Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Helmi 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jaksot(1000)

a16z Podcast: On Corporate Venturing & Setting Up 'Innovation Outposts'

a16z Podcast: On Corporate Venturing & Setting Up 'Innovation Outposts'

Every big technological shift (per Carlota Perez) brings with a structural shift too — an “institutional adjustment” in how companies innovated and build new products, according to Steve Blank and Eva...

11 Touko 201631min

a16z Podcast: Banking on the Blockchain

a16z Podcast: Banking on the Blockchain

Whether you think of it as a distributed ledger, decentralized database, computing infrastructure, open source/ software development platform, cryptocurrency, transaction platform, or financial servic...

10 Touko 201639min

a16z Podcast: E-commerce, Payments, & More in India's Evolving Retail Landscape

a16z Podcast: E-commerce, Payments, & More in India's Evolving Retail Landscape

So many modern e-commerce sites and marketplaces are really digital forms of their physical counterparts, which makes it easier to figure out how to present and sell products online. But in India, whe...

5 Touko 201637min

a16z Podcast: Finally a Tablet that Replaces Your Laptop

a16z Podcast: Finally a Tablet that Replaces Your Laptop

When the iPad first came out in 2010 there was chatter that went in two directions: It’s just a big iPhone I’ll never carry a laptop again Both were wrong. The big iPhone comment was quickly dispell...

28 Huhti 201627min

a16z Podcast: Connectivity and the Internet as Supply Chain

a16z Podcast: Connectivity and the Internet as Supply Chain

Our first instinct as technologists or users of technology is to think of 'connectivity' as digital connectivity -- the internet, our smartphone. But the internet is just the latest in a long line of ...

22 Huhti 201632min

a16z Podcast: Bots and Beyond

a16z Podcast: Bots and Beyond

So... about those bots. Bots bots bots. Bots! In this episode of the botcast, a16z partners Benedict Evans and Connie Chan -- along with Chris Messina, longtime advocate of the open web and more -- pu...

19 Huhti 201648min

a16z Podcast: Selling to Developers & Open Source Business Models

a16z Podcast: Selling to Developers & Open Source Business Models

Developers are more than just influencers inside the enterprise -- they're now buyers, too. That's a huge shift from before, when only IT and other departments had that kind of purchasing power. (It's...

14 Huhti 201625min

a16z Podcast: The Why, How, and When of Sales

a16z Podcast: The Why, How, and When of Sales

The hallmark of many great technical founder/CEOs is that they envision a better way of doing things, and that's why they're building a company that delivers on that better way, often disrupting the w...

8 Huhti 201640min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
mimmit-sijoittaa
psykopodiaa-podcast
rss-rahapodi
rss-rahamania
pomojen-suusta
ostan-asuntoja-podcast
juristipodi
rss-myyntikoulu
rss-draivi
herrasmieshakkerit
rahapuhetta
sijoitusovi-podcast
rss-lahtijat
rss-seuraava-potilas
bakkari-tarinoita-tapahtumien-takahuoneista
rss-h-asselmoilanen
rss-startup-ministerio
rss-bisnesta-bebeja
rss-turha-edes-yrittaa