Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Episoder(1000)

a16z Podcast: When Will Genomics Live Up to the Hype?

a16z Podcast: When Will Genomics Live Up to the Hype?

It's been nearly 15 years since the Human Genome Project was completed. But "are we there yet" in the golden age of genomics? What did we think we'd have by now, what do we actually have, and what do ...

22 Feb 201725min

a16z Podcast: Startups, Pivots, Culture, and Timing (Oh Shit!)

a16z Podcast: Startups, Pivots, Culture, and Timing (Oh Shit!)

The hardest thing about pivots (major shifts in company/product direction) isn't just the actual pivot. It's the courage to make the decision... and being honest with yourself as a CEO. Especially sin...

19 Feb 201732min

a16z Podcast: Securing Infrastructure and Enterprise Services

a16z Podcast: Securing Infrastructure and Enterprise Services

The modern enterprise holds all sorts of applications, devices, and workflow needs. How should we be thinking about securing infrastructure -- and identity -- in this context, for entities like major ...

14 Feb 201719min

a16z Podcast: Cars and Cities, the Autonomy Edition

a16z Podcast: Cars and Cities, the Autonomy Edition

Thanks to freeways, cities became something to get through instead of something to get to. Now, as the next transportation revolution -- from rivers to trains to cars to autonomous cars -- promises to...

8 Feb 201735min

a16z Podcast: What Startups Should Know about Analyst Relations

a16z Podcast: What Startups Should Know about Analyst Relations

In the age of the internet -- where information is freely available online, and connections between sellers and buyers of software products are visible on LinkedIn -- do analysts really matter? Do the...

1 Feb 201731min

a16z Podcast: Building Worlds with VR, Art, and Narrative

a16z Podcast: Building Worlds with VR, Art, and Narrative

Once upon a time, Robert Stromberg got a phone call from "Jim" Cameron (aka James Francis Cameron of Terminator and Titanic fame) about a little project called Avatar. Before he knew it, he was respon...

27 Jan 201738min

a16z Podcast: The Why, How, and When of PR

a16z Podcast: The Why, How, and When of PR

"Punch above your weight" -- If there's one thing public relations (PR) should help startups and founders do, it's that. Unfortunately, some companies are actually punching below their weight when the...

26 Jan 201742min

a16z Podcast: VR, AR, and Beyond: The New Medium of Human Experience

a16z Podcast: VR, AR, and Beyond: The New Medium of Human Experience

The building blocks for VR and AR are finally here -- but the content is just beginning. So everything you'll actually experience and consume in these new mediums over the next few years is being buil...

24 Jan 201726min

Populært innen Business og økonomi

stopp-verden
lydartikler-fra-aftenposten
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
utbytte
pengepodden-2
finansredaksjonen
livet-pa-veien-med-jan-erik-larssen
rss-sunn-okonomi
morgenkaffen-med-finansavisen
tid-er-penger-en-podcast-med-peter-warren
okonomiamatorene
pengesnakk
lederpodden
rss-markedspuls-2
rss-andelige-tanker-med-camillo
rss-fa-makro
stormkast-med-valebrokk-stordalen