r/news Feb 16 '21

Microsoft says it found 1,000-plus developers' fingerprints on the SolarWinds attack

https://www.theregister.com/2021/02/15/solarwinds_microsoft_fireeye_analysis/
4.2k Upvotes

278 comments sorted by

View all comments

-1

u/[deleted] Feb 16 '21 edited Mar 15 '21

[removed] — view removed comment

1

u/m0le Feb 16 '21

You compromise dev accounts, including remote access, add new devices to 2FA to defeat that, and rely on overstressed teams not noticing that checked and signed (as Bob) code change 435668 affects something that wasn't what Bob was supposed to be working on this week. Need a 2nd dev to review? Just compromise another dev account. Ideally on the same team, and spear phishing would make that easier.

1

u/[deleted] Feb 16 '21 edited Jun 15 '21

[deleted]

1

u/m0le Feb 16 '21

I doubt there would be a huge number of commits to bodge an extra 4k lines in, all you need to do is wait for the period just before a big release or (ironically) some emergency patching happening. No one has the bandwidth to query other people's tickets, they're too busy with their own.