haroon meer Profile picture
Security Geek at Thinkst. We build https://t.co/Sv6Gp3sG6b
Feb 2, 2021 12 tweets 4 min read
a16z had a great podcast ep. on the SolarWinds hack (props to @smc90)

a16z.com/2021/01/31/16m…

Quick thoughts on it:

1) It's worth noting that the SolarWinds build environment was compromised months before the effects of it were discovered. (This is painfully consistent)

1/12 2) Instead of the attackers modifying the SolarWinds source code, they modified the build environment to insert their back door. This may be a nod to the classic "Reflections on Trusting Trust" paper¹, but is more likely because it's stealthier.

2/12
__
¹ dl.acm.org/doi/pdf/10.114…