Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Avsnitt(1000)

Ben Horowitz: RSI, Crypto as AI Money, & Classified Physics

Ben Horowitz: RSI, Crypto as AI Money, & Classified Physics

Moonshots host Peter Diamandis speaks with Ben Horowitz, cofounder and general partner at a16z, alongside regular cohosts Salim Ismail, Dave Blundin, and Dr. Alexander Wissner-Gross, about whether AI ...

23 Feb 1h 48min

Patrick Collison on Stripe’s Early Choices, Smalltalk, and What Comes After Coding

Patrick Collison on Stripe’s Early Choices, Smalltalk, and What Comes After Coding

Michael Truell, CEO of Cursor, sits down with Patrick Collison, CEO of Stripe and an investor in Anysphere, to talk about Collison's history with Smalltalk and Lisp, the MongoDB and Ruby decisions Str...

20 Feb 52min

AI’s Capital Flywheel: Models, Money, and the Future of Power

AI’s Capital Flywheel: Models, Money, and the Future of Power

a16z's Martin Casado and Sarah Wang join Latent Space hosts Alessio Fanelli and Swyx to discuss what makes this AI investment cycle unlike anything in the history of venture capital. They cover why th...

19 Feb 57min

From Copilots to Agents: Rebuilding the Company Around AI

From Copilots to Agents: Rebuilding the Company Around AI

a16z's Angela Strange and Gabriel Vasquez speak with Carlos García Ottati, founder and CEO of Kavak, about building Latin America's largest online used car marketplace across Mexico, Brazil, Chile, Ar...

18 Feb 59min

WSJ x a16z: The Next 25 Years of Defense Innovation

WSJ x a16z: The Next 25 Years of Defense Innovation

In this episode from WSJ Invest Live, Andy Serwer speaks with Katherine Boyle, general partner at a16z, about the American Dynamism practice she helped launch four years ago. They discuss why saying "...

17 Feb 30min

Novartis CEO Vasant Narasimhan on Transforming a 250-Year-Old Company

Novartis CEO Vasant Narasimhan on Transforming a 250-Year-Old Company

a16z general partner Jorge Conde talks with Vasant Narasimhan, CEO of Novartis International, about transforming a 250-year-old conglomerate into a pure play medicines company and unlocking $180 billi...

16 Feb 58min

Balaji and Dan Wang: The Engineering State vs Lawyerly State

Balaji and Dan Wang: The Engineering State vs Lawyerly State

Balaji Srinivasan speaks with Dan Wang, author of Breakneck, about China's industrial rise, America's competing strengths in software and finance, and what happens when an engineering state and a lawy...

13 Feb 1h 3min

Anish Acharya: Is SaaS Dead in a World of AI?

Anish Acharya: Is SaaS Dead in a World of AI?

In this episode from 20VC, Harry Stebbings talks with Anish Acharya, general partner at a16z, about the future of SaaS in an AI world. Anish argues that software is completely oversold and that the ge...

12 Feb 1h 21min

Populärt inom Business & ekonomi

badfluence
framgangspodden
varvet
rss-jossan-nina
rss-borsens-finest
rss-svart-marknad
uppgang-och-fall
avanzapodden
svd-tech-brief
fill-or-kill
rss-den-nya-ekonomin
rss-dagen-med-di
lastbilspodden
borsmorgon
ekonomiekot-extra
dynastin
rss-kort-lang-analyspodden-fran-di
rss-inga-dumma-fragor-om-pengar
bathina-en-podcast
market-makers