General Discussion
In reply to the discussion: Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary response to breach [View all]Azathoth
(4,677 posts)1) Revoking digital certificates is done everyday. Its effectiveness depends on whether every client machine is configured properly to always check for revoked certificates. Doesn't do anything to repair already-compromised systems.
2) Two and four are Microsoft bragging that it added a virus definition to its antivirus software. *slow clap*
3) Sinkholing the domain is the only thing here that could be considered a "death star" move. It's an important mitigation step, but depending on how the trojan is designed, it's far less effective than the article implies. Sophisticated attackers would not design a worm that can only be accessed through a single domain. What likely happens is the trojan infects a system, then sends a message to the domain notifying the hackers that a new system has been compromised. The hackers store the info and can connect directly to the backdoor at a later time. So taking down the domain does nothing for the systems that are already infected and have already used the domain to notify the hackers. It also doesn't stop new infections from happening. It merely prevents the hackers from learning of newly infected machines.
Not trying to be a downer, but this isn't a benevolent sovereign using his awesome power to make everything right.