YouSaid · the spoken record

Joseph Menn

lines on the record
65
first
2021-01-26
most recent
2021-01-26
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. Well, turn on the screw would be giant companies, X, Y, and Z, you say that they were also breached by the same folks. They also had access to their source code. Maybe there were other updates that got their customers, that sort of thing. That's pretty likely. There may be in these hearings or there will be an intelligence report that is made public about why it's Russia, why they think it's Russia. And there will probably be some big review over practices in some other commission. On the other hand, maybe it's going to wind up like the Snowden Commission where some of the stuff gets adopted and some of it doesn't. So I don't know about that. I think a federal disclosure law is plausible because companies don't want to have to deal with this patchwork of states. It would also be nice if there's a federal privacy law. So maybe those initiatives go together.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  2. We can't have that crap anymore. We need people actually willing to give and take and deal with complicated issues, or we're going to keep getting owned like this.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  3. You know, people in the White House who still think of warfare and intelligence in the old terms and don't get into this, what about the private sector versus the public sector stuff because there aren't really straightforward answers. And right now, our government has been so dysfunctional that you couldn't get the two houses to agree on pizza topping. How are you going to tackle something like this? I mean, the Chamber of Commerce, the private lobbying group was outraged that the folks in Department of Energy and DHS wanted to put out voluntary guidelines for what are some best practices to protect your nuclear plants or your power plants from hackers because they thought that this is a slippery slope that would lead to more regulation.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  4. This is one of the good things. I mean, in the olden days when I started covering this, the only good thing you could say about cybersecurity was, well, awareness is rising. And now it's true. I mean, there are people in Congress that actually understand their actual engineers in Congress. This is a new thing. You still have a hearing where they drag in Zuckerberg or somebody and the questions, as you know, are really embarrassing from members of Congress, but it is a big change from where it was. And there are tech savvy staffers at all levels. People understand this and they're digital natives and they understand these trade-offs. I think that there's a better chance that we've ever had of people having a real discussion about this. But again, I'm concerned more about the establishment, the four-star generals, the people running intelligence agencies.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  5. Do you think there's like a cultural shift with a new generation of lawmakers, right? I mean, we have some younger lawmakers now. We have lots of younger people who've come up in things like Cult of the Dead Cow in parts of the government. Like people are good at computers now in a way that maybe they weren't so good at computers 10 years ago.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  6. Academy of Sciences or others to really beef that up. There's skunk works inside DARPA. There hasn't been a giant thing and there needs to be a giant thing.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  7. That'd be nice, wouldn't it? People will keep trying, but you can raise the cost. I mean, it obviously has to be a multifaceted thing. I mean, if you're talking about Cold War, then the big thing is deterrence and the certainty that, you know, the country ax will retaliate against country Y. It's true we have not seen that, or not very much of that. So that needs to be done too. But what I'm talking about is more the Reagan's Star Wars vision of being able to shoot down missiles as they come at us. Now that's what would actually change things. So yeah, the idea is that they would keep trying to get into Langley or Maryland and would fail. That would be super awesome. But we haven't actually even tried. There's really cool stuff happening in the private sector. There's been a lot of advances in defense, but there hasn't been a government-wide embrace of that initiative where you put lots and lots of money to the national.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  8. That everyone's going to offense, you just end up with more offense, right? That sounds to me like pretty classic, you know, foreign policy military deterrence language, right? I mean, this is how, this is the Cold War, right? You're speaking in the language of the Cold War in some way. What breaks it? Is it just we get so good at defense that no one tries anymore?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  9. A number two at NSA whose mission was defense, they got rid of that position, so they went the opposite way. I think defense has to be prioritized a lot more than it has been because if everybody's good at offense, then you're going to have a lot more offense around the world. The way to actually win is to get really, really good at defense. And I think we have not been focused that way at all.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  10. To the NSA's cyber budget. And the NSA had a whole division, the Information Security Information Assurance Division that was responsible for at least securing the U.S. government. And after the Snowden debacle, the Obama White House had a commission of five folks to look at this and figure out a whole bunch of things that we should do different to avoid another Snowden situation. And one of their recommendations was spin out the defensive division of the NSA from NSA proper because nobody trusts the NSA and because the offense of mission so dominates that you can't be sure that they're not going to subvert defense, which in fact they did. And that emerged from the Stowden Leagues. But they didn't. Instead, they did a disappearing act where NSA scattered the defensive mission, lowered down within the agency. So there was no longer like.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  11. Well, so first of all, it's in the nature to be fighting the last of things, to be fighting the last war. I'm not sure that we still need to be taking off our shoes at the airport. Because one guy tried that thing that one time, you're really high-end terrorists or other adversaries are not going to do the same thing that they've already taught us how to defend against. And this is a classic case of that. As to how you defend against this kind of intelligence driven attack, I think you need to deal with some really fundamental questions. And that includes supply chain, vendor relationship. To my mind, it definitely includes the defense offense balance. I did some stories a few years ago that said that 90% of what the US government spends on cyber things, at least back then, was about offense or intelligence gathering, not about defense. And the NSA is the agency at the time was charged with defense. Now DHS has taken up some of that, but their budget is minuscule compared to

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  12. Alex has been in and around The Verge in our shows for a long time. One of the things he has said about the 2016 election was we were all focused on the wrong thing at Facebook. They didn't know what it would look like. And then everyone in 2020 was worried about Russian disinformation and the threat ended up looking very different. And coming from a different place. I think Chris Krebs has said something similar. We were all focused on the election. We missed this thing. How do you build a broad enough array of censors and detection mechanisms to say, okay, there's a major election going, but there are these gigantic fat targets in Id States that need constant surveillance and protection.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  13. Mindset inside these companies. And one of the people, a lot of really amazing people came out of at stake and went to work on inside every major tech company in the United States. And one of them is Alex Stamos. So he joined at stake because he admired these guys who had testified before Congress about how fragile the internet was. And Stamos went on from there to do, among other things, work at Yahoo.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  14. Well, so the book sort of tells the history of the good guy impulse in security, and it tells the story of these old school hackers from before there was a web from back in the 80s to the present day. And their sort of moral evolution. And a lot of them turned pro. I mean, they were like teenagers, pranksters and whatever. And they turned pro in various ways and they invented hacktivism. But one of the things they did is that in order to make a difference, some of them went to work inside the government, including DARPA, and some of them went into the private sector and founded really important security companies because that was the, they thought the best way to actually help with security. And one of the companies they founded was called At Stake, which was an early security boutique where hackers went inside companies like Microsoft and Big Banks and whatever and said, this is what you're doing wrong. And so it brought the hacker.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  15. National Alliances. If that stuff gets firmed up, I think a lot of NATO saw the lack of response to that as a mistake. So we'll see how strongly the Biden administration feels about NATO and this issue. There are a lot of things in play. But I think cyber's back on the table now. Biden administration is going to make it a priority. And I think it's going to be a part of basically all major conflicts going forward. So there's no reason why it would not also be subject to treaties agreements, responses, norms, that sort of thing.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  16. I think that was a missed opportunity. There certainly could have been, and I think a lot of people think should have been more done there. But again, that was Russia attacking Ukraine. It wasn't attacking us. And I think the response would have been very different if Russia had attacked us in Ukraine. Unfortunately, Ukraine, like some of the Middle East, is kind of a proving ground for a lot of these capabilities. We haven't seen a lot of what nation states could do to keep parts of our infrastructure because people don't really haven't so far felt like it's worth it to bloody our nose. But they can. We probably can too. I think if Ukraine had been in a position to respond, it would have, there's a, you know, you could certainly make an argument that NATO should have done something. We'll see if, you know, with the passage of time, with people who care more about international,

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  17. Several months ago, I interviewed Andy Greenberg, who wrote a sandworm, which is a book about not Petya and shutting off the lights in Ukraine. His argument to me was that was the moment when the Obama administration could have stopped it, but instead they set a new norm that this is how we're doing it. We reserve the right to attack back, that the international outcry around turning off the lights in Ukraine was not big enough and the message was sent, this is in some way acceptable behavior. Do you think that's a groan? Was that the moment? Was that an inflection point or has it just been a study drum beat of other things?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  18. From these sorts of attacks. But the problem is verification. And we can barely verify nuclear treaty compliance. There are so many proxies, both sort of literal and figurative. The line between nation-state and crime is deliberately fuzzed up in a number of places. It's really, really hard to ensure that something wouldn't happen. And again, like, you know, there's never been a deal that really stopped intelligence exploitation. So if there is going to be some kind of like global treaty or understanding or something, it would probably be about physical destruction and not about intelligence gathering, which again this is.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  19. So, in theory, yes. You can certainly have international agreements. You can have, I mean, for many years under the Obama administration, it was all about norms, like setting norms. And if there's an attempt to do that kind of globally, and then maybe we'll do it in a given region. And it hasn't really led to very much. And when there have been big tests, it is widely understood that Russia shut out the lights in Ukraine a couple Christmases ago. The Not Petya attacks were terrible. The WannaCry attacks, which shut down hospitals, you would think that that would have given rise to some sort of international agreements, if anything would. And it hasn't yet. The president of Microsoft, Brad Smith, has been kind of a spokesman on this sort of thing for the industry, talks about kind of a Geneva convention sort of a thing that would, among other things, exempt civilian infrastructure.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  20. One of the questions I've been wrestling with, we do it too. The United States hacks a lot of things all the time inside and outside of the country. Is there a way to just pull that back internationally? Is there a treaty or a set of regulations or rules of engagement that exist or have been proposed to say, hey, like this is getting out of hand? And all of our economies aren't in threat.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  21. Again, one of those big hairy aspects to this, you're right that there's tighter integration between private companies in the state in many other nations. And it's not only helps them on offense, it helps them on defense. You know, if the government can simply order everybody in the power industry to apply a patch, then they do it. We actually, you know, the United States government does not actually have that power here. Which is kind of scary. It is also true that the companies that are based in the United States, many of them get a majority of their money overseas. So even if they think of themselves or for regulatory purposes, they're American companies, that doesn't mean they're going to march in lockstep with the American government, which makes it really...

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  22. I think about the big nation state actors that you would think about, right? The Russians, the Chinese, and North Koreans, the Iranians, there's a tighter nexus between government and industry in those countries. I think that's the most polite way of saying it, where the government does some espionage and they're going to hand over that information potentially to one of those large corporations. There's a level of corruption or maybe state design there that incentivizes both sides to act as one. I don't think we have that here, right? Like our incentives to go off and have our government hack a bunch of companies in other countries, their incentives are very different. So how do you align all of that stuff here beyond just simple deterrence if you hack us, we'll hack you back?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  23. Fair to expect private companies really no matter how large to fend off entire other nation states. That should be the job of the US government to defend private enterprise from other countries. It's really, really hard when you try to get into the weeds on that one because sometimes a nation state will use the same techniques as the 16 or 17 year old. So there should be some reasonable standard of defense that is expected of companies. But again, at the really, really high end, you know, look, if the Russians got into NSA, the Chinese got into the classified personnel files, it doesn't matter how big a company you are. You're going to get owned if they really want you. So that is one of the big strategic issues that I would hope that the White House of Congress addresses. How do you, where do you draw the line? What kind of help can be provided?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  24. But for a variety of reasons, after intense discussions at the highest levels of the government, the US did a response mostly under the table, but there were some cyber action taken against North Korea. So sometimes that is appropriate, just because another government attacks a piece of civilian infrastructure doesn't mean that they should not, there should not be any response. I mean, if a private power utility gets taken down in the United States by RAN, we certainly reserve the right to attack Iran militarily over that. Again, this isn't that. This is espionage. There's almost no very, very rarely do you see military response to legit espionage targets being attacked. But there's a separate issue which you hit on, which is like, is this a Microsoft problem? In my opinion, it is not.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  25. Talking about when North Korea hacks Sony over the movie the interview, which was about two journalists played by Seth Rogan and James Franco who went to North Korea to interview Kim Jong-ung and eventually assassinate him, which North Korea obviously didn't appreciate.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  26. So that's a really good question. And you put your finger on one of, I think, the biggest issues here. But let me separate out the Pentagon offense response part of it. The US responded, the U.S. government responded when the North Koreans attacked Sony for dumb reasons. I can't believe we're in an era where national government's attack each other over dumb movies, but here we are.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  27. So you're starting from a low bar, is what you're saying? You mentioned that this was primarily an espionage, or it looks like an espionage operation. What's interesting about that is you come after Microsoft view espionage, kind of the way Americans would see it is, well, that's Microsoft's problem, right? That's not, we don't need the government or the Pentagon or that doesn't merit a military response, right? Which is kind of what you're describing. But at the same time, this is a major national security problem. Like, how does that play together?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  28. have really intelligent really experienced people do they have the kind of you know broad blue sky strategic thinking that might help turn around this really gnarly problem i don't know uh we'll see you know the fact that that both houses of congress are from the same party probably helps as does the fact that a lot of this isn't that partisan in a terribly polarized environment Nobody's a big fan of getting hacked to pieces by the other countries. So I am more optimistic now than I have been in 20 years of covering this, but that doesn't mean I'd actually bet on a complete turnaround.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  29. That's really interesting. So this is playing out in real time. Biden has appointed most of the top cyber people as of this morning. One or two key holes. But among other things, for the first time, there's a deputy national security advisor for cyber, who's Ann Neuberger, who's very well regarded, was at the NSA for many, many years. And among other things, was doing the sort of cooperating with industry defensively part of NSA's mission. There are a number of people who have really strong military and government experience as of this weekend, the suspected new cyber czar inside the White House. Is Jenny Easterly who was one of the people that helped create cyber command as a separate unit of the Pentagon? The guys who do cyber attacks in other countries.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  30. Breach of this scale, right? We're the biggest companies in America, the American government itself, that is usually the thing that catalyzes change, that leads to a disclosure law or a reframing of the American posture towards offensive cyber attacks. But because of the transition and the sort of instant quiet from the attacked parties, it doesn't feel like this is that moment. Is there a group of people who are going to commend the Biden administration? Does they have appointees yet who have the expertise to raise the profile of this again and build the political capital to actually make the change?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  31. It involves how do you secure the supply chain? What do you do about employees in other countries, contractors in other countries? It's similar to the trade war with China. Computers and the software inside the computers go back and forth dozens of times before they wind up on your desk. And it is pretty impossible to secure complete.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  32. Files on the majority of folks in the US government and outside of the US government with a secret clearance or above. That was really, really bad. But it wasn't warfare. That's an espionage win. And we are trying to do exactly that sort of thing to China and Russia and other governments. But I think it's clear that there will be some kind of response. There are going to be hearings on this. you know, it has a lot of aspects like many things cyber, it has a lot of aspects. There's like, what do we do about country X was behind this? Can we prove that to the world satisfaction? And then do we respond economically or diplomatically in other ways? Hopefully not militarily, though. I suppose that's a possibility. And then there's like, how do we stop this from happening again? And that's really hard and complicated. It involves defense versus offense.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  33. The administration's been on the job for a few days. And in the sort of heated political atmosphere, there's stuff that there's a widesprum of noise before things are sorted out. So from the campaign, not from the campaign trail, but from the transition, Biden said that this is something specifically that is going to be responded to in a big way. Other folks said this is an act of war. The people who've been at this for a long time and don't have a particular axe to grind are not saying it's an act of war. There's no evidence of destruction. There's no human life lost. And this is classic espionage. It's just that we got owned really badly. It's similar. I mean, in my mind, to the hack of the Office of Personnel Management, widely attributed to China some years ago, where they got classified personnel.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  34. From here, I certainly doubt that there was any foreknowledge or anything like that in the administration of this. But from an attacker perspective, we're distracted, we, the US, are distracted. And we have a president that's less likely than predecessors, even if he finds us to yell and scream and threaten sanctions.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  35. I don't think that's something that we know yet. It may have been like a bit of insurance on the part of the Russians under Trump, the United States government did not aggressively punish, particularly the executive branch, did not aggressively punish Russia for a lot of really bad behavior that other governments would have done more about. There were sanctions, but it was driven by congressional action and that sort of thing. So you don't have to be a big conspiracy theorist to say that, well, you know, the Russians think, well, we're going to get a, you know, we've gotten away with invading Ukraine. We can do this big hack. And even if we get caught out, this is the least likely White House in memory to sound the alarm and rattle a saber at us.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  36. This is obviously complicated, right? The hack is happening in an election year. The Trump administration, President Trump himself, strangely cozy with Russia. There's a new administration. It seems like Biden's going to take a more aggressive posture during Russia in the middle of all this. There's the election security noise Trump fires Christopher Krebs who is in charge of cybersecurity. How does that all play into this? Is it we didn't want to say it was Russia too loudly and now we're saying it a little bit more loudly is it the Trump administration did not have a good cybersecurity infrastructure the shape of that seems really fuzzy to me too

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  37. That actually happened with Twitter. I mean, I'm not saying that Twitter said it was a nation state, but it looked like a very sophisticated hack and then it literally turned out to be teenagers. This is not that. This really is a nation state. I would be very surprised if it's not Russia, which does deny it. There is some overlapping code. It is also true that countries have gotten good at imitating each other's stuff. But I can tell you it wasn't the US. And it was somebody that is not after money because while there was a broad net, again, like the 50 or so whatever known secondary targets where they really went after them are classic espionage targets. The Department of Defense, the State Department, the Treasury Department, the Commerce Department. So, I mean, that pretty much rules out an economic motive. We're down to like a handful of suspects, and there's no reason to not believe that U.S. assessment that it's Russia.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  38. So, the sort of amazing disappearing code. They left almost no artifacts from their code. So there'd be all this careful work deobfuscating what happened, and then they get there, and then there's nothing. They cleaned up all their, they made all their code disappear. That thing, the fact that they got the code signing certificate, the fact that the back door was inserted only when a certain product was being compiled and only at the last minute. That's all really, really high-end stuff. They're pretty much by itself rules out anything but a nation state. I mean, people underestimate this is a complicated area because, you know, if you're the victim of a hack, particularly if you're a publicly traded company with investors, you definitely want to say this was a nation state of evil geniuses that you couldn't possibly have defended against. And sometimes it turns out to be a 16-year-old, and that's embarrassing.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  39. The US intelligence community and the sort of top flight private people who often unfortunately know as much as the government people all say science point to Russia. Are there some discrepancy over which agency within Russia? The trade craft is really, really high.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  40. We're back with Joseph Men from Reuters talking about the solar winds hack. Like I said, I very pointedly not asked you who was responsible for this because I think that deserves some focus. So to the best of our knowledge, who was responsible for these attacks?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  41. Companies that say that they were impacted. There is a weakness in disclosure law where you have to disclose if you have one of, I think, something like 40 states and there's personal information of people that was compromised, you have to disclose that. And if there's a if you're a publicly traded company and it's material to your revenue, then you have to disclose it. But everything else by and large, you don't. And that's actually most breaches. So one of the worst examples of that is when the F-35 plans got compromised and you would see these major defense companies, which I knew had been hacked, not disclose it in their SEC reports. And the reason is that it's not material because the government isn't going to buy an F-35 from somebody else. So it actually doesn't hurt their bottom line, which is, you know, there are big systemic incentive issues here, and that includes disclosure.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  42. And God loved lawyers and PR people and they should all make good livings. But sometimes it's the enemy of clarity in what security folks here need is clarity. And also these investigations are going to be going on for quite a while. So there are actually a number of companies that are saying that there is no evidence of X, but they're saying like, you know, absence of evidence isn't evidence of absence, right? We know they were in there where they shouldn't have been. They had control of some Microsoft employee at least one Microsoft employee accounts, maybe more, and the permissions that went with that. We know Microsoft was used in lots of attacks. We don't know really how we got from A to B or Foods just through the Microsoft resellers yet. This will come out at some point, but it is murky. And there are a number of big victims that haven't disclosed yet, that haven't said that they were compromised. And there will be at least a trickle, if not a stampede.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  43. Well, we know that Microsoft did download the tainted code, but that's true of thousands of companies. So we reported that, and Microsoft said, yeah, but there's no evidence they got into any production systems. It looks like it was contained. I and others reported that, well, it looks like Microsoft code was used in various other attacks. And then a bit later, Microsoft says, well, okay, actually, it looks like they did get into our source code. They could view our source code. They couldn't modify our source code. So it's still unclear. The problem is when you get to this level of crisis, there's a lot of lawyers and PR people involved.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  44. The Microsoft part of the story to me is very confusing. So they got into Azure and then Microsoft basically said, this isn't a big deal, even though all of the reporting around it says this is a big deal. And then Microsoft seems to have come around. Can you just walk me through that? Because as I've been looking at it, it seems like everyone wants this to be minimized and not quite so public. And so all of the statements are a little opaque. But tell me what exactly happened with Microsoft here.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  45. Bits of the Defense Department. And I should say that there's no evidence yet that they've got into classified networks which are segregated. But if I was running as agencies, I want to be sure of that. The other problem is that certainly one of the goals of the attackers was looking at source code, presumably to find additional vulnerabilities. So they did view Microsoft source code. They probably viewed the source code of other big companies. And then they can find new ways of attacks through other means that have nothing to do with solar ones. So you got to worry about that too.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  46. So that's how the attackers tried to get into crowdstrike, the security firm. That's how they did get into that may have been how they got into malware bytes, which is another security firm that doesn't use solar winds. So if you're in charge of an agency and you're trying to defend it, one of the things you're looking for are these other techniques that came in. Was there another way in? The bad guys coming in, their first job is to make sure it's a clean entry and get rid of all their logs to make it confusing about how they got in. But job two is putting in additional backdoors. So those could be planted in all kinds of places, which is why the cleanup is going to take months or actually years if you've got a really big network to be sure that they're actually out. There's some folks who say you've got to burn down the entire network and rebuild it from scratch. And that might be true for the highest value targets.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  47. Well, going back a bit, you've had a pretty lousy holiday break This stuff was coming out over the break. We haven't even talked about the additional vectors. So solar winds wasn't the only way in. Some of the attacker behavior was found at sites where they didn't download solar winded updates or they didn't have solar winds at all. So there are still unknown ways in. The US government has said that there's at least password spraying, password guessing, automated attacks of that sort. It looks like there are others and it turns out that Microsoft is also a big vector here. Their cloud architecture is complicated and they have a system of resellers that sell you Office 365 if you're a big company or an agency. And then those resellers frequently maintain access. And it looks like some of them were compromised.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  48. automatic up Yeah, I mean, it feels like we're at some point, trade-offs have to be made and that the trade-off is to concentrate attack surfaces in one place and ideally have that place be well fortified, but even that can't be perfect. What is happening at solar winds now? They've hired the three companies, they've got a new CEO, he says it's jobs one, two, and three, but there's also, however many clients, there's the 50 high value targets, there's the government. the simple level of i'm in charge of the network at the treasury department and i got to fix it what are the next steps

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  49. So automatic software updates are a terrific thing because the vast majority of hacks are not some super secret zero day nation state evil genius. It's garden variety known flaws that people haven't gotten around to patching. And it's certainly understandable for individuals and smaller companies. But I think still people don't get that at big companies they don't just automatically install updates because they can conflict with other software configurations and crash those. So there has to be a delay as you test it before you put it out there. But nonetheless, automatic updates are terrific thing and nobody should stop automatic updates because of this attack. It's just that, yeah, that is a grand prize. And there Other bits of that too. I mean, so there's digital certificates, you know.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  50. Right, but the trade off here is you should update your computer a lot for security reasons because people might try to update your computer, but then that makes the software update itself a rich, rich target. How has that dynamic changed in the industry?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT