Like razor blades in peanut butter cups, says CrowdStrike.
Like razor blades in peanut butter cups, says CrowdStrike.
The SolarWinds hack was a devastating attack on our sovereignty.
And so is the other.
Do you have any idea what America did in Russia in the immediate aftermath of the fall of the Soviet Union? The 1996 election in Russia which was majorly "interfered" with by Clinton: https://archive.is/R7i5u, not to mention the fact that most Russian hacking activities are done using NSA backdoors which were leaked?
I'm surprised and disappointed to see such flagrant ivory tower imperialism on HN.
But targeted ads are?
I think it's a mistake to minimize Russian influence, when it suffices to compare the unmitigated disaster of U.S. actions - both government and private sector, and at enormous scale - in post-Soviet Russia.
"They cleaned the crime scene so thoroughly investigators can't prove definitively who was behind it."
That's literally in the article but it doesn't stop them writing the whole thing as if it's utterly proven beyond doubt who was behind it.
Russia uses America as the core of their propaganda just the same as the DNC has been using Russia as their boogoieman since they needed a narrative to apply to Trump.
As someone who formerly worked for Crowdstrike and has performed the APT-29 demo countless times, I will say attribution is bullshit and people frankly have no real data to point fingers.
Major investigations were completed months ago.
There is no more evidence to suggest Russia was involved than there was that Dmitri himself was for political reasons. And Shawn Henry will fire you for saying this out loud.
Yea, wow, thanks NPR. Hard hitting stuff right there. Those are “very specific circumstances” that just happen to generally apply to a huge percentage of hacks.
I normally appreciate some stories on NPR, but you’re right. This is a narrative piece.
Plus, the article is written to condense technical information into something that's as layman-friendly as possible. The specific malicious update has to be downloaded, and also installed, and also running on a server which can reach out to anything on the internet. Their point is that there are only going to be so many servers that both use this software and meet those conditions, and that's in part why the backdoor took so long to identify. This is maybe a little obvious to people with infosec knowledge, but definitely not obvious to their target audience.
The article timing is interesting, but I don't think a coincidence is that unlikely. If you read the whole article, it covers enough that I could see it taking months to make.
I don't think coordination with the government is that unlikely, either, or perhaps just a pragmatic editorial decision ("everyone knows sanctions are likely going to be placed sometime in the next few months, and maybe we should wait until then so we can include those details in the story"). Both of those scenarios are more likely than a coincidence, probably - but, either way, I think your post seems overly cynical in general.
Nonetheless the article was correct the hack did not need bizarre or rare circumstances to take effect.
Docker's a decent way to address this, since you install the dependencies when building the image rather than when running the container, so you can build the image elsewhere or through CI and run the container on any server without having to allow access to package management repo servers.
You're ready for offline install!