Anatomy of the SolarWinds Hack: Who What Where When How
a16z Podcast1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Avsnitt(901)

a16z Podcast: Tools for How We Work Today

a16z Podcast: Tools for How We Work Today

You've heard the story: Slack began as a game. But almost exactly 1 year ago today, the internal tool the team built for its own use became a team communication app that anyone (and especially enterprises) can use -- and is now one of the fastest growing ones at that. It seems like collaboration is "something software should be helping us with” Slack co-founder Stewart Butterfield observes, yet it typically isn't. So what can an app like Slack tell us about how we work today, and how the nature of work will change (fewer meetings? less emails)? Butterfield is joined in this edition of the a16z podcast by a16z board partner Steven Sinofsky and a16z's Benedict Evans. The trio examines the origins of messaging and task management tools (many of which Sinofsky worked on at Microsoft) -- and how the advent of cloud-based services and mobile in particular have changed the requirements for modern workplace tools and information management. The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

11 Feb 201538min

a16z Podcast: Searching for Mobile's Third OS

a16z Podcast: Searching for Mobile's Third OS

Consumers seem content with the mobile duopoly we currently have. So what can be gained from a third mobile operating system? If it's an open computing platform, argues Cyanogen CEO and co-founder Kirt McMaster (in discussion with a16z's Zal Bilimoria), one big win for developers and device makers is access to the guts of an operating system -- and the opportunity to exist as core services rather than simple apps riding on top of an OS. For consumers this means potentially new and unique software for smartphones, tablets, and wearables that take advantage of that tight integration. How else could the next Siri or Gmail take hold on mobile ... without necessarily coming from the likes of Apple and Google?? The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

7 Feb 201522min

a16z Podcast: Crisis Time -- What to Do When Things Go Sideways

a16z Podcast: Crisis Time -- What to Do When Things Go Sideways

A crisis can be an opportunity to change your culture. But you have to get through the crisis first, and that starts with getting to the truth of what happened. a16z's Margit Wennmachers, who co-founded The Outcast Agency, and Judy Smith, the founder of a crisis management firm but also "the real life Olivia Pope" (the inspiration behind the ABC show Scandal) draw on their long experience managing all types of crises to walk us through what steps to take when things go bad.

3 Feb 201527min

a16z Podcast: Mobile is Eating the World (and Apple is Gobbling Fastest)

a16z Podcast: Mobile is Eating the World (and Apple is Gobbling Fastest)

Apple absolutely crushed its most recent quarter, and unquestionably owns the high-end of the smartphone market, says a16z’s Benedict Evans. So where does Android fit in the ecosystem going forward? Where is the leverage for Google? Not to mention for Facebook, Amazon, and handset-makers like Samsung? Get used to this market complexion for the foreseeable future, Evans argues, with Apple owning the high-end; forked Android-powered devices flourishing at the low-end; and a battle to sell Google-approved Android gadgets in the middle. Until, of course, everything changes yet again.

30 Jan 201528min

a16z Podcast: Virtual Reality v Augmented Reality, and What's Next

a16z Podcast: Virtual Reality v Augmented Reality, and What's Next

Virtual reality (VR) -- and augmented reality (AR) -- seem to be everywhere these days, showing up in demos and offerings from the world's biggest gadget makers to the Hollywood, gaming, and media crowds. But what's the difference between VR and AR? Is one better suited for work vs. play? What happens when you are building experiences -- and an entirely new visual grammar -- from scratch ... will we actually need standards next? a16z's Chris Dixon and Wired Entertainment's Peter Rubin discuss all this and more on this episode of the a16z Podcast. The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

27 Jan 201530min

a16z Podcast: Coding as Literacy

a16z Podcast: Coding as Literacy

Tracy Chou from Pinterest, and Chris Granger and Jamie Brandon from Eve, discuss whether coding is a literacy (or as Granger puts it, a "superpower" ). But as software infuses every industry and much of our lives, do we all really need to start writing code? Or is a less hands-on approach -- educating ourselves about what software can (and can't) do, and the basic architecture behind its creation -- the most useful way to gain software literacy for most people? The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

19 Jan 201524min

a16z Podcast: The Technology is Ready, So Where is the Internet of Things?

a16z Podcast: The Technology is Ready, So Where is the Internet of Things?

Does your burglar alarm need to speak to your thermostat? What about your lighting system? And if all those things need to interoperate, how does that happen -- and what does that look like on the shelf at Home Depot? These are just some of the questions facing the Internet of Things. It was one of the highest-profile collections of gadgets and ideas at this year’s International CES, but is also a tech trend that has lots of consumers scratching their heads. a16z's Benedict (just back from the Vegas melee that is CES), Preethi, and Zal discuss the Internet of Things and more in this a16z Podcast. The technology is ready, so what are the breakout use cases going to be? The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

9 Jan 201518min

a16z Podcast: Dumb Storage Gets Smart

a16z Podcast: Dumb Storage Gets Smart

Storage as a set of technologies in the datacenter has a conservative reputation when it comes to innovation. Reliability, capacity, speed, and cost -- those have long been the only levers to pull in storage technology. Until Paula Long had the idea to add intelligence to enterprise-grade storage. Long, the CEO and founder of DataGravity joins a16z's Peter Levine for a discussion about storage. Why (and how) intelligence is a fit for storage technology, and how this smarter approach to handling data fits in with the datacenter of the future. The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation. This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments and certain publicly traded cryptocurrencies/ digital assets for which the issuer has not provided permission for a16z to disclose publicly) is available at https://a16z.com/investments/. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

19 Dec 201421min

Populärt inom Business & ekonomi

framgangspodden
badfluence
varvet
uppgang-och-fall
rss-borsens-finest
svd-ledarredaktionen
avanzapodden
affarsvarlden
fill-or-kill
borsmorgon
rss-kort-lang-analyspodden-fran-di
dynastin
rss-dagen-med-di
kapitalet-en-podd-om-ekonomi
rikatillsammans-om-privatekonomi-rikedom-i-livet
tabberaset
lastbilspodden
ett-rikare-liv
market-makers
ekonomiekot-extra