Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Avsnitt(1000)

Emmett Shear on Building AI That Actually Cares: Beyond Control and Steering

Emmett Shear on Building AI That Actually Cares: Beyond Control and Steering

Emmett Shear, founder of Twitch and former OpenAI interim CEO, challenges the fundamental assumptions driving AGI development. In this conversation with Erik Torenberg and Séb Krier, Shear argues that...

17 Nov 20251h 10min

Can America Win The AI Biotech Race Against China? | Lada Nuzhna & Elliot Hershberg

Can America Win The AI Biotech Race Against China? | Lada Nuzhna & Elliot Hershberg

Two venture capitalists dissect why biotech burns billions while China runs trials in weeks—and why the next Genentech won't look anything like the last one. Elliot Hershberg reveals the "three horsem...

14 Nov 20251h 2min

The Frontier of Spatial Intelligence with Fei-Fei Li

The Frontier of Spatial Intelligence with Fei-Fei Li

Fei-Fei Li and Justin Johnson are pioneers in AI. While the world has only recently witnessed a surge in consumer AI, they have long been laying the groundwork for the innovations transforming industr...

13 Nov 202544min

Rocket Companies CEO: Here’s How to Fix the Housing Crisis

Rocket Companies CEO: Here’s How to Fix the Housing Crisis

The Empire State Building took 110 days to build—today, changing a window would take two years. Alex Rampell (a16z) and Varun Krishna (Rocket CEO) expose how asset inflation turned housing from the Am...

12 Nov 202555min

Grant Lee: Building Gamma’s AI Presentation Company to 100 Million Users

Grant Lee: Building Gamma’s AI Presentation Company to 100 Million Users

Grant Lee was told Gamma was "the worst idea ever heard" by an investor who hung up mid-Zoom—yet he built it to 100 million users and $100M ARR without spending a dollar on advertising.While competito...

11 Nov 202553min

Michael Truell: How Cursor Builds at the Speed of AI

Michael Truell: How Cursor Builds at the Speed of AI

When four MIT grads decided to build a code editor while everyone else was building AI agents, they created the fastest-growing developer tool ever built. Cursor CEO Michael Truell joins a16z’s Martin...

10 Nov 202527min

a16z's State of Crypto: The $4 Trillion Milestone and What's Next'

a16z's State of Crypto: The $4 Trillion Milestone and What's Next'

The regulatory environment has completely inverted. Stablecoins are now a top 20 holder of US treasuries. Every major bank wants in. In a16z Crypto's 2025 State of Crypto report, Daren Matsuoka (Head ...

9 Nov 20251h 38min

Amjad Masad & Adam D’Angelo: How Far Are We From AGI?

Amjad Masad & Adam D’Angelo: How Far Are We From AGI?

Adam D’Angelo (Quora/Poe) thinks we're 5 years from automating remote work. Amjad Masad (Replit) thinks we're brute-forcing intelligence without understanding it.In this conversation, two technical fo...

7 Nov 20251h 2min

Populärt inom Business & ekonomi

framgangspodden
varvet
badfluence
rss-jossan-nina
rss-borsens-finest
rss-svart-marknad
svd-tech-brief
avanzapodden
uppgang-och-fall
fill-or-kill
rss-inga-dumma-fragor-om-pengar
borsmorgon
rss-dagen-med-di
lastbilspodden
bathina-en-podcast
rss-kort-lang-analyspodden-fran-di
affarsvarlden
market-makers
rss-den-nya-ekonomin
borslunch-2