1009
Comments (40)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
1
marishiten 1 point ago +1 / -0

That's saying that they're using an API to hit SolarWinds servers then another tunnel to your own local servers. Why would your hardware/software tunnel to SW > SW then tunnels to local servers/other servers.

If they did that, there is no way in hell the government would allow that. I worked as IT for a solar monitoring company and we didn't have government contracts. Not because they weren't interested, but because our monitoring devices NEED to be connected to the internet. They wanted our it so the data would be sent to their local servers with an VM of our aggregate software so they can monitor. If that couldn't happen, they wouldn't do it. They were not keen on our devices punching holes in their firewall connecting to a remote server they can't oversee on a device they can't certify (they were also not happy with the device listening on ssh ports, but that's another thing completely).

Point of the story is that the government wouldn't allow that kind of tunneling/aggregation to third party private servers like that. The government is stupid, but they're not that stupid.

1
deleted 1 point ago +1 / -0