of_estimative_probabilit... and https://www.cia.gov/library/center-for-the-study-of-intellig...
I need some popcorn.
There must be a lot of all nighters behind the scenes.
I worked at a healthcare company that stored its production credentials (with no login auditing) in a plain text file accessible by half the employees and contractors and when I complained that this was dumb (and violated HIPAA) was told "we passed our audits and we trust our employees".
I keep seeing this information repeated all over the place, but no mention of how that is actually known.
Thoughts on this? It seems unlikely to me that someone who compromises literally the enterprise desktop OS manufacturer isn't going to take advantage of the situation.