Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Helmi 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jaksot(1000)

a16z Podcast: What's Next for Technology and National Security?

a16z Podcast: What's Next for Technology and National Security?

We live in very interesting times, to say the least -- whether it's a shift in how technology is built and adopted today compared to the past; a changing international landscape with leapfrogging play...

9 Marras 201634min

a16z Podcast: Messages and Movements in Politics AND Business

a16z Podcast: Messages and Movements in Politics AND Business

In business, as in politics, "the movement is the message" -- whether that "movement" is a product that's taking off grassroots-style in an enterprise, or is a political candidate. In fact, you can th...

3 Marras 201627min

a16z Podcast: So Where Are We on the 'S-curve' for PC Devices?

a16z Podcast: So Where Are We on the 'S-curve' for PC Devices?

There have been a number of new device announcements this past month -- from Google’s new Pixel phone (the first time they made their own phone on the hardware side as well) to more recently, Apple’s ...

29 Loka 201633min

a16z Podcast: On the Genomics of Disease, From Science to Business

a16z Podcast: On the Genomics of Disease, From Science to Business

Once we sequenced the human genome, we'd know the cause of -- and therefore be able to help cure -- all diseases... Or so we thought. Turns out, 20,000 genes (and counting) didn't really explain why d...

18 Loka 201630min

a16z Podcast: Stickers! Filters! Memes! Livestreams!

a16z Podcast: Stickers! Filters! Memes! Livestreams!

From glittery reaction gifs modded by grandparents to rage faces on Reddit, stickers (gifs and other layered images) and emotive “biaoqing” have taken over messaging culture in China and beyond. Stick...

12 Loka 201647min

a16z Podcast: Truce for Mobile, Battle for VR

a16z Podcast: Truce for Mobile, Battle for VR

The most recent Oculus Connect event (the third and largest yet) has been lauded as bringing us closer than ever to the future promised for virtual reality or VR. There have been many hardware moves b...

10 Loka 201635min

a16z Podcast: Mastering the Game (with David Oyelowo)

a16z Podcast: Mastering the Game (with David Oyelowo)

This special episode of the a16z Podcast is based on a Q&A from an early screening we hosted of Disney's Queen of Katwe, now in theaters. The movie -- directed by Mira Nair and based on a book by Tim ...

30 Syys 201621min

a16z Podcast: From Data Warehouses to Data Lakes

a16z Podcast: From Data Warehouses to Data Lakes

From the silver age of on-prem software companies like SAP and Siebel Systems to the golden age of enterprise software-as-a-service, we're now seeing an explosion of data. All types, all sizes, and al...

22 Syys 201628min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
mimmit-sijoittaa
psykopodiaa-podcast
rss-rahapodi
pomojen-suusta
ostan-asuntoja-podcast
rss-rahamania
rahapuhetta
rss-myyntikoulu
rss-draivi
herrasmieshakkerit
juristipodi
salkunrakentaja-podi
sijoitusovi-podcast
rss-h-asselmoilanen
rss-lahtijat
rss-startup-ministerio
rss-seuraava-potilas
rss-set-for-life-sijoita-ja-vaurastu
rss-viisas-raha-podi