Anatomy of the SolarWinds Hack: Who What Where When How
a16z Podcast1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Episoder(906)

a16z Podcast: A Conversation With the Inventor of Spark

a16z Podcast: A Conversation With the Inventor of Spark

One of the most active and fastest growing open source big data cluster computing projects is Apache Spark, which was originally developed at U.C. Berkeley's AMPLab and is now used by internet giants and other companies around the world. Including, as announced most recently, IBM. In this Q&A with Spark inventor Matei Zaharia -- also the CTO and co-founder of Databricks (and a professor at MIT) -- on the heels of the recent Spark Summit, we cover the difference between Hadoop MapReduce and Spark; what are the ingredients of a successful open source project; and the story of how Spark almost helped a friend win a million dollars.

24 Jun 201519min

a16z Podcast: Investing in Communities

a16z Podcast: Investing in Communities

Investing to make a return both financial AND societal isn't new, but the opportunities to reach and build businesses in communities that have been underserved by tech are larger than ever. One example is the business opportunity presented by hairstylist platform Mayvenn, which a16z recently backed. In this segment of the a16z Podcast, Kesha Cash (founder and general partner of the Impact America Fund, also an investor in Mayvenn) discusses how she puts her fund’s money to work in markets that target underserved Americans. Cash is joined by a16z’s Tawny Holguin (who leads our seed and early scouting efforts) to breakdown the intricacies -- and opportunities -- of so-called “impact investing.” Do core business principles change at all? But then how does impact get measured? And what happens when you connect more communities to tech?

22 Jun 201524min

a16z Podcast: The Rise of the Quasi-IPO

a16z Podcast: The Rise of the Quasi-IPO

"This time is different." But it's always different! So what's going on now in the public markets? Why does this even matter? For one thing, tech markets have grown significantly. And one big reason is internet and mobile. It's like a multiplier for the market size and opportunity. In this episode of the a16z Podcast, Andreessen Horowitz managing partner Scott Kupor, mobile analyst Benedict Evans, and corp dev research partner Morgan Bender break down a slide deck we recently shared, including answers to what all these so-called “unicorns” are, how it affects venture capital and the funding landscape, and how we define a "quasi-IPO." The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

17 Jun 201529min

a16z Podcast: Location, Location, Location -- and Mobile

a16z Podcast: Location, Location, Location -- and Mobile

Pick your metaphor: Smartphones are "remote controls" for the physical world, or perhaps, as Steve Cheney argues, they're "cursors for the physical world". Either way, it's clear that the age of mobile is here, GPS is not enough, and with sensors all around us -- both outdoors and in indoor locations -- it's finally time for truly context-aware computing. But what will that take, both content- and design-wise -- is it all just about eliminating friction? And how are players like Apple and Google positioning themselves for this micro-mapped world? a16z's Benedict Evans and Estimote's Steve Cheney talk about these questions and more in this episode of the a16z Podcast...

11 Jun 201522min

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

Every meeting a busy founder takes is time away from building the company. So it’s understandable why engaging corporate development groups is believed to be a waste of time, unless you’re selling your company. But... there ARE good reasons to engage corporate development. You just have to know when, and how. And what to avoid! On this episode of the a16z Podcast, operating partner Jamie McGurk, and Tyson Clark and James Loftus (veterans of corporate development from companies like Google, Oracle, and Yahoo) share advice for founders talking to corporate development.

10 Jun 201522min

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

Apple’s annual developer conference is cranking away in San Francisco, and a16z’s Benedict Evans examines the latest from the world’s most valuable company in this segment of the pod. Software is the star of WWDC and Apple highlighted updates to iOS and OS X, but the big news was in part Apple News -- a curation and aggregation app for periodicals. Newsstand, Apple’s earlier attempt to tackle news outlets on your Apple device didn’t catch on, but Evans gives Apple News a better chance. And Apple Music? “It was a bit wooly, frankly,” Evans says. Translation: it didn’t amaze. Evans explains why.

10 Jun 201526min

a16z Podcast: Apple Watch -- Looking for New Things Done in New Ways

a16z Podcast: Apple Watch -- Looking for New Things Done in New Ways

Is the Apple Watch breaking new technological ground, or just another accessory for your iPhone? a16z’s Benedict Evans and Board Partner Steven Sinofsky describe their experience with the Apple Watch one month after strapping the elegant piece of electronics to their wrists. So how is it? It’s not the one thing you will own that will fill this void in your life like the iPhone did, Evans says. And working out what is useful and pleasurable about the Apple Watch takes time, he says. Even so, Evans finds himself getting there. For example, being prodded by the watch’s map app to turn left or right while walking to your destination “is like a super-power,” he says. Sinofsky too is finding his Apple Watch more alluring than he had anticipated. What will really make the Apple Watch a piece of kit that people won’t want to part with is the evolution of the apps -- building novel things just for the watch that don’t mimic what we do on smartphones or any other existing piece of technology. “We’re in the phase right now (with the Apple Watch) where people are trying to figure out how to do the old things in a new way,” Sinofsky says. “And really, you need to do new things in a new way.”

5 Jun 201522min

The Cool Stuff Only Happens at Scale

The Cool Stuff Only Happens at Scale

Distributed computing frameworks like Hadoop and Spark have enabled processing of "big data" sets -- but that's not enough for modeling surprise/rare "black swan" or complex events. Just think of scenarios in disaster planning (earthquakes, terrorist attacks, financial system collapse); biology (including disease); urban planning (cities, transportation, energy power grids); military defense ... and other complex systems where unknown behaviors and properties can emerge. They can't be modeled based on (by definition impossible) limited data. And parallelization for this is hard. But what if companies and governments could answer these seemingly impossible questions -- through simulations? Especially ones where we can directly merge in knowledge and cues from the real world (sensors, sensors everywhere)? CEO of Improbable Herman Narula and Stanford University professor-in-residence at a16z Vijay Pande discuss this and more with Chris Dixon in this episode of the a16z Podcast. And as Herman says, "the cool stuff only happens at scale". The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

5 Jun 201521min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
finansredaksjonen
livet-pa-veien-med-jan-erik-larssen
utbytte
pengesnakk
pengepodden-2
tid-er-penger-en-podcast-med-peter-warren
morgenkaffen-med-finansavisen
rss-sunn-okonomi
aksjesladder
lederpodden
nordnet-norge
okonomiamatorene
stormkast-med-valebrokk-stordalen
shifter
stinn-av-gryn