Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

11–20 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#11

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability.

In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc).

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#12
Maybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software.

Here is the BBC news update about the NHS Cyber attack:

"NHS trusts 'ran outdated software'

Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated Windows XP software.

The website says that Microsoft officially ended support for Windows XP back in April 2014, meaning it was no longer fixing vulnerabilities in the system - except for clients that paid for an extended support deal.

The UK government initially paid Microsoft £5.5 million to keep providing security support - but the website adds that this deal ended in May 2015."

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#13
Cyber attacks use patched exploit to attack systems running out of date software, even in large enterprises handling sensitive data?

I give a pass to individuals (bandwidth for updates can be expensive, regular users don't know about patch Tuesday etc), but enterprise scale deployment should have IT for this, and IT should have been well aware of this kind of thing happening.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#15
One of the big problems here will be for any country which makes a lot of use of older computers using Windows XP as there is no patch for this vulnerability on that OS version.

How many systems that is, is debatable but by at least one benchmark (https://www.netmarketshare.com/operating-system-market-share...) we're looking at 7% of the desktop PC market that could be exposed with no patch available.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#16

Maybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software. Here is the BBC news update about the NHS Cyber attack: "NHS trusts 'ran outdated software' Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated…

Linux doesn't have a magic fix for buffer overflows in networking stacks written in C.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#17
This is what blowback looks like.

The US military and intelligence communities focused hard on cyber offense, rather than improving the defensive standards and technologies practiced among allies. Because of this, several allies have important systems compromised by (essentially) US-engineered malware.

Well, at least DARPA is sort of on it: http://archive.darpa.mil/cybergrandchallenge/

(There's also work stemming from the HoTT body of work on verified systems, as I understand it. But that doesn't have a sexy webpage.)

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#18

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#19

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network.

This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were using (although sometimes it was), it was that many medical devices (like CT scanners, pumps, etc) come shipped with old outdated versions of operating systems and libraries.

No big deal right? Just make sure those are up to date too? Well, many times the support contract for these medical devices are so strict that you can invalidate the warranty by installing third party software like an antivirus, or even doing something like Windows update.

Even worse, many hospitals don't even know what devices they have -- it's easy for IT to know about laptops and computers, but when every single medical device more complicated than a stethoscope has a chip in it and may respond to calls on certain ports, it's a tougher picture to know.

The startup was https://www.virtalabs.com/ by the way, they really are doing some cool things to help with this.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#20

Maybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software. Here is the BBC news update about the NHS Cyber attack: "NHS trusts 'ran outdated software' Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated…

Linux doesn't have a magic fix for buffer overflows in networking stacks written in C.

> except for clients that paid for an extended support deal

It does have a fix for this, though

Post reply on HN