AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
The Importance of Due Diligence in the Software Supply Chain
Maintainers, the people who have to maintain your software can very often fall to the business tactics of others. SolarWinds used to be a great engineering company but some very clever people set up in order to provide software that would enable you to optimize the performance of complicated Windows databases. They sacked most of the really able engineers who maintained this product and replaced them with low cost labor from Eastern Europe. The Russian FSB managed to infiltrate SolarWinds infrastructure and they saw to it that when SolarWinds updated its product it included an advanced persistent thread which basically installed itself and reported back to Moscow. And this meant that over a dozen US government departments were running Russian spyware together with 100