Anatomy of the SolarWinds Hack: Who What Where When How
a16z Podcast1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Avsnitt(902)

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

Every meeting a busy founder takes is time away from building the company. So it’s understandable why engaging corporate development groups is believed to be a waste of time, unless you’re selling your company. But... there ARE good reasons to engage corporate development. You just have to know when, and how. And what to avoid! On this episode of the a16z Podcast, operating partner Jamie McGurk, and Tyson Clark and James Loftus (veterans of corporate development from companies like Google, Oracle, and Yahoo) share advice for founders talking to corporate development.

10 Juni 201522min

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

Apple’s annual developer conference is cranking away in San Francisco, and a16z’s Benedict Evans examines the latest from the world’s most valuable company in this segment of the pod. Software is the star of WWDC and Apple highlighted updates to iOS and OS X, but the big news was in part Apple News -- a curation and aggregation app for periodicals. Newsstand, Apple’s earlier attempt to tackle news outlets on your Apple device didn’t catch on, but Evans gives Apple News a better chance. And Apple Music? “It was a bit wooly, frankly,” Evans says. Translation: it didn’t amaze. Evans explains why.

10 Juni 201526min

a16z Podcast: Apple Watch -- Looking for New Things Done in New Ways

a16z Podcast: Apple Watch -- Looking for New Things Done in New Ways

Is the Apple Watch breaking new technological ground, or just another accessory for your iPhone? a16z’s Benedict Evans and Board Partner Steven Sinofsky describe their experience with the Apple Watch one month after strapping the elegant piece of electronics to their wrists. So how is it? It’s not the one thing you will own that will fill this void in your life like the iPhone did, Evans says. And working out what is useful and pleasurable about the Apple Watch takes time, he says. Even so, Evans finds himself getting there. For example, being prodded by the watch’s map app to turn left or right while walking to your destination “is like a super-power,” he says. Sinofsky too is finding his Apple Watch more alluring than he had anticipated. What will really make the Apple Watch a piece of kit that people won’t want to part with is the evolution of the apps -- building novel things just for the watch that don’t mimic what we do on smartphones or any other existing piece of technology. “We’re in the phase right now (with the Apple Watch) where people are trying to figure out how to do the old things in a new way,” Sinofsky says. “And really, you need to do new things in a new way.”

5 Juni 201522min

The Cool Stuff Only Happens at Scale

The Cool Stuff Only Happens at Scale

Distributed computing frameworks like Hadoop and Spark have enabled processing of "big data" sets -- but that's not enough for modeling surprise/rare "black swan" or complex events. Just think of scenarios in disaster planning (earthquakes, terrorist attacks, financial system collapse); biology (including disease); urban planning (cities, transportation, energy power grids); military defense ... and other complex systems where unknown behaviors and properties can emerge. They can't be modeled based on (by definition impossible) limited data. And parallelization for this is hard. But what if companies and governments could answer these seemingly impossible questions -- through simulations? Especially ones where we can directly merge in knowledge and cues from the real world (sensors, sensors everywhere)? CEO of Improbable Herman Narula and Stanford University professor-in-residence at a16z Vijay Pande discuss this and more with Chris Dixon in this episode of the a16z Podcast. And as Herman says, "the cool stuff only happens at scale". The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

5 Juni 201521min

a16z Podcast: Tech Trends Changing Gaming

a16z Podcast: Tech Trends Changing Gaming

with Justin Bailey (@justinbailey12d), Herman Narula (@hermannarula), Tim Schafer (@timoflegend) and Sonal Chokshi (@smc90) We know that the gaming industry -- in some ways like but in other ways unlike the music industry -- has been changing due to the internet and especially technologies around crowdfunding, online discovery, and direct fan interaction. But how does this affect the creative process and studio model … especially when it comes virtual reality (the ability to craft more immersive experiences); systems tech (is there a tension between content-focused games there?); and the ease with which users -- not just a few rarified developers -- can mod the games themselves? In this episode of the a16z Podcast, hosted by Sonal Chokshi, listen in on the conversation between Tim Schafer, founder and CEO of Double Fine Productions (and designer of LucasArts’ Grim Fandango); Justin Bailey, COO of Double Fine; and Herman Narula (CEO of Improbable). The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

4 Juni 201530min

a16z Podcast: For Google, Android is a Tactic and Cloud is a Strategy

a16z Podcast: For Google, Android is a Tactic and Cloud is a Strategy

Google is a vast machine learning company. If you think about it in those terms, says Benedict Evans, every product and feature Google builds is an expression of its machine learning expertise -- or a way to distribute it, and provide easier access to it. Evans joins the pod to pick apart all the latest machine learning-driven tech from Google as it hosts its annual developer party I/O. What’s become very clear this year, Evans says, is that for Google all the really cool stuff isn’t happening in Android, it’s happening in the Cloud. Finally, what’s next in VR from Google, and how it plans to tackle the developing world.

30 Maj 201528min

a16z Podcast:  The Future of Entertainment and What David Petraeus and the Olsen Twins Can Teach Us

a16z Podcast: The Future of Entertainment and What David Petraeus and the Olsen Twins Can Teach Us

If there’s one business on planet earth that makes Silicon Valley look sober and level-headed it’s Hollywood, says Marc Andreessen. Hollywood and Silicon Valley meet in this segment of the pod which features Andreessen in conversation with Brian Grazer, the super-producer behind half the movies and television you’ve watched in the last three-plus decades including Empire, 24, Parenthood, Arrested Development, Friday Night Lights, The DaVinci Code, 8 Mile, A Beautiful Mind, Apollo 13, Real Genius, Splash… You get the idea. Grazer and Andreessen talk about the future of the entertainment business; why TV is in a golden age of creativity; and how technology and the kinds of stories that Grazer produces can feed off each other -- or not. The conversation took place at the launch of Grazer’s book, “A Curious Mind: The Secret to a Bigger Life,” which describes the “curiosity conversations” Grazer has held for the past 35 years with a succession of artists, scientists, politicians, technologists and people of every stripe. You name them, and Grazer has sat down with them to try and learn their secrets.

25 Maj 201519min

a16z Podcast: Finding and Hiring for (Expectations) Fit on Both Sides

a16z Podcast: Finding and Hiring for (Expectations) Fit on Both Sides

"Fit" is this squishy idea that a person, role, and company are a perfect match. But how do you tease out expectations and motivations from both sides of the hiring equation -- candidates and founding CEOs alike? In this segment of the a16z Podcast,a16z Executive Talent head Jeff Stump and resident talent expert Gia Scinto tackle ways to identify and analyze this, and methodically. And they share their secret weapon for putting the right person in the right job: "the 100-Day Plan".

22 Maj 201528min

Populärt inom Business & ekonomi

framgangspodden
badfluence
varvet
uppgang-och-fall
svd-ledarredaktionen
rss-borsens-finest
avanzapodden
borsmorgon
affarsvarlden
rss-kort-lang-analyspodden-fran-di
rss-dagen-med-di
dynastin
kapitalet-en-podd-om-ekonomi
fill-or-kill
rikatillsammans-om-privatekonomi-rikedom-i-livet
tabberaset
lastbilspodden
market-makers
ett-rikare-liv
rss-inga-dumma-fragor-om-pengar