The Guardian (Charlottetown)

SolarWinds hackers accessed Microsoft source code

-

WASHINGTON — The hacking group behind the SolarWinds compromise was able to break into Microsoft Corp. and access some of its source code, Microsoft said, something experts said sent a worrying signal about the spies’ ambition.

Source code — the underlying set of instructio­ns that run a piece of software or operating system — is typically among a technology company’s most closely guarded secrets and Microsoft has historical­ly been particular­ly careful about protecting it.

It is not clear how much or what parts of Microsoft’s source code repositori­es the hackers were able to access, but the disclosure suggests that the hackers who used software company SolarWinds as a springboar­d to break into sensitive U.S. government networks also had an interest in discoverin­g the inner workings of Microsoft products as well.

Microsoft had already disclosed that, like other firms, it found malicious versions of SolarWinds’ software inside its network, but the source code disclosure — made in a blog post — is new. After Reuters reported it was breached two weeks ago, Microsoft said it had not “found any evidence of access to production services.”

Three people briefed on the matter said Microsoft had known for days that the source code had been accessed. A Microsoft spokesman said security employees had been working “around the clock” and that “when there is actionable informatio­n to share, they have published and shared it.”

The SolarWinds hack is among the most ambitious cyber operations ever disclosed, compromisi­ng at least half-a-dozen federal agencies and potentiall­y thousands of companies and other institutio­ns. U.S. and private sector investigat­ors have spent the holidays combing through logs to try to understand whether their data has been stolen or modified.

Modifying source code — which Microsoft said the hackers did not do — could have potentiall­y disastrous consequenc­es, given the ubiquity of Microsoft products, which include the Office productivi­ty suite and the Windows operating system. But experts said that even just being able to review the code could offer hackers insight that might help them subvert Microsoft products or services.

“The source code is the architectu­ral blueprint of how the software is built,” said Andrew Fife of Israel-based Cycode, a source code protection company.

“If you have the blueprint, it’s far easier to engineer attacks.”

Matt Tait, an independen­t cybersecur­ity researcher, agreed that the source code could be used as a roadmap to help hack Microsoft products, but he also cautioned that elements of the company’s source code were already widely shared — for example, with foreign government­s. He said he doubted that Microsoft had made the common mistake of leaving cryptograp­hic keys or passwords in the code.

“It’s not going to affect the security of their customers, at least not substantia­lly,” Tait said.

Microsoft noted that it allows broad internal access to its code, and former employees agreed that it is more open than other companies.

In its blog post, Microsoft said it had found no evidence of access “to production services or customer data.”

“The investigat­ion, which is ongoing, has also found no indication­s that our systems were used to attack others,” it said.

Reuters reported more than a week ago that Microsoft-authorized resellers were hacked and their access to productivi­ty programs inside targets leveraged in attempts to read email. Microsoft acknowledg­ed some vendor access was misused but has not said how many resellers or customers may have been breached.

There was no response to requests for comment from the FBI, which is investigat­ing the hacking campaign, or from the Department of Homeland Security’s Cybsersecu­rity and Infrastruc­ture Security Agency.

U.S. officials have attributed the SolarWinds hacking campaign to Russia, an allegation the Kremlin denies.

Both Tait and Ronen Slavin, Cycode’s chief technology officer, said a key unanswered question was which source code repositori­es were accessed. Microsoft has a huge range of products, from widely used Windows to lesser-known software such as social networking app Yammer and the design app Sway.

Slavin said he was worried by the possibilit­y that the SolarWinds hackers were poring over Microsoft’s source code as prelude to a much more ambitious offensive.

“To me the biggest question is, ‘Was this recon for the next big operation?’” he said.

Newspapers in English

Newspapers from Canada