30k U.S. organizations newly hacked via holes in Microsoft Exchange Server
krebsonsecurity.com
krebsonsecurity.com
Some of the detail on where this is a mess -
The relevant security update is only offered for the latest (-1) Cumulative Update for Exchange. So you can open Windows Update and it will say "fully updated and secured", but you're not. Complicating matters, Cumulative Updates for Exchange 2019 have to be done from the licensing portal, with a valid logon.
So maybe you have a perfectly capable 24x7 tech team, but the guy who manages license acquisition is on leave today. This is how you may basically find yourself resorting to piracy to get this patched.
For used devices off support contract, security incidents were a great opportunity to get free updates.
I always just got copies of the .bins from friends who worked at places that had contracts. They didn't gate updates at that time by which model you bought, once you had access you could get firmware for anything Cisco.
> As a special customer service, and to improve the overall security of the Internet, Cisco may offer customers free software updates to address high-severity security problems. The decision to provide free software updates is made on a case-by-case basis. Refer to the Cisco security publication for details. Free software updates will typically be limited to Critical and High severity Cisco Security Advisories.
> If Cisco has offered a free software update to address a specific issue, noncontract customers who are eligible for the update may obtain it by contacting the Cisco TAC using any of the means described in the General Security-Related Queries section of this document.
https://tools.cisco.com/security/center/resources/security_v...
OK
> but the guy who manages license acquisition is on leave today.
Then I wouldn't have "the" guy for anything.
Yeah uh, I don't think I wanna work for you then
The fact a critical security update can't just be downloaded is bad. I don't care if someone in sales thinks every licensed user should probably be able to get it. Here NCC produced a list of "valid" files to help people scan for not legit files. Except they don't have Exchange 2019 CU 8 because they couldn't get it:
https://github.com/nccgroup/Cyber-Defence/tree/master/Intell...
Microsoft has a hard limit (5?) on the number of individual accounts you can grant access and in a big enough org it's still plausible they'll be scattered across the world and you'll find none of them available the exact hour you need this update.
I know you’re trying to save the original comment but that comment can legitimately be taken the way the downvotes are taking ... that the commenter believes that guy should be fired for being away from his phone. Why legitimately? Because I’ve worked with people like that.
At that point, if you really have no other options, you pull the network plug. Or firewall it to internal-only. Email can wait for a day. And the nice thing about the protocol is that it will all get re-sent automatically.
Are non-standard retry intervals actually that common?
(Managers are very rarely jailed for anything except the most deliberate fraud; even negligence that gets people killed is routinely not punished at all)
There have been a couple of big GDPR fines for customer data breach, but obviously those are made against the company and not individuals.
It's a punishment system, not a justice system.
Is there a specific thing you want me to clarify?
He was not a victim of cybercrime; he was the “perpetrator” of something that was retroactively classed as cybercrime. I know you're upset, and angry – we all are – but that just isn't relevant to this discussion.
"Victim of being made an example of."
I never said he was the victim of a cybercrime. And it IS relevant because because it makes it unavoidably clear what I wrote that someone didn't read with proper care: The financial sector doesn't have this experience. - They don't have their own Aaron Swartz.
Clearly is is less customer friendly than 2016, but then Microsoft do REALLY want that sweet reoccurring subscription for Office 365 (or is it Microsoft 365 now?). Can't make it too easy to host your own Exchange server these days...
Is there a means of fending off these attacks on the political front? If this same level of espionage was happening in person, there would be a kinetic response but it seems everyone is happy to just turn the other cheek.
These attacks have a very real impact. Copying others homework is a tried and true way to get a technological edge and in practical terms, it means a lot of research and development money is effectively wasted as it doesn't generate any returns.
Mind, I don't think there should be a violent response, but it's odd that even the threat of sanctions isn't made whenever this happens.
For most businesses, air-gapping would mean we are back in the 20th century of business with filing cabinets and armies of people pushing paper between 2 rooms.
Basically the idea is defense in depth. The valuable stuff (design files, schematics, code, documentation) lives in the air gapped network while communications live inside a VPN and detailed technical discussion is often discouraged.
Hardware backdoors most probably.
No, I honestly don't think so.
> The US must have some fantastic assets if they are putting up so little fuss about solarwinds and this attack.
Actually they are putting up so little fuss because they are incompetent and castrated since the last administration.
I think this is one of the most ridiculous things I've ever read on HN, if not anywhere on the Internet. There are a few hundred native English speakers who are ethnically Russian/Ukrainian who speak fluent Russian in any one small neighborhood in a mid-sized city in the US, and there are dozens of such neighborhoods in the US, and the US is only 5% of the world's population. I personally know about 50 people who meet this description, I was at a Greek Orthodox christening with them last year! Not to mention that you can hire non-native English speakers who can read Russian, not to mention the new world of translation apps
If you mean the strategy as the end nears, it should be what it should always have been: trust no single product or supplier, implement multiple layers of defence for what is important. Maintain in-house expertise.
If you mean the "Lessons (never) Learned"... Train developers better, build better software through validation and verfication, train management to understand technology and risk. Humans become increasingly incompetent as complexity is scaled.
Everyone is doing espionage, no one is going to war because Microsoft has flaws.
The Soviets were better at spying than the West was, but their being better at copying the West than the West was at copying them didn't seem to help them all that much.
Obviously, you cant mitigate 0-day exploits in any situation where reasonable/expected network access is possible. But our concern, despite not being directly impacted by this, is that we may have accumulated malware over the past decade+ that has never been discovered. How many exploits exist in the wild which have never been documented or even noticed? Do we think it's at least one?
The thinking we are getting into is - If we nuke-from-orbit and then reseed from trusted backups on a recurring basis, any malware that gets installed via some side-channel would not be able to persist for as long as it traditionally would. Keeping backups pure via deterministic cryptographic schemes is far easier to work with than running 100+ security suites across your IT stack in hopes you find something naughty. It is incredibly hard for malware to hide in a well-normalized SQL database without SP or other programmatic features.
What if we built a new IT stack that was designed to be obliterated and reconstructed every 24 hours with latest patch builds each time? Surely many businesses could tolerate 1-2 hours of downtime overnight. It certainly works for the stock market. There really isn't a reason you need to give an attacker a well-managed private island to hide on for 10+ years at a time.
Rebuilds are mostly automatic. Of course, netboot in itself opens new attack vectors where we're in early stages of exploring different approaches, even the painful secure boot crap. Honestly I think most of the security in our case right now comes from being an obscure in-house solution that you'd need to specifically target. Also, in case you do get pwned, a post mortem becomes mostly impossible since once you reboot a machine, everything is gone except stuff on network shares of course.
A team gets to re-build while B team is running and the cycle repeats. This has a few advantages, it keeps the org very current with tools and technology, everyone stays sharp on the latest tech, nothing is sacred, and teams get experience across the spectrum of design build implement and run. It also has good Disaster recovery properties if you idle the old environment so that you can fall back if some critical failure occurs in the new environment.
This would be expensive, but please poke holes. I like your idea of clean rebuilds and can see a path to it with automation / terraform / cloud resources. And you don’t need the downtime if you stand up the second one in parallel and just fail over. There’s still persistent data that needs to carry through, so you’d need to figure out how to separate your persistent data from the elements that reset.
1) turnover 2) skillset
Some people are amazing at the architect/build side of things while either sucking at or hating the run side, and vise versa. Mismatched skill sets leads to higher turnover, which makes running an a/b team routine even harder.
I think the main drawback is cost - it essentially doubles the cost of staffing for the organization’s IT. I guess there is core functionality that could be shared and stay consistent.
Maybe I misunderstood, but I’m trying to recap your point:
The teams are on a 3 year production deployment cycle —
0.5y - design next gen system
1.5y - implement next gen system
0.5y - deploy next gen system
3.0y - production (primary, solo, backup; 1y each)
0.5y - decommission
Is that what you had in mind?
I think what a lot of people aren’t seeing is what it looks like with multiple cycles overlapping:
You begin architecture design on gen3 1.5y after deploying gen1.
The coding team rolls smoothly from implementing gen1, deploying gen1, and running gen1 into implementing gen3, deploying gen3, and running gen3. (Assuming minimal coders for the backup phase.) It even works out roughly for promotion cycles: an SDE 1 at the start of implementation for gen1 manages a service as an SDE 2 (2yr experience) and can get promoted to SDE 3 part way through gen3 in time for them to design gen5 (having seen two implement-to-maintain cycles).
On the production side, operations are continuous: your 3 years of production overlap with the other team by 1, making the entire cycle for a single team 4 years in length. Your production crew spends their entire time on a commission-operation-decommission loop. There’s no downtime: they go straight from decommissioning gen1 to commissioning gen3.
Expense is the negative: each team needs a full set of architects, coders, and operators.
But nuclear submarines have two teams for a reason, so I think there’s certain domains where operating two full development teams in lockstep like this makes sense.
I think it would help a lot with “legacy” bloat: to have upgrade cycles be a fact of the business structure.
The challenge is “how do we run this organization as efficiently and securely as possible? What tools does the business need in place to get the job done? Is our current set sufficient?”.
The fact that any company hands a new employee a Windows 7 laptop in 2021 shouldn’t be happening, but a surprising number of Fortune 500 companies are in that state because of legacy dependencies that require Win 7 to operate. I think the ability to give an organization the opportunity to reset every 3 years would keep things efficient, better integrated, and identify legacy issues that often come up and cause emergencies (the guy who wrote that script left the company 5 years ago and it runs on a server under this desk... we just don’t touch it).
Right now, upgrading a payment system may be difficult due to certain dependencies or other legacy internal systems. If the whole architecture is being re-done, there is a lot more flexibility.
The biggest requirement I see is automation. For this to be feasible in a general sense, it has to be down to a single method invocation completes in 1 hour what those teams are doing in 2-3 years.
The biggest challenge that will emerge from trying to meet this objective is the import/export of data to/from these now-highly-ephemeral IT systems. The ability to easily import pure business data back into a fresh instance of the system will likely constrain the vendor & product choices as well.
Very soon, you might find yourself building a 100% custom vertical to support these objectives explicitly. I think this is ultimately inevitable and desirable though. We just need to learn how to build these things quickly & reliably.
That would be amazing but incredibly complex. Each week I guess you would run a script to re-build your architecture in AWS with the latest builds and patches. Then run a config script to re-import all your data.
It would be painful to figure out, but you could essentially store a copy of your data at another AWS location and fail over within a day or two just given your two install scripts (the architecture build out and then the config script to read in the data), Depending how often and on how many systems you did this on, you’d basically make attackers restart every night or week. And ideally you’re patching as quickly as possible, so it might block some of them out quickly.
You're also assuming that you know ahead of time all use cases and interfaces. It's surprising how dependencies are taken. I've seen large scale systems break when a HTTP 204 was changed to a HTTP 206, or a base36 field changed to base62. Now again maybe you're thinking the consumer can stuff it and update everything whenever you decide to switch over, or that you'll have captured everything and have tests around it. But.. for any sufficiently complex system with a sufficiently large customer base everything about your interface becomes your customer contract. Changing everything all at once is going to break a ton of things nobody ever thought about.
Doing upgrades every 2-3 years means you're pretty much never going to be good at them. Institutional knowledge seems to have a 2-3 year memory horizon. Sure, you get that one person who is a bit of an archeologist/historian but tenure at most shops is not long ("The median number of years wage and salaried employees stayed with their current employer in 2018 was 4.2 years" - first hit on Google). While you're upgrading every 3 years, each team only does so every 6 years. Nobody is gonna remember what it looked like.
There's also a meta point, which is what are you actually trying to solve? Is it so hard to go from architecture A.v0 -> A.v1 -> architecture B that you need to build A, maintain A and simultaneously build B? If moving between architectures is so hard but moving between versions of an architecture isn't - why is that the case and why can't you make the former case easier?
I'm assuming that your plan has you upgrading the A-architecture within those 2-3 years. Maybe you're saying you wouldn't touch it at all and just hope there are no security issues or features or scaling you need to do.
There's also another point which is you've coupled all changes to a particular cadence. Maybe you want to upgrade your network, servers, storage systems, OS, application services, etc on different cycles. At the very least you're sorta hoping that all of those things have similar release cycles, which realistically you're going to be picking some network switch that's been out for 2 years and marrying it to a storage product that was released last month (because the previous one is 5 years old and will be out of support before your next refresh).
And scaling... what happens when you can't get the same server you were ordering 2 years ago? Tell users they can't have nice things until the other team rolls out their massive platform shift in a year? Or would you adopt a new platform to scale on, in which case, why are you doing this A and B team thing again?
And not only do you need two teams, but you need two sets of hardware which means you need twice as much datacenter space, etc etc. Do folks need to two desk phones when you roll that out?
And ... I'm gonna stop here...
I should have clarified the context and my experience. I was thinking this is a process for dealing with legacy bloat and mostly internal IT systems (IT Architecture) in mostly stable Fortune 500 size companies that are already operating at scale.
From what I’ve seen, big shifts are often a one time “transformation” with lock-in to a service. In cloud it’s azure or AWS or GCP. Or companies are stuck on legacy exchange and can’t move to O365 without a major initiative. Or there is no viable path to move from Microsoft to Google.
These things only occur with great pain, and resources aren’t often provided to reconsider alternatives and to stay current. I picked three years because things tend to operate at that pace at large organizations. It’s probably a faster upgrade cycle than where most of those companies are today.
It would be interesting to go back to the drawing board with the business lines to develop tech internally to better support them. Lots of stuff is just operating on terribly outdated systems. There is some lock-in (e.g. we’re going to use O365 for our office products for the next 3 years), but it would increase bargaining power because your org could actually migrate away.
For a lot of applications I agree with what you are saying - pick a good architecture and stick with it. And I don’t think there would be a need to change the way the company works for the sake of change, but I’ve seen enough big shifts that it makes me think a total redesign of an organization’s architecture every few years (or at least considering it) would be useful. Right now a big advantage to startups is that they can design much more efficient IT models than most legacy large corps.
I know if I could start from scratch I’d do a lot of things very differently and could show major cost, efficiency, and security improvements. So the idea would be to take a team who knows the company, break them off and say “build an architecture for the organization that will go live in 3 years” - take the best of the current environment and tool set, integrate new tech and security, and we will start moving users to the environment in 3 years. Then you get to run that for 3 years while the other team does the same thing.
You’re right on turnover point.
I think the whole goal of this would be to never go more than 3 years without seriously considering alternatives for major systems (ERP, HR, Security tools) while giving the chance to have it all be integrated and put into place as a cohesive design.
Inevitably an update is going to break something. So even if you can automate all of that, how can you make sure it doesn't break something? This requirement isn't just the automation and technology gathering, it's testing too. It seems to me like you'd need a lot more benefits to make this worth the time/money/effort. You'd probably be better off having 2 networks for employees: 1 for public internet and 1 for internal company stuff. I think the intelligence community has something like that?
(and if your infrastructure service provider(s) don't have suitable test coverage they can offer, perhaps it's time for a conversation with them about that)
This is a crazy huge hack. The numbers I've heard dwarf what's reported here & by my brother from another mother (@briankrebs).
Step 2.) Pay above market rate for talent, even import it from Israel or other friendly nation states. We need a Wernher von Braun style approach to recruitment.
Step 3.) ???? Profit ????
(I wouldn’t be surprised if folks start to push testing as a HIPAA issue.)
Hint, the I in HIPAA stands for insurance. If insurance isn't involved, HIPAA probably isn't either.
https://www.hhs.gov/hipaa/for-individuals/employers-health-i...
The few I asked seemed to feel they were _required_ to provide information if simply asked without a court order backing up the request. And they made it seem like I was the crazy one for asking that they agree to only provide my data if legally compelled. I ended up doing direct billing out of principle.
This goes for . . . well, how about most federal IT-related jobs.
It’s funny that you mention Israel. The would be one of the worst “allies” to partner with. Jonathan Pollard was just given a hero’s welcome. https://en.m.wikipedia.org/wiki/Jonathan_Pollard
Probably not. And that's also why cyber law enforcement and national cyber defense should be two separate entities.
The NSA has some military staff members but it is a civilian agency
Launching attacks during major news events surely also helped the attackers stay under the radar for longer.
Until you've personally experienced the full horror of attempting to keep on-premises Exchange patched, especially in the SME space where you may have few servers, it's hard to imagine how awful this is.
Cumulative Updates are essentially "completely uninstall Exchange" and then "reinstall Exchange again". This is not what one might call a "patch". Then you get into dependencies on .Net and suddenly you need to upgrade the OS as well while you're in the middle of completely-uninstalling-and-reinstalling-Exchange.
Last time I got sucked into this, I told my client it was nuts to run on-premises Exchange, to bin it completely and move to a cloud-hosted [Linux] IMAP mailbox system.
I wouldn't put out any new on-prem Exchange today, but the ones I support have reasons to be on-prem or planned migration off-prem.
Aside: I've been administering Exchange since version 4.0. I've never experienced "horrors" like so many people talk about. Failing to follow best practices, using dodgy hardware, and cutting corners are the reasons for problems that I've been privy to by way of friends, emergency engagements with non-Customers, etc.
I'm sure there are some SMEs who are happy to throw serious budget at doing on-prem Exchange "right".
For everyone else, I'm not sure what they're supposed to do.
I don't buy the "Exchange is expensive to support" argument. It's cheaper on-prem than paying for the subscription. We always saw break-even at around 16 - 20 months.
I have billing records for a small business Customer w/ a single Exchange 2016 server for last year that amount to 6.5 hours for the entire year, including installing CU's 16 thru 18 (CU 19 fell in this year). Yes-- a piece of their overall Windows Update application budget applies to Exchange, as does the amortized cost of backup software, and server computer and support hardware. Even w/ the OS license, Exchange license, and CALs at 120x an Office 365 E3 monthly subscription they're still money ahead over the 4+ years they've been running Exchange.
Moving to subscriptions results in a net increase in spend for organizations that were executing on-prem IT well and frugally. That's the only game now. I just think it's disingenuous to say that it's a cost savings. I reject the massive availability increase argument too, at least in the US, because of the lack of competition in the ISP space and the tier of service that is available to SMEs in their budget.
You spend more for the same stuff, are forced to "upgrade" (read: lose features, see changes in UI) at the whim of a third party, and may experiece decreased availability if you're unwilling to spend more on Internet connectivity. There "upsides" for sure, but too many people peddling hosted solutions fail to recognize downsides.
365 is a really good value, even comparing it to running an large scale standalone environment. Ditto for Google Workplace. For almost any other product, I subscriptions always drive more cost than value.
The
Some people disabled /ECP facing the Internet. It was "unsupported" by MSFT so I never did that. In retrospect it would have been worth the gamble. If I had it to do over again I would have taken that bet.
None of the compromised boxes I saw this week showed signs of post-exploit activity. They dropped their payload and left. Every compromised box was restored from backup, temporarily isolated from the Internet, and patched.
It was more beastly back to run back then though. We did reduce our risk profile at the time by putting OWA behind a sslvpn and only allowing BlackBerry.
But most Exchange management I do is mailbox management, and you have to do that if it's in the cloud too.
What did they reply?
It's possible that <Random F500 Co> has a great security team. But it's also possible that <Other F500 Co> doesn't.
It's quite funny in a way: regular mail worked for two hundred or so years without too much in terms of trouble, ok, we had some spam but that was about it. And now mail delivery has become so complicated that the mere act of accepting mail can lead to your corporate secrets being made public or lifted without your knowledge.
But you can still send it if you want that kind of security. There’s trade offs galore, but obviously the cheapness and convenience of email seems to have won out versus security concerns.
Email cam be copied and sent wherever without the operators knowledge, from anywhere with internet, if they break into the mail daemon.
In the digital world there is no such sentry.
Also, at some point the cloud provider may figure out that they can increase profitability by hiring more and more below-average people and just market them as world-class.
What I described is a situation of basically converting reputation into cash. Once you're known for having "armies of above-average developers" and then cut back on employee quality, it's going to take a long time for the market to figure it out (and you can probably extend that time significantly with slick marketing). In the mean time, you profit margins are increased.
Besides, it’s not really true today that clouds only employ “above average” developers. I mean hell, they employed me!
In part, this is the different service model: if I go to AWS and buy, say, S3 they have a very clear responsibility not to lose your data and to serve it quickly. If my CIO picks one of the bargain basement outsourcers and the centralized storage service fails badly, each different group will be saying that the failure wasn’t due to them but the company management, outsourced project management, the contractors who set it up/operate/monitor/secure, vendor products, vendor professional staff, Microsoft, etc. Since truckloads of cash will have been spent by then, many of those parties only care if it’ll reach the point of a lawsuit and everyone in the approval chain who didn’t say it was troubled before has an incentive to say the failure was unforeseeable and the solution is not to hold anyone accountable.
When you proceed to the logical end of enforcing simplicity to achieve security, you get OpenBSD. That's great for certain applications, but I think we can agree it doesn't check a lot of boxes for contemporary feature set demands.
My point being, achieving that is way harder than it sounds.
Speaking of OpenBSD, that might actually be a better OS for most stuff on the shop floor in companies that I have seen from the inside, where Windows is used almost exclusively. The plus being, nobody can really mess around with it. There is usually exactly one app that needs to run 24/7/365 with occasional opportunity to update e.g. during a maintenance window and that's it, anything that causes the app to close is lost time on the shop floor. OpenBSD being minimal is a large plus here.
Let’s say you are a big airline company, there is absolutely not a single reason you should manage your email system. Your job is to fly airplanes not to manage some goddam emails.
The really fun part in that is that most of the big airlines actually outsourced some key part of their core job (IT wise I mean), like how they manage seats and load, this kind of stuff, while keeping some absolute non-core IT services internal, like an internal Exchange system with dozens and dozens of people to manage it.
The state where big companies are make the second option impossible. That may be unfortunate, I don’t know, but that’s really where we’re at.
There is absolutely no way to cure big companies from all the shit they have accumulated. For them, the actual restart is to go to Cloud. Hopefully they will not go simply bare metal, because then they can recreate the exact same shit but in the Cloud.
One camp assumes if you don't expose it to the internet, and keep it on-prem, it's secure. Think exchange server on-prem (but let's overlook the gaping internet exposed parts - they don't see those, they see the fact it runs in their office).
On the other hand, it's public cloud, hosted service, rely on a big company with the resources (but accept loss of tenant isolation when something big goes badly wrong, and hope the cloud host has the skills to mitigate and detect issues).
We need more secure systems, but if they're publicly exposed then you'll require that team of experts around the clock simply to detect the potential of a compromise. Something I see a lot of confusion around is knowing when something is compromised. Responding is then "easy" in comparison for them, but they don't know what they should be looking for. With complex exposed services (mixed user and management plane over HTTPS, email interfaces for multiple protocols with different versions and authentication mechanisms), the likelihood of serious comprise tends towards 1.
Better hardening services would help to get some way towards the world you describe, but that has to filter through the whole supply chain and ecosystem - no, you shouldn't be able to manage the exchange server from outside, nor should any such interfaces be exposed. No, the exchange service shouldn't execute aspx code from folders on the local filesystem that can be modified other than through a privileged updater service.
But what we pay for is features.
https://offensi.com/2020/08/18/how-to-contact-google-sre-dro...
And the HN thread:
By consolidating targets when you can not even reach the level to protect a single one you are making the situation worse, not better by consolidating. For it to make any real amount of sense they would first need to demonstrate an ability to prevent attacks at least in the correct order of magnitude and then demonstrate that they can scale up without creating correlated risk. Only then does it make any sense to actually centralize on a single solution, let alone a single provider.
I'm not advocating for a single provider, and I'm not necessarily advocating for cloud hosting as a solution, I'm just pointing out that in this case the cloud fared better than practically all of the self-hosted systems
It's not the same OWA that one hosts on-premises. That one's still vulnerable even if it's hosted "in the cloud".
On a different note, if they could prevent this in "the cloud version", why couldn't they -- why didn't they -- prevent it in "the non-cloud version"?
Even if we assume that they did create two independent systems, there is no reason to assume that two products developed by the same company in tandem serving the same fundamental, lucrative use case should have material differences in quality/process. That there were multiple trivially exploitable, catastrophically effective vulnerabilities that were unknown for 8 years and that Microsoft never discovered themselves (they discovered it by realizing somebody else discovered it and was using it) should indicate that their cloud product is equally atrocious even if we assume that these were distinct products and thus would not be affected by the exact same bugs.
In conclusion, as you say virtually every computing system out there is a house of cards, so there is no reason to assume that consolidating on the cloud and letting one of those groups of people focus will result in anything other than more houses of cards, except in this case being used on an even juicier target.
The point is not if the Cloud can defend against a very sophisticated attack, the point is whether they can at least do a better job than what those big companies are doing.
And the answer is really easy: Fortune 500 are at the Stone Age of security (among a lot of other computer science topics) so of course the Cloud is doing better. It’s not even the same world or the same order of magnitude.
And the abyss will become bigger and bigger because it’s becoming more complex. There is no way a Fortune 500 company can keep up with the complexity of what AWS, Google or Azure is dealing with, and the new tech world we live in. And it’s also quite stupid, that’s not your job nor where you will be making money. Just concentrate on the app/code that is indeed your core job, on top of solid and proven Cloud services.
Also, you talk about centralisation and the issue of a single provider, well, here’s the actual joke: the level of centralization and concentration is way, way bigger internally than if it was on the Cloud. Most of those Fortune 500 companies have only a few datacenters. Although they are international, some even have datacenters only in their local region of origin, with zero region/local hub of some sort, as crazy as it may sound.
And most of those Fortune 500 companies have only one provider for each of their key component.
If they were on the Cloud (and they will be, eventually), reversibility and transferability is « built-in » almost, because it is an actual feature, or because everything is way more standardized, or just because moving into the Cloud, you will think from the start about how to move back or to a different provider. And in any case is much much better than the state there’s in.
Obviously, no engineer can have even a sufficient overview of the full Exchange Server implementation not speaking of full understanding. In such a situation security, quality and user (or admin for that matter) experience always take a big hit. It doesn't help Exchange Server is most likely developed using programming languages and approaches that more or less demand complecting the solution with OOP-related ceremony. Supporting two decades or more of legacy features and protocols doesn't help. Some companies even want to connect AD and Exchange to SharePoint... which is at least as complex as Exchange.
The problem companies don't understand is that you have to work on simplifying, which is very hard - much harder than adding features. If you don't, the interactions between components will overwhelm even the largest and best skilled team on the planet. The result is, we see breaches and security issues like this every day and realistically, nobody who can decide anything in the corporate environment gives a f** anymore because nobody pays the more or less laughable fines with their own money and nobody really goes to jail but the user data is lost, peoples lives are shattered.
Certainly, "in the upcoming version" is a bit late for those affected and most of those other Exchange-related hacks in the past. The thinking around Exchange is still more or less left in the 20th century and it shows.
This statement certainly doesn't help the credibility of your comment.
There's a reason why everyone uses microsoft exchange, despite all its myriad of flaws, and the flaws of its major client Outlook.
And it's because it offers so much functionality, precisely because it so much more complicated.
It's like saying you can secure your house if you build a 20ft wall round it with no gate.
Sure you can, but it becomes pretty useless.
Like the majority of awful “enterprise” products on the market, the primary reason that it’s popular is because it’s from a megacorp who speaks the language of the buyers, who are all aspiring megacorps. I was horrified the first time I used exchange and couldn’t wait to change providers the moment I had the chance.
So it’s more like saying you can secure your house if you use a security service who sets security targets instead of sales targets.
Sometimes being the least worst option is all it takes.
I call maximum shenanigans on this. Exchange is a fully-integrated groupware suite with a single-pane-of-glass on both the management and the user side. I am aware of precisely zero feature-complete alternatives, let alone anything "better".
So I’m sure that for some huge enterprises, the complete feature set from Exchange is actually necessary, or at least desirable. But for everyone else - including many companies I’ve worked in at a senior level, and almost certainly many of the victims of this vulnerability - I’d call shenanigans right back at you.
And you are right, loose coupling does rule out a very small set of functionality. For example an email sent to a user might have an smb: link, and then Outlook used to do a preview of the email, automatically loading all the links, which would cause your credentials to be sent to the smb:// server just by previewing the email, thereby allowing malicious attacker to steal password hashes by sending emails to victims (no click was needed).
So that would be an example of excessively tight integration and a design philosophy that was fast and loose with shipping both credentials and executables across the network. I think we have learned from those lessons.
In terms of why it is dominant today, it is because of fairly rational C level decisions, not users clamoring for it as opposed to some generic email/calendaring solution. Microsoft still knows how to do support, there is a large pool of cheap IT admins certified to work on it, and it allows you to run your own server instead of buying a service from gsuite. Really if Google could shed their disdain for human beings and learn to think of them as customers, they could take a lot of market share away from Exchange, because right now it is a trade off of security versus support - the functionality is basically the same.
Gsuite email doesn't even have good support for things like delegated access to shared mailboxes, treating them more like a distribution group. On Outlook they appear by magic on your sidebar.
Source: I am currently migrating some acquired users from gsuite to 365
You conflate functionality and complexity. If you think about it for a minute, complexity actually hinders functionality. There is some intrinsic minimal complexity to useful features of a software system for it to be functional. Exchange could be way more useful, if it wasn't so complicated and it could be a lot easier to keep somewhat secure.
Exchange in many circumstances feels more like a banks vault but instead of steel door with a wooden one with the cheapest padlock you can buy and a sign "we go here once a year to check everything is in order" where real banks usually work a bit differently... There are many cases, where an attacker gained access to the complete Active Directory through Exchange. At least so I was told by a company that did the consulting afterwards to clean up the mess.
Of course a server process which is designed to modify (among other things) group memberships needs different permissions than a user, why would that not be the case...?
If you don't like it being highly privileged, don't grant it the permissions. Or hire someone who can.
What on Earth OOP has to do with the quality / security of the Exchange? This reads like someone is on crusade.
You should really watch "Simple Made Easy" by Rich Hickey and think really hard about it. If you don't come to the conclusion that most software development could be way more sustainable in the long run would we use simpler tools and approaches instead of complecting everything especially with questionable OOP balast then maybe we have very different experiences.
I see nothing wrong with OOP. It is convenient for many things. It is not a silver bullet though. Nothing is. Personally I do not adhere to any concept / programming paradigm. They're just tools. I use many. Depends on what I am doing.
Generally one can take a tool and put it to good use while the other will fuck things up regardless.
It's a little easier to have foobar.update(), rather than update(foobar, state).
I started off mostly programming in R, so using mostly bare functions, but I have to admit that objects are really, really useful when you need to maintain state. Yes, you can do it with closures, but it's a little harder and a little uglier.
That being said, the mutability that makes objects useful is also problematic in that you can end up with magically updating references without defensive copying.
I don't know R and I don't really want to know it. For me, it doesn't seem to bring anything extra to the table that I couldn't do in Clojure or ClojureScript much more consistently and simply. If in my project, I have a number of transformation functions for my state, passing it around isn't a huge deal as it is just a nested map usually. It forces you to be very consistent and helps you as the project grows. Also, most of the functions are easily transferable between projects even when the state would have a very different structure.
Of course the whole thing is a complicated topic and in some cases you want mutability and local state e.g. because the performance is a bit better. Usually, that involves a few simple transformations.
And if you figure out how to fit a generalised additive model in clojure with one line of code, please let me know :)
So, in DS/stats you end up needing mutability because the datasets are really large, and the models take a long time to run, so copying is generally bad.
Convincing a developper to add features rather than remove requirement when the feature has no simple implementation in view :D
Actually, you want to work in a setting where you understand the need and value of a feature and how it fits into the overall design and feel of the (software/ hardware) solution to a problem. Is such a case, you understand that there is no requirement but a need or pain point that needs to be addressed, if you want to deliver more value to the user, some of which may turn into financial or other benefit for you.
Why? I don't see moving to a cloud solution being much better. The cloud service itself would be the single point of failure and would be just as vulnerable to a zero day. The organization would have even fewer risk mitigation options like NAT, firewalls, etc.
The patches were single file downloads, one for each version of Exchange, yes you needed to be on the latest Cumulative Update for Exchange, so if you weren't you really have no right running a production mail system...
Bear in mind after updating you still need to check if you were already hacked.
These days it's starting to feel like China might get to a point where they could shut down an entire country, all at once, with the flip of a switch.
It's not really one system. It just looks like that because it's one news story. If instead, all school districts were hacked this year and all police departments next year, how is that any better than both together? If it was one system like one network, your idea is even worse because having more different software increases the attack surface so hacking any one of those compromises the whole system.
Would you personally use uncommon software to avoid being part of a big hack like this? I don't think that's a valid way of protecting yourself.
Your idea would make sense if many of these institutions were just providing services that were redundant with each other. Then if some of them are disabled, the others can take their place. But a police department's email server can't do the job of a school district's one. And if confidential information is taken in a hack, redundancy doesn't help at all.
Only one vendor for all corporate email is bad for the same reason that only one popular variety of banana is bad.
Yes, but you're describing a more resilient system. A monoculture can get totally knocked out by one vulnerability.
I’d assume the enterprise segment is not as bad, but I’d also assume GP is talking about something along these lines - that you can’t trust vendors for anything these days.
Doesn’t seem more secure than traditional VPNs.
/s
And if you don't have proof, or can't show me the proof, then don't just blame Americas enemies. It's sloppy and dangerous.
But if they won't show proof yet it's nevertheless true and they have strong privately held evidence concluding it (perhaps from the NSA), that doesn't suddenly make it dangerous to blame the actual perpetrator.
It's only dangerous if they're doing it incorrectly or presumptively or deceitfully (which you don't know to be the case).
I can imagine they are sending an email to support@microsoft.com pleading for help. A future attacker would be well served to deny email to be sent to any mailbox @microsoft.com
EDIT: I'm now realizing that this follows the Microsoft-angle of the Solarwinds' attack. These customers are not going to be happy with $MS
Won't hurt MS in the long run. There is no viable alternative to switch to, for any of their products:
* OS: macOS runs only on expensive Apple hardware, Linux can't run business software, plus both have retraining costs for employees
* Office software: Libreoffice just... doesn't cut it, let's be honest. Apple's stuff only runs on Macs.
* Exchange: Lotus Notes is dead, and while there are open source solutions, there is no comprehensive single solution.
They (did? / are doing?) Edge for Linux though, for some reason.
My coworkers used Macs which really don't cost anything given hardware lasts 8+ years now. Most companies using Windows have a large budget for laptop IT that costs more than replacing expensive machines often if that were necessary.
At my previous employer they started to allow Macs and people were clamoring for them because they ran GREAT but after the first few thousand went out they started building up the amount of BS loaded approached being equal to the Windows ones and suddenly the satisfaction levels started to even out with the standard build. Chromebooks actually became very popular because they were even harder to be loaded with crap than Macs.
I'm not at all fond of the newer more disposable Macs. Still, they should perform pretty well. One of my coworkers installed browser themes that seemed to be crypto mining or something equally ridiculous once. You may want to create a fresh user without any personalization and see if problems go away. I find Mac users and PC users tend never to do a wipe/install and almost everyone tends to port their problems with them by bringing their home directory even to new machines of the same OS.
With a HP/Dell Enterprise line model all you need is a decent set of screwdrivers (and if you're touching anything that requires taking off heat pipes, skme thermal paste) and you can literally replace any part in a hour or two from a spare laptop - or you just swap the disk in a spare.
With Apple's newest shit you can't even do that since everything is soldered.
I'm a die-hard Apple fan, but for large shops professional machines are lower in maintenance cost.
So do big orgs actually have people internally swapping random parts in a laptop to see if they can fix it?
Doesn't change the point that Apple was more expensive, but mainly because Dell/HP prices go way down at volume.
Go look at the source, IBM. They started a pilot program, with power users, and converted them to Macs, and then a year in said that Macs need less support and cost less over their 3 year lifecycle.
See the problems? They couldn't know a year in about 3 costs over 3 years, and taking power users that demand Macs and saying they don't need support is obvious. That's a bullshit and obviously wrong "statistic" and source to use.
At most companies, a small percentage of employees will still need Excel for really complex/large spreadsheets, or Word for complex formatting destined for publication. But for 95% of people Google's good enough or better.
Year after year, Google keeps stealing more of Microsoft's customers, and it's extremely common for new companies to adopt Google rather than Microsoft.
Which country, and what level of education? In the US, cheap Chromebooks with GSuite have taken over K-12
And nowadays, I use excel (in part because I don't really work in a cloud-friendly industry).
So I guess my point falls apart pretty hard.
Word is an application that puts looks, thousands of mostly useless features and pixel-pushing up front. Excel at least really enables normal people to do some advanced calculations on data but the former still applies. Both are very complex tools mostly hindering any kind of value-added thinking and creativity but give you enough foot-guns and are really "fun" to support if you count Outlook in as well. I mean, how do you program an application that regularly crashes and corrupts the email database? LibreOffice is the same kind of thinking, because it mostly is a copy of the ideas in Word, Excel etc. Actually, when we are at it, Google Docs is more or less as problematic as the other tools.
Actually, just opening any of these applications seems a bit overwhelming. Why should you care that the readable font is 11 or 12 px big (it actually isn't that comfortable to read, but ok)? Why should you care that the default font is called Calibri or whatever? This is information and complexity that is shown by default that usually adds exactly nothing to your business. The same is with colours. Why should you want to have the option to select custom colours with two clicks or so when most people choose colours badly? The default colours offered are really not that great either.
I certainly would prefer plain text for most content a business generates, but the market has overwhelmingly voted in the other direction.
I believe for some interactions with the U.S. government Word is even mandatory. And it’s effectively mandatory for collaboration with everyone else.
Accounting and finance should know much, much better to use something actually auditable. Pretty much all software in any way associated with those industries that I have seen is at best average by enterprise software quality standards but most is barely useable. In that sense, Excel is probably the better choice. :-)
I’ve experienced this first-hand when building custom business apps. You’re building your UI in React or whatever only to conclude: “Fuck, this is a spreadsheet.”
I don't mind rich text and I know a bit of typography to avoid some common mistakes but I don't think most users really appreciate a full scale of sizes in pixels for a font or other information not relevant to the content they are producing. Most would be much better of using normal, small, large, very large for presentation or posters or something like that. The absolute values could be set in settings or overwritten somewhere maybe but Word isn't actually meant for designing websites or posters. It does all of those things to some degree but it very much isn't the right tool for the job in those areas and shouldn't be treated like one.
Btw. nobody can tell, if the businesses wouldn't be better of using something more robust than Excel even when that would mean actually training people to use a different tool. Most companies probably never train Excel, so even using that is very certainly inefficient. You know, there isn't much business value in Excel macros with viruses in them or macros nobody understands - so maybe what they calculate isn't even correct in some or all cases.
Excel is great for some things, but for many things it is used in practise it is actually quite bad. E.g. some people write working hours in Excel. There are much better apps just for that. You could have Google or Microsoft Forms, that are much easier and more robust. The data can then be used as well in a spreadsheet or imported into a DB. Unfortunately, Word and Excel (and Outlook) have developed their own gravity field in many industries and so the (very low) local maxima cannot be escaped (somewhat easily).
Having a government use anything as a stamp of approval does it a bit of disservice. If we would rely on current governments for innovation, we could just as well return to the caves directly. More seriously, if by collaboration you mean sending people word documents by email named final-assessment-v2-final.doc (because docx hasn't really arrived in many places and people suck at useable version control) then I am with you. Everyone else (including you probably) just writes the text into the email directly or uses something actually collaborative (for example Google Docs). The real final version is produced, after a consensus has been reached using more efficient communication channels.
The state of affairs is the market for pretty much everything currently is in a bubble. The US governments debt is more than twice the total amount of gold mined during the whole of human history (https://www.gold.org/about-gold/gold-supply/gold-mining/how-...) if a tonne of gold is roughly worth 60 Mio. USD. We haven't improved the working efficiency since the end of 90s much if you are frank. I wouldn't be so sure the market is a good measure of a products absolute quality actually.
I know everyone who has worked in an office setting can at least open and read a spreadsheet. I don’t know about an ms form or an access DB. The default (and sometimes only) ways most people can process text files on their machine is notepad or word. Word is way better than notepad for text processing.
If I send out a docx file, I know the formatting will be consistent when they open it. We can track changes easily without having non-technical people figuring out git or some other repo, and it will be compatible and easily viewable if we acquire any companies or are acquired.
The MS apps have basically become the standard applications to process plain text.
Lastly, I understand the value of some applications for data processing over excel. But when you’ve got to train up a new marketing or sales person every 6 months in R, that will get old very quickly. You can at least expect they know Excel and should be able to understand a spreadsheet.
Not very hard tasks to me - because I have done all of them hundreds of times. Other, even more advanced tools by Microsoft of course would fare much worse even with people like you and me, otherwise quite proficient with digital tools, if we haven't learned to use the one tool beforehand.
Yeah, Word is better than Notepad if what you want is to write rich text, but is it actually much better than WordPad from the usability perspective?
You have other problems, when your environment is so unstable that you have to hire new people every 6 months. Nowadays, you cannot expect any knowledge really unless the people can show a certification. Even a diploma in CS from a university doesn't mean the people know how to program useful stuff.
A new trainee every six months for a sales or marketing department isn’t crazy - it could be growing or a team of 6 people rotating out every ~3 years. I’ve bounced between WYSIWG and plain text, but there is a hard and steep learning curve when you ask people to use plain text.
Word also has spell-check and other features we take for granted.
You can't be serious. There's not much businesses need excel for?
I am not saying, Excel isn't useful in any case. I am saying, it is very far from a good solution in many, many cases and state concrete examples.
As long as those are true, I'm not sure you can say "there just isn't much you really need eg. Word for", unless you're never on the business side. If you deal with the people who use them, you probably also want to use them to avoid headaches. Network effects are a bitch.
If you're only ever slinging code, sure, congrats, you may never need to use either.
Note, I'm not arguing that either is good.
Heck, this year I watched someone struggle to find and license a third party add-on just to do a mail merge on Google Workspace.
Most of the time, actually stepping back a bit and thinking about the problem at hand for a minute can save many hours of tedious work. E.g. keeping track of hours worked - probably just use Toggl and export a CSV at the end of a month or something - much better UX overall than a form in Excel that you have to print out. Doing project planing in anything from Excel, over SharePoint, OneNote, Outlook Calendar etc. was always extra hassle in my experience. Everything kind of works but not really, you avoid doing changes, because it is very tedious.
I have seen all the enterprise "Export to Excel" web interfaces that are usually so bad, you cannot get anything done without the Export/ Import feature. I mean, Export/ Import is great but maybe you should just have na API and/or a useable web interface. There of course, Excel/ Spreadsheet is a temporary saviour but you should think about why do you have to use such a bad software system at all!
GSuite seems like the answer here. Mail, Docs, Sheets, Slides will work for a vast majority of businesses.
I do not believe without data that switch from one closed source proprietary software provider to another one will guarantee you from hacks.
Switch to open source most certainly does not. Nor is switching from one proprietary provider for your software from Microsoft -> google
That said, it's not the question. The question is if a company wanted to switch away from Microsoft here, what is their option? It's not an inherent statement that one is actually better, but that there is an option if one feels burned by Microsoft here.
Last week Firebase sent me a notification that several of my properties (some of them enterprise apps) had lost domain name verification. The panel in the console was clearly glitched when I inspected it. Two days later they sent a correction saying that this had been a mistake. No big deal, but it goes on to show that Google is not perfect.
Not to mention that GSuite already has 6M different customers/tenants. They're already at a comparable scale, and that doesn't mention that the free versions have the same application security model, with zero incidents (knock on wood). "but scale" feels like it's ignoring the already existing track record and scale and just making excuses for Microsoft.
And that's individual licenses. I can't easily fetch the number of medium to large companies on Microsoft Office vs GSuite but I wouldn't be surprised if it was significantly larger than 50x.
My original contention is that hackers may be particularly interested in that dimension, rather than in the number of individual licenses (which MS also dominates by an order of magnitude).
> “It’s massive. Absolutely massive,” one former national security official with knowledge of the investigation told WIRED. “We’re talking thousands of servers compromised per hour, globally.”
Microsoft Exchange server software , not to be confused with MS Outlook email software or the lesser Windows Mail software.
One that server is hacked, you may be wide-open internally.
I’d be at least as concerned about an Exchange vulnerability as I would be about Outlook, but probably more.
I used to work for a law firm which ran on-premises Exchange, but had OWA running behind a VPN. I remember finding it extremely inconvenient at the time. But they're the ones laughing now.
Or to replace email for internal use altogether. TMTP is a new protocol with that goal:
Hardly anybody does that, though.
If defense contractors keeping exchange on prem for security/compliance reasons are offering OWA on the internet, obviously there’s a deeper problem.
Isn't this the problem in replacing almost any technology that we know is "broken", it is often too ingrained to be replaced easily.
EDIT: you might never silence SMTP altogether, but a suitable protocol could supplant it for the great majority of its use cases.
The appearance of email being replaced exists in some places, but you find pretty quickly that you can't survive without it because it's still getting used for some critical communication or process.
The "new" email has been launched quite a few times now. It doesn't seem possible at this point unless all the major players agree on some new protocol which is seamlessly implemented in their mail services, while still allowing SMTP to function as a fallback to the improved protocol
I'm not aware of any alternative email protocol that's implemented, except TMTP. I don't believe closed-source, walled-garden services, which don't allow third-party clients or servers, really count as legitimate alternatives.
There's Matrix, but that's a synchronization protocol for chatrooms, not a store-and-forward messaging scheme.
https://en.wikipedia.org/wiki/Dark_Mail_Alliance
The stuff Ladar Levinson created after the Lavabit takedown, (famed for begin Snowden's email provider). Although I'm not just talking about email protocols; but additions or other improvements that always have the same problems (PGP encrypted email, or whatever Facebook tried to do when they reinvented email...)
I could see this being rolled out within an org where the one org can deploy clients & server to all internal users at once.
https://www.digitalocean.com/community/tutorials/how-to-use-...
this affects not only the operating system and platform itself, but also major applications, development philosophies, major utilities and even the approaches used to operate it in production.
it's actually an interesting question, while internet security problems largely outmoded old pc inspired designs and product-market fit (the diy part time sysadmin), will they outmode the personal operation of any software... that is, will computer security problems grow to the point to where everything must be actively managed and defended?
I have a client who was hit with ransomware that exploited holes in RDP. They paid Microsoft about 5% of their annual IT budget to upgrade.
How much more license revenue and 365 subscriptions will this latest fuckup generate?
And if vulns are this profitable, where's the incentive to prevent them in the first place?
Prior to upgrading their software, where was the incentive for your client to keep everything up to date and put in the infrastructure needed to patch all of their systems minutes/hours/days of a new zero day?
I can't speak for your customer (obviously), but do you think they would have invested 5% of their budget in upgrades for this particular hack? A ransomware attack shuts you down. This is blackmail/corporate espionage stuff. Very easy to ignore depending on what your company is saying in their email.
so basically for free / at low cost?
2. Do a speedtest
3. Add location and speed to remote desktop access marketplaces on darknet
4. Collect passive income from renters looking for clearnet computers in certain areas to use.
Often times all the known VPN IP addresses are polluted - even their "dedicated residential IPs" and this can ensure you have worse treatment on the internet, such as more captchas, outright bans, inability to use streaming services, and for actual criminals it means their stolen credit cards don't work. But with remote desktop marketplaces, you can find a computer near the postal code of the credit card you have and this ensures your online transactions go through. Obviously not "you" as you don't have to care what the people do on the other side of your tollbooth. Since you weren't the one compromising anything (computer, credit card, any actual spending) you'll be fine, but you're also going to do all this over Tor anyway. But because you'll be fine you don't have to worry about being detected due to some flaw in Tor because you won't have triggered a criminal investigation, the actual hackers and skimmers and thieves will have though, and incurred all the liability for themselves, people who will have paid an address on a darknet marketplace in Monero and gotten temporary access to a server.
but I also figured that the spike in traffic or someone messing up their botnet's activity windows would alert the computer owner to something
https://play.google.com/store/apps/details?id=mobi.biko.exch...
Description: https://support.microsoft.com/en-us/topic/description-of-the...
I suspect that the number of compromised software companies are much larger than these 2 companies. I'm almost certain that we will hear about others in the future. If you manage a software product I hope you are auditing the code regularly. You should also harden the security for it and who has access to the source code and its build no matter how unlikely you think you are a target.
Given one of the CVEs is CVE-2021-26857, there has already been more that 26000 vulnerability submitted for an CVE ID this year so there are indeed countless other compromised systems - the two big hacks of recent are only in the news thanks to their large blast radius.
They did find a tool left behind it seems.
I am just increasingly skeptical of these hacking stories that have a nat sec angle on them after the previous ones have been shown to be mostly or entirely fraudulent years later.
...they said, while providing no evidence to the public.
"Bombshell: Crowdstrike admits ‘no evidence’ Russia stole emails from DNC server"
https://thegrayzone.com/2020/05/11/bombshell-crowdstrike-adm...
Remember "Russia is hacking our democracy!"?
Tangentially, it could still be Russia going through China...
In this case, Microsoft is identifying the actor quite clearly:
https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nat...
If you have a reason other than your feelings about domestic politics for skepticism about this case, please share it.
(1) Not that Republicans wouldn't be above this, just that the Democratic party has a history of this particular tactic.
EDIT: My guess is that if they actually showed what they were basing this allegation on, a lot of people would conclude it was extremely weak stuff, maybe impossible to decide who did it if anyone did. Hiding information is extremely useful for spinning authoritative narratives. Of course let's not forget that NSA implants are probably present in strategic locations around China, but that's par for the course.
Telling the criminals, publicly and in detail, exactly how you know it's them is also extremely useful -- to them! -- in that they know what not to do the next time around. It's in your own best interest to keep that information secret, especially if you have any reason whatsoever to expect that it may be useful again in the future.
Yes, this requires that we simply trust Microsoft when they say it was $attacker. You can choose not to believe them, if you like, and demand to see all the evidence. I don't think that will hurt their feelings all that much -- and I also don't think you should hold your breath while waiting for them to give you that evidence.
Ultimately, it doesn't matter all that much -- as far as I'm concerned -- whether it was China or North Korea or Canada or New Zealand. I'm less worried about who did it than I am cleaning it up and doing whatever I can to prevent it from happening again.
Conducting a Successful False Flag Cyber Operation (Blame it on China) - Blackhat Europe - Jake Williams
Great point, although I wonder, isn't the goal for them to not do it again next time anyway? Seems appropriate to weigh the costs and benefits of continued detection versus sunlight as a disinfectant.
This statement still holds whether you replace "they" with "Brian Krebs" or "Microsoft".
Attributing blame on cyberattacks is a very difficult problem, as it's easy to cover and obfuscate your tracks. Even your tactics; using strategies and tools from other state-sponsored groups, for example.
[0] https://www.wsj.com/articles/china-linked-hack-hits-tens-of-...
Btw Microsoft, CERTs and a bunch of other orgs are also using Shodan to find out who is exposed. We already had all the data to determine vulnerability before the announcement was made so enterprise customers could search their local Shodan database for affected systems. And we've been sending out notifications as well.
Lovin' my membership.
The question that comes to mind is: to what extent did Threat Actors have unfettered access to security bulletins?
There is no easy solution to the issue. Thank you for bringing this up.
> On March 2, Microsoft released emergency security updates to plug four security holes in Exchange Server ...
> ... [Volexity] first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021, ...
If it still wasn't apparent by then, though, I would have thought that this line should've cleared things up:
> We’ve worked on dozens of cases so far where web shells were put on the victim system back on Feb. 28 [before Microsoft announced its patches], ...*
edit: this tweet restates this in a much nicer way:
https://twitter.com/SwiftOnSecurity/status/13668672289148108...
> If you're not an F50 running your own Exchange Server is organizational clownery at this point.
However, NSA, has been around a long time. Dont forget about them.
If by "applying digital force", do you mean attacking other countries?
If so, does the same apply when the US destroys computer systems in other countries? If your country is attacked by the US what force are they reasonably allowed to use as a counter attack?
You ruin one or more nuclear weapons facilities; they get to destroy a few nuclear installations of several types in the US?
The US is not sitting around being the innocent victim. The US is engaged in offensive attacks on regular basis.
(At the same time the US is engaged in massive real world war as well. Unike most of its counterparts. Oh "military conflicts" not war. Unless you are the country at the receiving end of "military conflict" in which case you will have to spend a lot of time trying to figure out why it is not war.
None has the mission of broad national defense of civilian assets from cyber warfare by foreign nation states.
Almost like a certain company would like to get its customers to migrate AD to Azure and Exchange to full office 365.
If the hosted version lacks the component that has a security issue, it won't have that issue, it is technically misinformed to conclude anything nefarious.