Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

31–40 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#31
"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems."

What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers?

Could someone share a "What should I do now to protect myself" guide, please?

Thanks!

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#33
post #31

"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers? Could someone share a "What should I do now to protect myself" guide, please? Thanks!

For this, run Windows update and install all updates. Additionally, it's smart to disable SMBv1 on all machines.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#34

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automatically loses certification and cannot be used for medical purposes.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#35
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Yeah, I am pretty sure all governments do this. Why would they release it if their goal is to get unrestricted access to the public. They don't want those holes patched, so to speak.

I wonder how much of their efforts are deterred when good minded infosec persons find vulnerabilities and report them; remember Heart bleed.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#36

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

Why are those devices being connected to an unsecure network? Surely they should have super limited data exchange features?

As is commonly the case, hardware vendors are more concerned with selling you the hardware and probably spend bottom-dollar for their software developers. I can't say that I've worked in such an environment, but my impression is that management at such companies probably see software dev as a cost-centre rather than something to actually spend money on for quality.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#37
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Your last sentence seems to contradict your first, whereas what you would really prefer is to disarm the police. Sadly I don't think that's so practical, in the same way that it would be impractical for US police to go unarmed given the high incidence of gun ownership in the US. I grew up in a country where police are not normally armed (other than with a small baton or similar personal defense weapon) and much prefer that, but when there's a lot of weapons around that's a reality you have to deal with.

As regards these cyberattacks, the NSA is at fault for its poor security allowing the weapons to become available to bad actors, but the mere existence or stockpiling of weapons is not the direct cause of crime. It might be more useful right now to consider who is operating these weapons, where they are firing them from, and how best to neutralize them.

tl;dr when you're under fire is not the time to worry about gun control.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#38

I am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.

This malware is well written, and uses strong encryption.

I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software.

I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against future attacks.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#39

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

well I suspect that such devices should not be connected I was on dialysis at a clinic from one of the effected trusts and boy am I glad that my hemo dialysis machine was not connected to the network.
Post reply on HN