News: 1611653405

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK Cabinet Office spokesman tells House of Lords: We're not being complacent about impact of SolarWinds hack

(2021/01/26)


The British government has denied being "complacent" over the Solarwinds hack as a fed-up peer of the realm urged a minister to "answer the question".

Lord True, the government's Cabinet Office spokesman in the House of Lords, described the attack as "a complex and global cyber incident" and said UK.gov was "working with international partners to fully understand its scale and any UK impact."

[1]

The Conservative minister had been [2]answering questions from the House of Lords over the SolarWinds hack, the largest supply chain security breach in recent years. Although the attack had been seemingly targeted at the US, parliamentarians are worried that the British government is simply brushing off suggestions that the UK was also affected, [3]which it certainly is .

Lord Harris of Haringey remonstrated the government for its "complacence" yesterday afternoon, noting "a large number of systems in the national infrastructure use SolarWinds software and have been compromised" and that "the House has not been told how many." He went on to ask: "Does not the reliance on these sorts of commercial software solutions

such as SolarWinds

create a single point of failure for our security and economy as multiple systems, otherwise unrelated, can be penetrated simultaneously, potentially leading to a catastrophic collapse?"

[4]

Lord True told peers: "I'll say it again, the government's response is not complacent and the NCSC is working to mitigate any potential risk, actionable guidance has been [5]published to their website . And we urge organisations take immediate steps to protect their networks."

Lord Clement-Jones, a Liberal Democrat peer whose [6]written query had brought the minister to the [7]Lords' Westminster debating chamber , tartly responded: "Answer the question!"

Lord Browne of Ladyton, a Labour peer, went on to describe "21st century mercenaries" involved in some attacks – it was not immediately clear what he was referring to, though some Russian APT crews have previously shown signs of going (even more) rogue – and asked the minister: "Can we be assured that the government review will consider whether our cyber capability and our regulatory infrastructure is fit for purpose in the face of this emerging threat?"

Backdoored SolarWinds software, linked to US govt hacks, in wide use throughout the British public sector [8]READ MORE

Replying for Her Majesty's Government, Lord True said: "The government is certainly giving attention to that, seeking to promote cyber skills and seeking to encourage a sustainable pipeline of homegrown cyber security talent."

Evidently frustrated by the minister's smooth denials, Baroness Hayter, another Lib Dem, quoted Microsoft security 'n' legal veep Brad Smith, echoing her Parliamentary colleague's praise for Redmond's comparatively "transparent" [9]communications about the SolarWinds attack .

The [10]SolarWinds hack was focused on compromising that company's Orion system management platform. Hackers unknown infiltrated SolarWinds' build environment to deploy an extremely carefully crafted set of exploits that let them include compromised code inside updates for Orion as the company itself compiled them. That code then gave the attackers a known route into any network running Orion.

[11]

SolarWinds' customers, aside from a telephone directory-style list of American government agencies, also included Britain's Cabinet Office, the NHS, the Ministry of Defence' and other critical government institutions and ministries. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YA-2RkYqKslxmBgHdccYrQAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.parliamentlive.tv/Event/Index/d0ef739f-f7be-4bbc-9491-79007fae12a2?

[3] https://www.theregister.com/2020/12/14/solarwinds_public_sector/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YA-2RkYqKslxmBgHdccYrQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.ncsc.gov.uk/guidance/dealing-with-the-solarwinds-orion-compromise

[6] https://lordsbusiness.parliament.uk/ItemOfBusiness?itemOfBusinessId=89848&sectionId=38&businessPaperDate=2021-01-25

[7] https://www.parliamentlive.tv/Event/Index/d0ef739f-f7be-4bbc-9491-79007fae12a2?

[8] https://www.theregister.com/2020/12/14/solarwinds_public_sector/

[9] https://www.theregister.com/2021/01/21/microsoft_solarwinds_deep_dive/

[10] https://www.theregister.com/2021/01/21/microsoft_solarwinds_deep_dive/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YA-2RkYqKslxmBgHdccYrQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/

Largest attack?

Eclectic Man

The article states: "The Conservative minister had been answering questions from the House of Lords over the SolarWinds hack, the largest supply chain security breach in recent years."

Shouldn't that be "the largest KNOWN supply chain security breach in recent years"?

The Enigmatic Endemic Novel Security Systems Start-Up Problem

amanfromMars 1

Replying for Her Majesty's Government, Lord True said: "The government is certainly giving attention to that, seeking to promote cyber skills and seeking to encourage a sustainable pipeline of homegrown cyber security talent."

The difficulty government and Her Majesty's Government has is that it can all too easily catastrophically fail to recognise homegrown cyber security talent* and in so doing encourage it to exercise its skillsets elsewhere and for others, and that may not be necessarily in the best interests of a homeland.

* ..... because of the extremely strange and peculiarly unusual nature of its effective disciplines.

Anonymous Coward

What's the worst that could have been exfiltrated? The "off button" for the domestic internet? The abort command for Trident? Some embarrassing expense claims? Got to frame it in terms that can be readily grasped. Cyber-this and hack-that doesn't really cut the mustard.

Meh

Peter Prof Fox

I thought Government plans were kept on the back of a fag packet. They 'lose' those all the time and just jot down something new as they're told. You know, "Schools MUST reopen for one day before Christmas."

45RPM

Recent governments, and the Tory party in particular, seem to have a real problem with ‘experts’ - whether those experts are scientist, engineers, whatever. What they seem to like are populists and their blandishments, regardless of how based in reality those blandishments might be. We’ve seen it with the covid response (which has lead to the highest death rate per capita in the world), with Brexit (which is only mildly inconvenient and expensive at the moment, at least compared with the raging storm of financial loss and disaster that it will become over the next few years), with the NHS (which absolutely won’t be sold off - oops).

Populism be damned. Let’s now listen to the science, pay attention to the evidence - and put any exceptionalist and jingoistic ‘feelings’ on the back burner for a while. Someone needs to hold our Government’s feet to the fire - and if it’s the LibDems then so be it (but, ultimately, this is a bigger issue than any one party).

"On two occasions I have been asked [by members of Parliament!], 'Pray, Mr.
Babbage, if you put into the machine wrong figures, will the right answers
come out?' I am not able rightly to apprehend the kind of confusion of ideas
that could provoke such a question."
-- Charles Babbage