YouSaid · the spoken record

Joseph Menn

lines on the record
65
first
2021-01-26
most recent
2021-01-26
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. One of the questions I have about supply chain attacks here in this context is the attackers got in, they modified an update, the updates got sent out. We now live in a world of automatic software updates or kind of, I don't want to say careless, but we're conditioned to software updates.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  2. So, everything you said is true except for the one or two players that allow you broad access. The real problem is that there are 100 companies like this. Yeah, SolarWinds has this major, major position in network management, but there are all these other companies that are also completely dominant. And this has been like a known sort of point of weakness for the security posture of the country for a long time way back when at stake actually the Stabilisation, the CTO there, wrote a paper about Microsoft being a threat to the world because everybody used it. So if you hack Microsoft, then you can hack everybody. And it's still true, really, of Microsoft and SolarWinds and Oracle. And 100 other companies you've never heard of. It's really scary. And that's why supply chain attacks are so alarming.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  3. As well, it should be an existential crisis, I think That's actually one of my questions, it feels remarkable to me that this many major American companies have all converged on one software provider for network management. You know, as I think about security broadly, honestly, as I think about the technology industry, it feels like so many things have converged onto one or two providers that they're rich targets for attackers, right? If you can break solar winds, you get the Treasury Department, but you also get Microsoft and you also get Cisco and you also get whoever else as opposed to, you know, if there was a broader spectrum of service providers at this level, the attacks kind of, their effects are limited. Is that part of the puzzle here that SolarWinds is just kind of big and dominant and maybe got a little lazy?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  4. You know, if you sell something and it's used to attack all your customers, that's potentially existential crisis. And so they have a new CEO by coincidence. And he said that this is jobs one, two, and three for him.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  5. Solar winds, they were notified by FireEye. They looked at it. They confirmed that that code was tainted. They figured out which other editions of their code had the backdoor. And then they hired a bunch of firms. So they hired CrowdStrike, which is another prominent security firm, kind of a rival FireEye. They've hired one of the big consulting accounting firms to do a forensic dive. And then they hired this new firm run by Chris Krebs, the former head of the cyber structure and infrastructure security agency within DHS and Alex Stamos. They've hired them to sort of, you know, tell them what to do better in the future, sort of like a culture, you know, how to prioritize the culture overhaul and best security practices. Because if, you know, Southern Winds' name is really on the line here.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  6. Yeah, so this is not good, not just the They actually went nuts and they eliminated, they couldn't figure out how the bad guys had gotten in as far as they had. And so they went digging for how they could have gotten in. And they eliminated basically all the sort of more straightforward ways in. And then they started tearing down the code of the software that was on the servers that were compromised. And that is a nightmare. I mean, that is not something you want to do. But they did it and they actually found what had gone gone wrong. And it was in the solar winds code. And then they disclosed it. You know, they warned everybody. They found out what the hackers had taken, which included, you know, some of their tools for red team pretend hacking, testing their clients' systems. And then they disclosed it before knowing the entire story, like knowing which of solar winds customers were affected and all that stuff. They said, hey, this needs to get.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  7. One of the things that really just sort of has caught my attention from the beginning is that, you know, the State Department didn't catch it, Treasury didn't catch it. Microsoft didn't catch it. A much smaller cybersecurity company caught it. How did that happen?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  8. So let me just take one step back and make sure I understand it. So, solar winds is you're the CIO of a big organization. You're responsible for the network. You need to set up a bunch of servers and switches and just network management tools. You're probably running some of your own applications in a some environment somewhere. You need to manage all that. You buy Orion, this is the software from SolarWinds, and that helps you manage your whole network. And then solar winds itself was compromised. We're saying we kind of don't know how. The hackers compromised it so badly they were able to inject code into updates into Orion that were almost unetectable. Those updates were shipped to 18,000 customers.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  9. Right, and major technology companies. So we're talking Microsoft, Cisco, and some security companies, which is another reason to be alarmed by all of this.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  10. It only happens when the code is being compiled at the last minute. So it was almost impossible to find. But once they're in there, anybody who downloaded at least two relatively recent updates of the Orion software last year downloaded this backdoor. And then it looked around to see where it was. It connected with the original attackers, and then the attackers could decide whether to deploy additional code and really exploit that further. So the universe of customers that downloaded the tainted solar winds code is around 18,000 customers, but so far it only looks like around 50 of the most important customers got that secondary infection that said where the attackers were really interested.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  11. So we don't actually yet know how the hackers got into solar winds. There are a number of theories, solar winds itself uses software from other providers. So this is what's known as a supply chain attack, which is among the scariest kinds of attacks. And SolarWinds was used to attack was compromised in order to attack customers of SolarWinds, but that also may have been how the hackers got into solar winds in the first place. It could have been an employee gone bad. It could have been a direct hacking technique that the company hasn't discovered yet, or at least hasn't disclosed yet. But one way or another they got in there. And when they did, they got into the code building environment in a very sophisticated way. We're able to insert a backdoor into solar wind's Orion network management software code, but they did it in such a way that it

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  12. Sure. SolarWinds is a company that most folks haven't heard of unless they work in big companies. They make mainly network management software. So you download it, you install it. It sits on your network and it lets you know when things are, you know, how things are working on your network. And it helps things run smoothly. It's one of the many, many sort of boring enterprise software infrastructure software makers. But it happens to be used by a large percentage, a majority of the biggest companies in the United States and the biggest government agencies in the United States.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  13. Agree with that, and I think it's by design. This attack goes back, the roots of it go back more than a year, but the activity escalated and it came at a perfect time because the US was so distracted, in particular the US government. And even the security people within the US government were busy worrying about securing the elections. And so you couldn't have picked a better time to launch a massive spying attack on the government.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  14. So, I really wanted to have you on because I feel like in the transition between the Trump administration and the Biden administration, the story of the SolarWinds hack and its fallout kind of got lost. And I know it's a huge story, but so many other things have happened in our country that it almost to me feels like it's not getting any attention that it deserves. Is that kind of your sense of it too?

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT

  15. Payment of $45 for three months, $90 for six months, or $180 for 12 month plan required, $15 per month equivalent taxes and fees extra. Initial plan term only greater than 50 GB is busy.

    2021-01-26 · Decoder with Nilay Patel · The SolarWinds hack: cyber attacks and national security with Reuters reporter Joseph Menn · IDENTIFIED FROM THE TRANSCRIPT