[HN Gopher] The DOJ detected the SolarWinds hack 6 months earlie...
       ___________________________________________________________________
        
       The DOJ detected the SolarWinds hack 6 months earlier than first
       disclosed
        
       Author : fortran77
       Score  : 102 points
       Date   : 2023-04-29 13:31 UTC (9 hours ago)
        
 (HTM) web link (www.wired.com)
 (TXT) w3m dump (www.wired.com)
        
       | scrose wrote:
       | The Cuckoos Egg[1] round 2? A bit funny how several decades
       | later, some things just don't change...
       | 
       | [1]https://en.m.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book)
        
       | rst wrote:
       | If there's any justification for this kind of delay between
       | detecting an intrusion and acting on it, it would have to be
       | giving the government time to investigate, in order to correctly
       | identify the source and means of intrusion, so the right parties
       | were charged and innocents weren't dragged in.
       | 
       | Which, unfortunately, was not the case with Solarwinds. Almost
       | immediately after the intrusion was publicly disclosed, there
       | were a bunch of stories, in both industry outlets like The
       | Register and mainstream ones as august as the New York Times,
       | suggesting that software from JetBrains might have somehow been
       | implicated in the hack -- citing no evidence other than that
       | Solarwinds had bought JetBrains products, and that they were,
       | y'know... one of them _furrin_ companies (though Czech, not
       | Russian -- one wonders whether the FBI knows the Czech Republic
       | is an EU member these days).                 https://www.theregis
       | ter.com/2021/01/07/jetbrains_solarwinds_accusation/
       | 
       | And yet, when a full technical writeup of the way the build
       | servers got breached was available, it turned out that JetBrains
       | software was not at fault; the hack to the build servers worked
       | at a lower level, and switching to a different build orchestrator
       | wouldn't have changed things at all:
       | https://www.crowdstrike.com/blog/sunspot-malware-technical-
       | analysis/
       | 
       | So, extra time to investigate didn't keep the investigators from
       | leaking a report that was just false. JetBrains obviously wasn't
       | well served by this -- but neither were the rest of us.
        
         | ochoseis wrote:
         | IIUC JetBrains products are developed in St. Petersburg,
         | Russia.
        
           | whaleofatw2022 wrote:
           | They had an office there but IIRC it has been shuttered
        
             | ochoseis wrote:
             | Where was it at the time of the hack?
        
               | sam_lowry_ wrote:
               | This is irrelevant to the discussion, anyway.
        
       | hnburnsy wrote:
       | Amazing the amount of government, industry, and academic
       | coordination that was put in place to fight disinformation. Why
       | can't that same effort be put into cyber and ransomeware
       | security?
        
         | asynchronous wrote:
         | Because "fighting disinformation" is simply a cover for
         | introducing political censorship into the modern populace. The
         | same effort could be applied, but it wouldn't benefit the
         | powers that be nearly as much.
        
           | cpurdy wrote:
           | Words have meaning.
           | 
           | The fact that you fear that possibility is indicative.
        
             | zmgsabst wrote:
             | That's the natural conclusion to draw when factually
             | accurate information is repeatedly censored in support of
             | establishment narratives:
             | 
             | This isn't about "misinformation" but suppressing voices
             | which challenge the government narrative -- especially when
             | the "official" narrative is misinformation.
        
           | hnburnsy wrote:
           | Excellent point.
        
       | boomboomsubban wrote:
       | They noticed the breach in the trial version and still bought the
       | product. Makes me wonder what would have led to them not buying
       | the product.
        
         | dayofthedaleks wrote:
         | They likely had a compliance box to check and a limited number
         | of approved vendors.
         | 
         | For the use case of enterprise network monitoring and alerting,
         | with integration of netflow and DB or application-level stats,
         | there are very few effective competitors. HP OpenView probably
         | exists in some hopelessly outdated form under a new name, but
         | every other NMS seems to involve baking a lot of custom scripts
         | or else is cloud-centric.
        
       | 0xC0ncord wrote:
       | https://web.archive.org/web/20230428233337/https://www.wired...
        
       ___________________________________________________________________
       (page generated 2023-04-29 23:02 UTC)