Anatomy of the SolarWinds Hack: Who What Where When How
a16z Podcast1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Episoder(904)

a16z Podcast: Government Transparency Powered by Software

a16z Podcast: Government Transparency Powered by Software

What if we could tap into our government with the same speed and ease as our smartphones and search? Can technology make a difference in how government operates, and how we citizens interact with it? Two-time Mountain View Mayor Mike Kasperzak, OpenGov CEO Zac Bookman, and a16z’s Tom Rikert discuss government’s historically uneasy relationship with technology, how a growing trend in government transparency is being powered by software, and why you should be glad your local city council takes its sweet time to pass a budget.

10 Jul 201420min

a16z Podcast: Protecting Your Company from Itself: Why You Need HR

a16z Podcast: Protecting Your Company from Itself: Why You Need HR

One of the ways to damage a fast-growing startup is to not have an HR person. But when is the right time to bring someone on? What qualities should you look for? How can you preserve the company culture and energy that got you where you are -- while still putting in place the processes that HR requires? Ben Horowitz and a16z’s head of technical talent Shannon Schiltz (Callahan) dive into the world of HR for startups. How does a good HR professional partner with a CEO? When you have to fire someone for the first time … and how should it go down? Musical kicker at end: If you thought you couldn’t rhyme Oculus, think again. For Ben’s debut on the a16z podcast, we included an original song provided by friend of the firm Divine (and produced by a16z’s own Chris Lyons). For more on Divine and his relationship with Ben, check out Rap Genius. http://rapgenius.com/Divine-the-4th-letter-venture-capitalist-like-ben-horowitz-lyrics

8 Jul 201424min

a16z Podcast: When Large Scale Gets Really Massive -- Managing Today’s Enterprise Networks

a16z Podcast: When Large Scale Gets Really Massive -- Managing Today’s Enterprise Networks

Managing enterprise networks with thousands of users and endpoints has been hard enough. Now that large enterprise networks routinely include hundreds of thousands of nodes it’s amazingly difficult and time-consuming (we’re talking days often) to get definitive answers to seemingly simple questions like, how many PCs do I have running? Never mind, how many PCs do I have that could be at risk of the Heartbleed virus? Tanium, the most recent company to join the a16z portfolio, offers a systems management and security tool that allows administrators to ask virtually any question about the configuration, performance, and complexion of an enterprise network and get an answer in seconds. Tanium CTO and Co-founder Orion Hindawi and a16z Board Partner Steven Sinofsky discuss the origins of Tanium; the invention of the “linear peer-to-peer communications” architecture that turbo-charges the Tanium solution; and with Internet of Things coming online fast, the prospect of networks quickly going to millions and billions of nodes.

27 Jun 201418min

a16z Podcast: Google I/O -- A Three-Hour Tour (in 30 minutes)

a16z Podcast: Google I/O -- A Three-Hour Tour (in 30 minutes)

The Google I/O keynote was epic in at least one respect, length. For three hours Google laid out the near horizon for all things Google. This included the next version of Android; a new platform for connected watches; Google for your car; yet another Google TV; and a new health platform. Andreessen Horowitz’s Benedict Evans plowed through it all, including what was noticeably absent: Google+ and Google Glass. What the future looks like as the lines between mobile apps and web pages blur, and why Google is the new Microsoft -- in the best possible way.

26 Jun 201433min

a16z Podcast: Datacenter of the Future

a16z Podcast: Datacenter of the Future

The datacenter has long been -- there's no nice way to put this -- a bit of a snoozer. Expensive boxes running expensive software. No more, says a16z General Partner Peter Levine. Along with Chris Dixon, Levine lays out a vision for the datacenter of the future. Building on the technology established by companies like Facebook and Google, Levine and Dixon describe a software-led transformation of the datacenter, one where the mobile supply chain and fast-moving companies are reimagining everything -- from the underlying architecture to new business models. Be prepared to get in the weeds, hear Levine talk about the next opportunity, “hosted instances,” Dixon describe the “the dream within the dream,” and discover why the datacenter is about to get exciting.

18 Jun 201425min

a16zPodcast: People Marketplaces Take On One of the Last Great E-Commerce Opportunities -- Groceries

a16zPodcast: People Marketplaces Take On One of the Last Great E-Commerce Opportunities -- Groceries

People Marketplaces are a lot like eBay -- connecting buyer and seller -- but for services, says a16z General Partner Jeff Jordan. These two-sided marketplaces are cropping up across the economy, from finding a ride to house cleaning and pet sitting. Now Instacart is bringing the People Marketplace model to the grocery business -- a massive market that has seen very little change even as the internet and mobile have upended most retail categories. Joined by a16z's Sam Gerstenzang, this segment outlines the elements of a People Marketplace; why the model is gathering momentum now; and if we all remember what happened with Webvan, why is this time is different?

16 Jun 201412min

a16z Podcast: Mapping the Information Economy -- Where’s the Cloud Going Next?

a16z Podcast: Mapping the Information Economy -- Where’s the Cloud Going Next?

a16z Board Partner Steven Sinofsky and Box CEO and co-founder Aaron Levie discuss findings from a study of the information economy that has been built on cloud and mobile. The findings were based on workflow data collected anonymously from a subset of 25 million users, 225,000 businesses, and five industries (you can see the report here: http://blog.box.com/2014/06/mapping-the-information-economy-a-tale-of-five-industries/). It all amounts to big shifts in enterprise IT. But what are the implications of these findings for everyone’s business ... beyond Silicon Valley and the software industry? And finally -- shared in a live brainstorm at the end -- what’s the future of the cloud?

13 Jun 201417min

a16z Podcast: The Promise (and Nightmare) of Cross-Platform Software

a16z Podcast: The Promise (and Nightmare) of Cross-Platform Software

The announcement by Apple of its new programming language Swift is prompting developers to consider yet again how to tailor their efforts in the battle between iOS and Android. Benedict Evans and Steven Sinofsky discuss the questionable history of cross-platform software, and strategies for startups building apps today. How developers can build great apps on both of the largest mobile platforms. This platform question is one Sinofsky has been grappling with for a very long time, and which he also details in this post: http://blog.learningbyshipping.com/2013/07/08/juggling-multiple-platforms-and-the-bumpy-road-ahead/

6 Jun 201416min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
finansredaksjonen
utbytte
tid-er-penger-en-podcast-med-peter-warren
livet-pa-veien-med-jan-erik-larssen
pengepodden-2
aksjesladder
morgenkaffen-med-finansavisen
pengesnakk
rss-sunn-okonomi
lederpodden
nordnet-norge
okonomiamatorene
stormkast-med-valebrokk-stordalen
rss-impressions-2
shifter