Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Helmi 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jaksot(1000)

a16z Podcast: The Science Of Extending Life

a16z Podcast: The Science Of Extending Life

Is it real or science fiction to dream of being able to treat… getting old? In this episode, we discuss with Dr. Thomas Rando from Stanford (who directs the Glenn Center for the Biology of Aging), Kri...

18 Huhti 201729min

a16z Podcast: Crisis Communications

a16z Podcast: Crisis Communications

A crisis is an opportunity to change one's culture, to model scenarios and set up a crisis plan/process, to become a better company. But it's also a bit like therapy, from the act of asking probing qu...

13 Huhti 201733min

a16z Podcast: Monetizing Open Source (Or, All Enterprise Software)

a16z Podcast: Monetizing Open Source (Or, All Enterprise Software)

Here’s what we know about open source: Developers are the new buyers. Community matters. And there will never be another Red Hat (i.e., a successful “open core” business model … nor do we necessarily ...

11 Huhti 201729min

a16z Podcast: The Changing Culture of Open Source

a16z Podcast: The Changing Culture of Open Source

The culture of open source has changed across generations, from previous ones that had to fight for the brave new way -- to the current "GitHub generation" that not only accepts open source, but expec...

8 Huhti 201739min

a16z Podcast: Cryptocurrencies, App Coins, and Investing in Protocols

a16z Podcast: Cryptocurrencies, App Coins, and Investing in Protocols

Most of us have probably heard of bitcoin and ethereum -- but did you know there were 15 new cryptocurrencies launched this past month alone? How then do we know which protocols to invest in -- not ju...

3 Huhti 201732min

a16z Podcast: Eyes in the Sky

a16z Podcast: Eyes in the Sky

In this episode of the a16z Podcast recorded at our inaugural Summit, Jonathan Downey, CEO of Airware, Grant Jordan, CEO of Skysafe, and Kyle Russell, partner at a16z, discuss our future with “eyes in...

25 Maalis 201719min

a16z Podcast: From Hidden Figure to Sonic BOOM

a16z Podcast: From Hidden Figure to Sonic BOOM

An aerospace engineer who worked for NASA for over 40 years, Dr. Christine Darden is one of the mathematicians that the book and movie Hidden Figures was based on. Darden eventually would lead the son...

22 Maalis 201738min

a16z Podcast: The Storage Renaissance

a16z Podcast: The Storage Renaissance

As we enter a new era of distributed computing -- and of big data, in the form of machine and deep learning -- storage becomes (even more) important. It might not be sexy, but storage is what makes th...

21 Maalis 201722min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
psykopodiaa-podcast
mimmit-sijoittaa
rss-rahapodi
pomojen-suusta
rss-rahamania
ostan-asuntoja-podcast
rss-myyntikoulu
herrasmieshakkerit
rahapuhetta
salkunrakentaja-podi
juristipodi
rss-bisnesta-bebeja
rss-set-for-life-sijoita-ja-vaurastu
rss-draivi
taloudellinen-mielenrauha
lakicast
rss-lahtijat
rss-ammattipodcast
rss-merja-mahkan-rahat