Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Dominion Voting Systems CEO Says Company Has Never Used SolarWinds Orion Platform
Epoch Times ^ | 12/15/2020 | Zachary Steiber

Posted on 12/15/2020 3:30:16 PM PST by SeekAndFind

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last
To: palmer

See my prev comments on this matter.

Signing your malicious code with a random cert is trivial, but creating your own binary signed by ‘microsoft’, or ‘solarwinds’ or ‘etc’ is hard. Inserting it into their update program is harder. I know cause i have done it. Very stressful, cause its on you if something is wrong and there are insane audit trails that do not go missing.

Unsigned ‘open source’ is not even in the same ball park’

Yes Adobe (flash product) has been a clusterf#(k forever but that has nothing to do with this.


41 posted on 12/15/2020 9:32:09 PM PST by algore
[ Post Reply | Private Reply | To 40 | View Replies]

To: SeekAndFind
Gosh, one more time we are told by the “experts” that we should not believe our eyes when they tell us things, as they get to choose which parts of what they tell us are true and which parts are false.

I would like to see him under oath in a court of law with the threat of perjury and under cross examination make the same statement. I would wager he would take the 5th Amendment.

42 posted on 12/15/2020 10:03:55 PM PST by Robert357
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #43 Removed by Moderator

To: SeekAndFind

Sorry... can someone get me up to speed on what “Solar Winds / Orion” is all about? Having a hard time keeping up with everything lately. Thanks.


44 posted on 12/15/2020 10:08:04 PM PST by nutmeg (Mega prayers for Rush Limbaugh)
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #45 Removed by Moderator

To: SeekAndFind
from Imgflip Meme Generator
"width=500">
46 posted on 12/16/2020 12:30:58 AM PST by Spitzensparkin1 (Donate often, it is our FReeping ammo. Keep the supply train rollin', become a monthly donor. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind

What is the version of the software with the known vulnerability? Whether these machines are running Windows or Linux, getting this version info is pretty easy.


47 posted on 12/16/2020 2:45:26 AM PST by nonsporting ("Christ shall be magnified in my body, whether it be by life, or by death." Philippians 1:20b)
[ Post Reply | Private Reply | To 3 | View Replies]

To: algore
but creating your own binary signed by ‘microsoft’, or ‘solarwinds’ or ‘etc’ is hard. Inserting it into their update program is harder. I know cause i have done it.

You mean easier. Just because solarwinds says it was "highly sophisticated" doesn't mean it was. It was very likely trivial to get the malicious software in. The solarwinds code signing cert private keys may or may not have been protected. The attackers may have used their own code signing private key.

Adobe is very relevant. A long vulnerability track record in both cases. Those track records are not an accident or random slop.

48 posted on 12/16/2020 5:54:41 AM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 41 | View Replies]

To: palmer

” The attackers may have used their own code signing private key.”

that fact that you even said that means you are totally clueless.

but don’t let that get in the way of your narrative.


49 posted on 12/16/2020 11:46:24 AM PST by algore
[ Post Reply | Private Reply | To 48 | View Replies]

To: algore
I don't have a narrative, you do. I looked up the attack and it was just a compromise of the integration environment, so they piggybacked on normal code updates. Their shotgun result may have benefitted some adversaries but more targetted attacks on other vulnerable SolarWinds products will be harder to detect.
50 posted on 12/16/2020 2:52:26 PM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 49 | View Replies]

To: malach

The presence of “QSnatch” does not necessarily indicate a hack, that could be intentional.


51 posted on 12/19/2020 9:20:05 AM PST by WHBates
[ Post Reply | Private Reply | To 43 | View Replies]

Comment #52 Removed by Moderator


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson