Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Avsnitt(1000)

a16z Podcast: Is Entrepreneurship a Universal Language?

a16z Podcast: Is Entrepreneurship a Universal Language?

In this special international edition of the a16z Podcast, Mohsen Malayeri, co-founder of Avatech -- one of the more prominent startup accelerators in Iran among many (much like Y Combinator in the U....

1 Juli 201542min

a16z Podcast: Layering Tech and Culture in Iran

a16z Podcast: Layering Tech and Culture in Iran

In this special international edition of the a16z Podcast, Nazanin Daneshvar, co-founder and CEO of Takhfifan, the "Groupon of Iran", shares her experiences and broader observations about the startup ...

30 Juni 201519min

a16z Podcast: A Conversation With the Inventor of Spark

a16z Podcast: A Conversation With the Inventor of Spark

One of the most active and fastest growing open source big data cluster computing projects is Apache Spark, which was originally developed at U.C. Berkeley's AMPLab and is now used by internet giants ...

24 Juni 201519min

a16z Podcast: Investing in Communities

a16z Podcast: Investing in Communities

Investing to make a return both financial AND societal isn't new, but the opportunities to reach and build businesses in communities that have been underserved by tech are larger than ever. One exampl...

22 Juni 201524min

a16z Podcast: The Rise of the Quasi-IPO

a16z Podcast: The Rise of the Quasi-IPO

"This time is different." But it's always different! So what's going on now in the public markets? Why does this even matter? For one thing, tech markets have grown significantly. And one big reason i...

17 Juni 201529min

a16z Podcast: Location, Location, Location -- and Mobile

a16z Podcast: Location, Location, Location -- and Mobile

Pick your metaphor: Smartphones are "remote controls" for the physical world, or perhaps, as Steve Cheney argues, they're "cursors for the physical world". Either way, it's clear that the age of mobil...

11 Juni 201522min

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

a16z Podcast: Dealing with Corporate Dealmakers -- When to Talk to Corp Dev

Every meeting a busy founder takes is time away from building the company. So it’s understandable why engaging corporate development groups is believed to be a waste of time, unless you’re selling you...

10 Juni 201522min

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

a16z Podcast: Apple Gets Its Music Streaming and Gives News Another Try

Apple’s annual developer conference is cranking away in San Francisco, and a16z’s Benedict Evans examines the latest from the world’s most valuable company in this segment of the pod. Software is the ...

10 Juni 201526min

Populärt inom Business & ekonomi

framgangspodden
varvet
rss-jossan-nina
rss-svart-marknad
rss-borsens-finest
svd-tech-brief
avanzapodden
uppgang-och-fall
badfluence
bathina-en-podcast
fill-or-kill
lastbilspodden
rss-inga-dumma-fragor-om-pengar
rss-dagen-med-di
dynastin
tabberaset
24fragor
rikatillsammans-om-privatekonomi-rikedom-i-livet
borsmorgon
kapitalet-en-podd-om-ekonomi