HomeSecurityGoogle Cloud: We use some SolarWinds, but were not affected by the hack

Google Cloud: We use some SolarWinds, but were not affected by the hack

Google Cloud CISO Phil Venables revealed that the cloud uses software from the vendor, SolarWinds, but says its use was "limited.".

Google Cloud SolarWinds

Google Cloud announced the hiring of its first CISO, Phil Venables, in mid-December, just as the US was beginning to understand the scope of the SolarWinds attack.

The breach affected the U.S. and the U.S. Department of Commerce's National Telecommunications and Information Administration (NTIA), the Department of Justice, Microsoft , and more.

But Venables, a Goldman Sachs veteran, insists that no Google systems were affected by the attack. That's an important message from Google at a time when breaches have undermined trust in well-known software vendors.

"Based on what is known about the attack, we are confident that no Google systems were affected by the SolarWinds attack," Venables said in a blogpost.

“We make very limited use of the affected software and our approach to mitigating supply chain security risks meant that any subsequent use was limited. These controls were reinforced by sophisticated monitoring of our networks and systems.”

Venables also shared some top tips that Google uses to protect itself and its customers. This particular attack revealed how interconnected the entire software industry is and how vulnerable the ecosystem is due to updates received from various vendors.

Google Cloud SolarWinds

According to Venables, Google uses secure development and continuous testing frameworks to identify and avoid common programming. He goes on to explain what reliable cloud computing means in Google Cloud, which comes under the control of hardware and software.

Google verifies that the software is built and signed in an approved isolated build environment from properly tested, audited code .The company then performs various checks during development, depending on the sensitivity of the code. Finally, the company ensures that at least one person other than the author confidently reviews the code submitted by the developers.

“Sensitive administrative actions typically require additional human approvals. We do this to prevent unexpected changes – whether mistakes or malicious imports.”

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS