SolarWinds: The more we learn, the worse it looks
zdnet.com
zdnet.com
Example: "Russia, we now know, used SolarWinds' hacked program to infiltrate at least 18,000 government and private networks. The data within these networks, user IDs, passwords, financial records, source code, you name it, can be presumed now to be in the hands of Russian intelligence agents."
Reality from the linked source: "The breach is far broader than first believed. Initial estimates were that Russia sent its probes only into a few dozen of the 18,000 government and private networks they gained access to when they inserted code into network management software made by a Texas company named SolarWinds. But as businesses like Amazon and Microsoft that provide cloud services dig deeper for evidence, it now appears Russia exploited multiple layers of the supply chain to gain access to as many as 250 networks."
There's a big difference between 250 and 18000.
Further it claims that the source code access is significant. As noted in this thread: https://news.ycombinator.com/item?id=25599210 all major Governments have had read access to the source code for Microsoft products for years.
The hack is extremely serious and for that reason it merits accurate claims, response, and technical actions. Fearmongering like this article does to push an opinion piece is not it.
As for why the attackers did not proceed, resourcing probably had nothing to do with it and more along the lines of many of those customers were not interesting. Proceeding to load further malware stages in those uninteresting customers increases the chance of getting detected and given that the attacker was targeting long term persistent access to highly valuable targets, the attacker by design more likely simply left targets without valuable information alone.
Based on this, as you say there were likely a high number of targets who probably were not worth the time to exploit, especially when every exploitation action increases the risk of detection and cessation of the op.
18,000 networks were backdoored, but the Russians only chose to actively attack ~250 of the most "interesting" targets. Avoiding detection for as long as possible was deemed more important than e.g. exfiltrating data from cancer clinics in Indiana.
The attack pattern also makes no sense for a criminal organization with this level of access. Why wouldn't you go after resources you could trivially monetize or data you would want to know about like customer data, IP, financial resources, law enforcement, etc? Reading government emails seems like a waste of time unless you are trying to resell the intelligence to interested parties. Going after FireEye red team tools seems like a very high risk waste of time.
Lastly, you're taking on American intelligence with above the wire capabilities. You're telling me a group of this size has the opsec capabilities to evade the NSA? No one made a mistake?
> The methods utilized in this compromise are consistent with methods utilized in other attributed breaches not disclosed.
I am unable to understand what meaning I should extract from your comment.
My expectation is that an answer to my question must be one of: Yes, No, or Unknown (and possibly accompanied by additional commentary).
Would a proper interpretation of your answer be either of these?:
- "No, there has not been any evidence provided that establishes that this must be Russia."
- "There has not been any evidence provided that establishes that this must be Russia, therefore it is UNKNOWN whether this is Russia."
Not particularly. It is no secret that Americans really don't like the Russian government, and there is precedence for APT groups associated with the Russian government attacking the US. I agree though that there is no publicly available data to support the assertion that Russia is responsible for this at this time. My earlier post was simply pointing out the low likelihood of an individual or independent group performing this attack. The high level of sophistication combined with their risky target selection suggests it is a nation state.
That's a 5x increase, and is pretty substantial, especially because each of these organizations are generally large, important, and were likely specially targeted for a reason.
It's also important to get this message out because so many people are out there thinking that since they weren't on the initial list, that they are safe.
That is not the case. The attack was much wider than reported, and this is a huge deal because it means there are likely still breaches that have not been found yet.
Yeah, the more I know about USG cyber, the more I'm convinced the delta is simply those who have gotten around to a) finding the payload, and b) actually annotated it in their reporting system.
This article is _terrible_ - from the "security through obscurity" sections through to Microsoft not taking security seriously (ask anybody who was around in the late 90s when they had issues - they essentially pivoted the entire company around securing their products) and complete ignorance to "dumping" Orion
[0] https://www.nytimes.com/2021/01/02/us/politics/russian-hacki...
Sure, some of their customers or customers' customers got exposed to attackers, and some government secrets may have been lost, and some of their tech employees had to do a bit of overtime and "reputation was harmed", but so what, why should they care? Is there any material impact on the company finances? Currently it does not seem that it's going to destroy their future sales and ongoing licencing revenue, and it does not seem that they are going to have any huge liabilities for negligence.
If anything, the consequences (or lack of them) to SolarWind and other historical breaches are a good illustration that in the current business environment intentionally cutting corners on security is a smart move as it saves you money but if you get used to harm many others then you just shrug, do some apologetic PR and move on, and the impact of reputation damage is small and fleeting.
In short if you are in the security field at this point you aren't being brought in to secure or stop anything you're there for upper management to point the blame at when the attack does occur. Because spending money on security cuts into revenue and profits and unlike not investing in paying off technical debt this has no material consequences.
And on some level that's even appropriate as generally the whole industry is vulnerable, it's reasonable to expect that the competitors have just as bad security as the breached company, they just didn't get breached because they weren't targeted by this particular attacker or because their breaches aren't (yet) detected or because they managed to hide and not publicize that breach.
The 2013 data breach at Target is a good example of the worst case scenario because it was the first major widely publicised case, all the newer ones had far less effect because people start to understand that the breached company is not unique (like they thought in 2013 about Target) and even then they lost just ~2.5% of customers, and regained the customer confidence after 2-3 quarters. So even in the worst case scenario, 97.5% customers won't drop you, and any effect is short term, as the Target case demonstrates.
(No shade being thrown; good on you for recognizing the opportunity and acting on it)
edit: source seems to be Washington Post article "according to people familiar with the matter, who requested anonymity"
https://web.archive.org/web/20201213220635if_/https://www.wa...
I’ve looked at the source code that Microsoft and others have realeased of the initial backdoor but I don’t see anything in those few lines that can positively attribute to anyone.
In fact, the only thing that looked familiar was the crypto that was used to create the sub domains on the fly that hid the victims Fingerprints looked similar to what has been used in mobile malware created by China but that is still too flimsy to attribute anyone to as well.
The question of whether it was Russia is not that interesting.
This thing of countries blaming other countries for attacks is getting boring. In cyber, there are no borders. If something is vulnerable, it's vulnerable. You don't need the prerequisite of APTs or 'sophisticated nation state cyber threat actors' or whatever. Attribution is boring these days and so much emphasis on Russia as if we don't know already they have their fingers in so many American pies.
These are things we really don't want additional countries knowing how to make.
Technically correct, and very wrong in all other ways.
Who performs the attack is a very real concern, because unlike some of us, the attackers likely have lofty goals in the real world which are aided greatly by their successes in "cyber."
(I maintain that anyone who uses the word "cyber" seriously today doesn't understand what they're talking about, in virtually all cases. It's fine to not understand stuff, by the way. Just be open to learning more.)
If Russia is able to find holes in Windows, the OS used by nearly every business on the planet, they will use those vulnerabilities to their advantage in whatever ways they require. They will obtain personal information about people, blackmail them, maybe. Who knows. Russia and others WANT to take down those who disapprove of them quite strongly. They potentially want to bring low anyone who has spoken bad about them publicly (if so, I'm screwed) or anyone who could have helped them in some way and chose not to. North Korea, Iran, Saudi Arabia, Russia (perhaps to a lesser extent) have real beefs with the US.
Information gained via incredibly catastrophic breaches like this one give real countries with real weapons real leverage against others, potentially. Especially if the vulnerability opens more doorways that would otherwise not have been accessible.
I've been divorced twice. DO NOT UNDERESTIMATE the lengths that people will go for revenge for even the smallest slights. Some people get absolutely drunk on the slightest bit of power they have over others, and they know that, so they accumulate leverage against their enemies, real or imagined, continually in anticipation of a time when it will be useful.
In short: this is a big deal. It matters who is behind it.
Furthermore, I am ashamed of some of the things my government has done with my tax dollars and in my name around the world, and I won’t be duped into defending my abuser in some state-level blackmail game.
I'm not afraid of the CIA or NSA or any other three letter agency in the US. They are doing what Congress has allowed them to do (mostly.)
What scares me is people like Mitch Mcconnell who somehow continue to get elected when polls show nearly the entire state of Kentucky wants him out. That is keep-me-awake-at-night level of scary.
EDIT: Source: https://projects.fivethirtyeight.com/polls/kentucky/
It was removed the day this hack went public.
I don't believe in coincidences.
In Georgia, a security professional proved that machines were not only attached to the Internet, but were getting updates from servers outside the country and had the ability to be updated in real-time.
This was never investigated.
https://medium.com/@micallst/misusing-osint-to-claim-electio...
The other key thing to understand is that Georgia had a full hand recount of the paper ballots which those machines tabulated. Even if they were completely hacked, they couldn’t rewrite the paper records and there’s no credible evidence of even a single ballot being changed much less the many thousands of them which would have been needed to make the electronic and hand counts match.
There were other allegations that Dominion machines were attached to local networks for updates during election night. Were they? I have no idea. There as no investigation. Only denial.
I personally have used dead people's names (with DoB and city) in a few of the battleground states and I could see they not only received a ballot on election night, but sent it back. How could this possibly happen?
This was passed off as 'fake news'.
I'm not going to repeat all of the other claims, but we had a bigger investigation on Trumps Russian collusion, which had a fraction of the evidence.
If I could put in a handful of names into a government site and see this, I can't imagine the amount actually in these databases.
The sickest part is that people just aren't curious. They hate Trump so much, they want to win at all costs.
After so much time has passed and state leaders have rejected any and all calls for investigation (and big tech sites have censored anyone that questioned it), even if there was evidence at one point in time, it would be long gone by now. These investigations should have been immediate.
The Democrats are now going to usher in some of the worst laws imaginable for free speech. It has already started with the de-platforming of Parler.
At some point talking time will indeed be over, and it will be a time for action.
Who gave you the list of dead people? How did you verify its accuracy and rule out things like that case with an older woman voting as “Mrs. [dead man]”? What did reporters say when you contacted them?
> I'm not going to repeat all of the other claims, but we had a bigger investigation on Trumps Russian collusion, which had a fraction of the evidence.
That’s just silly: we have a mountain of evidence from multiple governments’ investigations into Russia’s activities and it’s had extensive hostile cross-examination. In contrast, we have a pile of unsupported allegations rife with errors and bad faith claims which the president’s own lawyers kept dropping because they knew that they didn’t have a case. That’s why Trump had to pressure people to manufacture fake votes because the real ones didn’t give the answer he wanted.
Take a look at the number of vulnerabilities reported to US Department of Defense via Hackerone: https://hackerone.com/deptofdefense/hacktivity?filter=type%3... (and these are just the ones publicly disclosed, a lot of them remain undisclosed, you can change the filter to see how many are reported in last few days/hours)
And taking this single report as example: https://hackerone.com/reports/761790
Reported at: December 19, 2019 4:19pm +0000 Resolved: 1 Month ago
And this is when there is no bounty attached to these, just some Hackerone points which help you gain higher reputation and possibly win some private program invitations. Imagine how many reports a monetary reward would bring in. I would really be surprised to know that adversaries are not already hoarding the flaws, especially when this is their daily business.
It was only a matter of time.
For decades, one of proprietary software's stupid assumptions is that "security by obscurity" works. While it can help -- no, really it can if used intelligently -- that's not the case with proprietary code.
PIE:
https://en.wikipedia.org/wiki/Position-independent_code#Posi...
Obfuscation:
https://en.wikipedia.org/wiki/Obfuscation_(software)#Obfusca...
In the SANS report a research tries to discredit people who claim this is CIA or a US state sponsored operation, yet also claim there is clear evidence of a "signature" from "Cozy Bear" ... what is this signature? Shell code? A known compiler flag? FireEye and SANS have released zero information on this or anything that connects things to Cozy Bear.
Also from that report, there were excluded IP ranges that were all Microsoft IPs (not all of the Microsoft IPs, but all the ranges belonged to Microsoft).
Vault 7 shows the NSA and CIA are involved in domestic operations (and if you go back far enough Church Committee) and there is a chance this was a US based State Actor. Let's not forget about STUX.
The level of this attack was incredibly sophisticated. It had built-in delays for several days to avoid network sandboxing tests in the CI/CD pipeline. It was signed and released from Solarwinds CI/CD pipleine as well.
Let's not dismiss Snowden so easily and not realize this could have been an American state actor as well (or even the UK, the EU or any other "allay" or enemy).
Which in weak cases can be an artifact observed throughout the attacks though not necessary for the behaviour to occur (e.g. compiler timestamp), and in strong cases the artifact is tied directly to the malicious behaviour (e.g. explicit registry key or anti-infection marker)
Even if US intellegence is pinning it on Russia or it was someone else, there's no way we're going to know about it right now.
Releasing attribution evidence right now will not happen as that would intrude on the response. Instead you will get signatures for specific pieces of malware or generalized yara rules to look for indicators of compromise. The specific indicator that allowed for attribution may never be released as then this particular adversary could work around it.
FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. If you have legitimate evidence that casts doubt on their statements please share it. Finding something that significant would shake up the industry.
Attribution is most likely a combination of evidence and forensic data collected both from the initial breach (SolarWinds) and other breached entities. Things like how data was exfiltrated and to where to who purchased and setup the domain names, any other malware that was loaded (was it signed, compiled, contain a certificate, etc).
While Snowden did reveal interesting things, there is zero basis to support anything other than a Russian state actor at this time.
I think a more likely outcome would be their stock price would drop for a few weeks, maybe executives would resign, and then it would be forgotten.
So was RSA when they accepted $10 million from NSA to backdoor their crypto library. As long as FireEye keeps the customers who pay the bills happy they'll be fine, just like RSA was.
We _knew_ at the time that Dual EC_DRBG was bad - there is an entire openssl mailing list archive from the moment it was announced/proposed talking about it being bad
FireEye / Mandiant are _the_ team within infosec who are experts in the field of attributing state threat actors - you won't find many experts who openly disagree with them
SANS isn't some secret government group - I have a colleague who is an instructor there. Those recordings aren't some top secret briefings. I and a lot of other industry professionals attended them
> " It's FireEye spewing out stuff as "facts" with very little evidence."
An APT has certain TTPs that allow you to start to figure out who is behind attacks. FireEye has tracked the attacker as UNC2452, which means it is "uncategorized" in their view. Others have come forward pointing fingers at the SVR.
Finally, just a tip: if you want to sound like you know what you're talking about, it's not a "CNC" it's a "C2".
> SANS isn't some secret government group
I understand that, but the video/livestream they released at the time was Unlisted on YouTube and had a watermark saying it wasn't for general release. I realize they didn't intend to have it up permanently and am familiar with the roles SANS has in the security industry. I was just commenting on the video and things I think they got wrong.
> Finally, just a tip: if you want to sound like you know what you're talking about
No need to be insulting. I've heard them called Command and Control servers before. I don't currently work in security; haven't in years. I'm just speaking as as developer/sysadmin.
If you genuinely don't know how companies like FireEye do attribution then one has doubt the level of insights you have.
Notably in this case FireEye said they COULD NOT attribute the attack to any group initially:
"FireEye wouldn't confirm the APT29 attribution and gave the group a neutral codename of UNC2452, although several sources in the cyber-security community told ZDNet the APT29 attribution, done by the US government, is most likely correct, based on current evidence"
https://www.zdnet.com/article/microsoft-fireeye-confirm-sola...
seems very very far fetched. i guess if i got caught breaking a ton of laws against my own government I might want to misdirect too
this seems like the same trolling type comment farm crap we see anytime these countries come up
This event appears not related to any country. Someone interested on sell private data would do something like this.
I thought this was common knowledge, but in a previous related thread my comment saying the same was downvoted with some replies about how MS engineers are security gods or some such. Interesting to contrast mainstream tech coverage with HN's RSU echo chamber.
Yep. I'm SURE it was just Russia. It's not like our government is perfectly happy squirreling away CVEs so our own intelligence agencies can exploit them themselves.
I just wanted to throw back to a childhood game :)