Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

41–50 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#41
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Right, I'm sure the NSA doesn't currently take any effort to secure their trove of 0-days. It's not like they're valuable assets or anything. Edit: My point is that thinking that requiring the NSA to keep them "as secure as possible" as though that would eliminate risk is just silly. There will always be risk of breach or insider theft, as well as the requirement that the exploits actually be put to use outside some…

Welp, here we are.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#42

Earlier quoted context omitted.

Your analogy doesn't really work because you can't copy a gun. These tools are way more dangerous than a gun because you can replicate them very quickly. You can never destroy the tools once they are created, someone always has a copy. This is what scares me more than nuclear weapons. A nuke requires a huge amount of people and infrastructure to maintain and launch. But a digital weapon? Pfft, copy that shit onto a U…

Why are power stations on the same network with some guy with a USB key?

Because they are all connected in a IoT with MongoDB, React, and Node.js

/s

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#43

Earlier quoted context omitted.

Your analogy doesn't really work because you can't copy a gun. These tools are way more dangerous than a gun because you can replicate them very quickly. You can never destroy the tools once they are created, someone always has a copy. This is what scares me more than nuclear weapons. A nuke requires a huge amount of people and infrastructure to maintain and launch. But a digital weapon? Pfft, copy that shit onto a U…

Why are power stations on the same network with some guy with a USB key?

Because people still use USB drives to copy information to airgapped computers. It is easier than the alternatives.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#44
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Right, I'm sure the NSA doesn't currently take any effort to secure their trove of 0-days. It's not like they're valuable assets or anything. Edit: My point is that thinking that requiring the NSA to keep them "as secure as possible" as though that would eliminate risk is just silly. There will always be risk of breach or insider theft, as well as the requirement that the exploits actually be put to use outside some…

> Right, I'm sure the NSA doesn't currently take any effort to secure their trove of 0-days.

This case seems to show that whatever effort they're making is not sufficient.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#45

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

They had better at least honor their warantee and replace all this hosed equipment.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#46

Can't law enforcement follow the transactions of the public address of the ransom bitcoin wallet until the bitcoin is sold?

There are services that will mix your coins making it impossible to track because he will receive other people coins from the pool.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#47
post #18

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

Keep in mind that on business grade installs the updates are not forced.

And there have already been situations where updates have caused problems. Maybe not as severe as a full on attack, but enough to potentially disrupt production and thus risk someones job.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#49

Earlier quoted context omitted.

Your analogy doesn't really work because you can't copy a gun. These tools are way more dangerous than a gun because you can replicate them very quickly. You can never destroy the tools once they are created, someone always has a copy. This is what scares me more than nuclear weapons. A nuke requires a huge amount of people and infrastructure to maintain and launch. But a digital weapon? Pfft, copy that shit onto a U…

Why are power stations on the same network with some guy with a USB key?

see https://en.wikipedia.org/wiki/Stuxnet

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#50
post #31

"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers? Could someone share a "What should I do now to protect myself" guide, please? Thanks!

From everything I read last year... as long as someone has write access to a shared network resource, your network is vulnerable.

I read about ways to detect it early with FSRM, but never tried it:

https://chrisreinking.com/stop-cryptolocker-from-hitting-win...

Experts, chime in? What is out there in 2017 (paid or not paid) as a way to protect network drives from ransomware?

Post reply on HN