Microsoft says it found 1,000-plus developers' fingerprints on the SolarWinds attack
- Reference: 1613368627
- News link: https://www.theregister.co.uk/2021/02/15/solarwinds_microsoft_fireeye_analysis/
- Source link:
Speaking on US news magazine program 60 Minutes , Smith labelled the attack “the largest and most sophisticated attack the world has ever seen.”
[1]
“When we analysed everything that we saw at Microsoft, we asked ourselves how many engineers have probably worked on these attacks. And the answer we came to was, well, certainly more than 1,000.”
If anyone understands the havoc 1,000 developers can create, it’s Microsoft.
[2]
Smith didn’t say who those 1,000 developers worked for, but compared the SolarWinds hack to attacks on Ukraine that had been widely attributed to Russia (which denies involvement).
“What we are seeing is the first use of this supply chain disruption tactic against the United States,” he said. “But it's not the first time we've witnessed it. The Russian government really developed this tactic in Ukraine."
The 60 Minutes segment also featured FireEye CEO Kevin Mandia. FireEye also fell foul of the SolarWinds attack and Mandia revealed how his firm spotted the attack when an attempt at two-factor authentication raised suspicion.
US court system ditches electronic filing, goes paper-only for sensitive documents following SolarWinds hack [3]READ MORE
“A FireEye employee was logging in, but the difference was our security staff looked at the login and we noticed that individual had two phones registered to their name,” he said. “So our security employee called that person up and we asked, ‘Hey, did you actually register a second device on our network?’ And our employee said, ‘No. It wasn't, it wasn't me’.”
That admission led to further probing and eventually to SolarWinds, then to FireEye’s disclosure of Orion’s compromise.
60 Minutes also dropped a little nugget of insight by revealing that 4,032 lines of code were at the core of the crack.
Others featured in the [4]segment opined that it exploited a blind spot in US defences by running on servers hosted in America itself. Most US cyber defences look at activity beyond the nation’s borders and assume the private sector in the USA takes care of itself.
[5]
Which it tried to, but the nature of this attack meant it was devilishly hard to detect. ®
Get our [6]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCpUX-UYDmbcEw1FQQ0yDgAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCpUX-UYDmbcEw1FQQ0yDgAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[3] https://www.theregister.com/2021/02/01/us_court_papers/
[4] https://www.cbsnews.com/news/solarwinds-hack-russia-cyberattack-60-minutes-2021-02-14/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCpUX-UYDmbcEw1FQQ0yDgAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://whitepapers.theregister.com/
Re: Oh those Russians!
But doesn't M$ view Open Source and its Contributors as a bigger threat than Communism?
Re: Oh those Russians!
Why look abroad at all?
Isn't the hack DIRECTLY attributable to poor development processes in the organisation which was attacked?
Exactly how easy is it to insert an extra 4000+ lines of code into a process where multiple teams are delivering "new code" with every two week "sprint"? Maybe too easy!!!
Re: I know why they do it.
Are they covering up for the fiendish machinations of that usually little known independence group, the West of Lothian Free Separatists?
Re: I know why they do it.
West of Lothian Free Separatists
Splitters!
Re: I know why they do it.
"the West of Lothian Free Separatists?"
I question that.
How many of those fingerprints
are there because of the fashion for 'cut/paste' from sites like stackoverflow.com?
Thinking of it another way...
How else would MS be able to fingerprint so many if it wasn't for repositories like stackoverflow?
Re: How many of those fingerprints
Seems to me that Microsoft is one of the companies with over a 1000 developers.
Re: How many of those fingerprints
Microsoft probably needs 100+ people to produce Hello world.
Re: How many of those fingerprints
One code monkey to write the Hello World program and 99 to issue a steady stream of Hello World updates over several years to fix most of the critical bugs and introduce some new ones, amirite?
Figures
I never trust these kinds of guesses, how many times have they claimed something uncrackable only for it to be cracked that same day? *cough* Fairlight *cough*
Mind sure they would of been using code from all over the place, pointless redesigning the wheel unless it needs todo something new.
Yeah, must be those pesky furry Russians:
"The attack used a backdoor in a SolarWinds library; when an update to SolarWinds occurred, the malicious attack would go unnoticed due to the trusted certificate. In November 2019, a security researcher notified SolarWinds that their FTP server had a weak password of "solarwinds123", warning that "any hacker could upload malicious [files]" that would then be distributed to SolarWinds customers."
" SolarWinds did not employ a chief information security officer and employee passwords had been posted on GitHub in 2019".
"Insiders at the company had sold approximately $280 million in stock shortly before this became publicly known, which was months after the attack had started. A spokesperson said that those who sold the stock had not been aware of the breach at the time".
Seriously, half the stock market, many teenage boys and any UK/Iran/Mossad/Russia/Chinese hackers would want stock market intelligence like this.
The difference
Between 1000 Mshaft engineers causing havoc and the perpetrators of the solar winds attack, is that the Havoc1000 approach is chaos based, whereas the solarwinds attack was highly defined,seemingly well executed and didn't appear to rely on frequent patching.
So, maybe a hundred devs.....
...And your lucky colour is puce.
4.5K lines of core code and 1000 different developers identified. So supposedly a handful of lines of code is enough of a 'DNA sample' to distinguish one developer from another. How does that work? (None of them ever linted of course.) Perhaps they put their names in the in-line comments? // And a big shout-out to Vladimir Ruskyname for his trapdoor.
Probably only 50 guys/gals
They're just 20 times better than Micros~1 could imagine...
Personally, I'd go with Steve Davies 3 Idea of stackoverflows copy&paste.
2FA
Two Factor Access at work again, it's sold as "Authentication" but it's only effective when it works. It's a permanent security risk the rest of the time.
Re: 2FA
Yep - security works best when it's seen as security rather than a bit of a hassle.
The real takeaway
"If anyone understands the havoc 1,000 developers can create, it’s Microsoft."
Genius
> Most US cyber defences look at activity beyond the nation’s borders
Well that's stupid since my router sees twice as many attacks from US than from RU and CN combined.
Oh those Russians!
...or Chinese, or North Koreans, or Iranians, or Israelis, or GCHQ...
Why does the western media always accept the default of Russia bad, America good and always blame them accordingly?
Rhetorical. I know why they do it. Sigh.