Welcome to DU!
The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards.
Join the community:
Create a free account
Support DU (and get rid of ads!):
Become a Star Member
Latest Breaking News
Editorials & Other Articles
General Discussion
The DU Lounge
All Forums
Issue Forums
Culture Forums
Alliance Forums
Region Forums
Support Forums
Help & Search
General Discussion
In reply to the discussion: Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary response to breach [View all]klook
(13,604 posts)85. Hard to defend against human foibles.
SolarWinds exposed FTP credentials in Public Github Repository
SolarWinds exposed their FTP server credentials in a public Github repo, which was identified by cybersecurity expert Vinoth Kumar who reported it to SolarWinds in 2019. Did some poor security practices lead to the US Government breach?
- SaveBreach.com
Good information at https://savebreach.com/solarwinds-credentials-exposure-led-to-us-government-fireye-breach/
Updated info in this Twitter thread says the credentials were exposed as far back as June 2018:
https://threadreaderapp.com/thread/1338929932647477257.html
SolarWinds exposed their FTP server credentials in a public Github repo, which was identified by cybersecurity expert Vinoth Kumar who reported it to SolarWinds in 2019. Did some poor security practices lead to the US Government breach?
- SaveBreach.com
...the SolarWinds breach seems to be just another case of gross carelessness and weak credentials. Although not confirmed by official sources, this is what we can conjecture for now. This reveals a very important piece of the puzzle, that is the attack was possibly not as sophisticated as it was reported to be.
Good information at https://savebreach.com/solarwinds-credentials-exposure-led-to-us-government-fireye-breach/
Updated info in this Twitter thread says the credentials were exposed as far back as June 2018:
https://threadreaderapp.com/thread/1338929932647477257.html
Edit history
Please sign in to view edit histories.
Recommendations
0 members have recommended this reply (displayed in chronological order):
128 replies
= new reply since forum marked as read
Highlight:
NoneDon't highlight anything
5 newestHighlight 5 most recent replies
RecommendedHighlight replies with 5 or more recommendations
Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary response to breach [View all]
SheltieLover
Dec 2020
OP
Just limiting the damage is like not prosecuting and punishing those in the Trump admin.
Ligyron
Dec 2020
#30
Ponletz, that was my reaction, too. It's a puff piece about how awesome Microsoft is. I'm waiting
Nitram
Dec 2020
#99
Taking Microsoft at their word that they saved the day would be dangerous because it would result
Nitram
Dec 2020
#124
Yeah, I agree. This is puffery by Microsoft to change the 'Windows vulnerability' narrative
Maven
Dec 2020
#113
Quantum computing will make passwords obsolete and systems, as we know them, untenable.
Ponietz
Dec 2020
#17
"the only thing you can infect on a Mac or a Unix machine is an application like a browser"
CloudWatcher
Dec 2020
#96
Can't protect some people from themselves, but Unix, Mac, Linux all ask for a password and inform
infullview
Dec 2020
#109
So now we're accusing people we disagree with of posting "right wing Trump excuses?"
Nitram
Dec 2020
#100
"Death star"? Apparently Microsoft is the Empire and the hackers are the Rebel Alliance?
Klaralven
Dec 2020
#76
Microsoft unleashes 'Death Star' on SolarWinds hackers in extraordinary response to breach
LudwigPastorius
Dec 2020
#39
It is a great article and consider...there were things used that are not in the article...they
Demsrule86
Dec 2020
#71
If that's true, it is one more reason not to rely on TV "news". It's been in the Post for a week at
Nitram
Dec 2020
#125