The SolarWinds hack is a fundamental challenge, but I went into work yesterday focused on the same basics.

This may be a game-changer for policy and industry, but the essentials are what make the difference here. It revalidates basic visibility and monitoring. Same as before.

I do not see complex networks as they exist today as bastions where you can close your eyes anywhere assuming you're fine.

What if an attacker just compromised Orion with an exploit like a normal attacker? Or pivoted into its memory space from elsewhere?

What's the difference?
You've got to have pretty incredible network segmentation and administrative tiering and insider threat program before this kind of attack is the biggest risk to worry about.

That doesn't mean it's not incredibly serious. But we're failing way worse than this every single day.
This is a hard dichotomy to talk about without sounding dismissive, but I think it's worth bringing up. Be ever more mindful, but keep our foot on the gas on our fundamentals without letting up.
I'm putting some thoughts together, but I can't get over the fact _they didn't even try to infect your network if it looked like you were watching the machine_.

Like, we should be screaming about this. They know this shit works against them.
Note: This is not saying FireEye and other networks did not have monitoring in place, but it may not have been with tools in their list of "nope I'm not even trying" list.

The fact they hit FireEye seems like a massive mistake since they have internal custom tooling.
Everyone is doom and gloom while I'm like Neil Patrick Harris in Starship Troopers where he puts his hand on the bug and says "they feel fear" and everybody cheers.
It's worth saying, cyber hygiene may be in refutation of buzzwords, but it's not the end-all-be-all of IT protection.
You do need top-flight systems and people at the edges looking for the exceptional vectors.
But I want to keep harping on these fundamentals for everybody else.

More from War

You May Also Like

शमशान में जब महर्षि दधीचि के मांसपिंड का दाह संस्कार हो रहा था तो उनकी पत्नी अपने पति का वियोग सहन नहीं कर पायी और पास में ही स्थित विशाल पीपल वृक्ष के कोटर में अपने तीन वर्ष के बालक को रख के स्वयं चिता पे बैठ कर सती हो गयी ।इस प्रकार ऋषी दधीचि और उनकी पत्नी की मुक्ति हो गयी।


परन्तु पीपल के कोटर में रखा बालक भूख प्यास से तड़पने लगा। जब कुछ नहीं मिला तो वो कोटर में पड़े पीपल के गोदों (फल) को खाकर बड़ा होने लगा। कालान्तर में पीपल के फलों और पत्तों को खाकर बालक का जीवन किसी प्रकार सुरक्षित रहा।

एक दिन देवर्षि नारद वहां से गुजर रहे थे ।नारद ने पीपल के कोटर में बालक को देख कर उसका परिचय मांगा -
नारद बोले - बालक तुम कौन हो?
बालक - यही तो मैं भी जानना चहता हूँ ।
नारद - तुम्हारे जनक कौन हैं?
बालक - यही तो मैं भी जानना चाहता हूँ ।

तब नारद ने आँखें बन्द कर ध्यान लगाया ।


तत्पश्चात आश्चर्यचकित हो कर बालक को बताया कि 'हे बालक! तुम महान दानी महर्षि दधीचि के पुत्र हो । तुम्हारे पिता की अस्थियों का वज्रास्त्र बनाकर ही देवताओं ने असुरों पर विजय पायी थी।तुम्हारे पिता की मृत्यु मात्र 31 वर्ष की वय में ही हो गयी थी'।

बालक - मेरे पिता की अकाल मृत्यु का क्या कारण था?
नारद - तुम्हारे पिता पर शनिदेव की महादशा थी।
बालक - मेरे उपर आयी विपत्ति का कारण क्या था?
नारद - शनिदेव की महादशा।
इतना बताकर देवर्षि नारद ने पीपल के पत्तों और गोदों को खाकर बड़े हुए उस बालक का नाम पिप्पलाद रखा और उसे दीक्षित किया।
Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.