Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

51–60 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#51
post #34

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

Seems like the FDA should certify on software tests and not software versions.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#53
Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt

Live map: https://intel.malwaretech.com/WannaCrypt.html

Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01...

Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#54
post #18

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

It justifies security updates for all operating systems. It does not justify the installation of spyware or changes to the user interface.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#55
post #36

Earlier quoted context omitted.

Why are those devices being connected to an unsecure network? Surely they should have super limited data exchange features?

As is commonly the case, hardware vendors are more concerned with selling you the hardware and probably spend bottom-dollar for their software developers. I can't say that I've worked in such an environment, but my impression is that management at such companies probably see software dev as a cost-centre rather than something to actually spend money on for quality.

But the hospital management shouldn't be plugging them onto the same network where end-users have access, no?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#56

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

Why are those devices being connected to an unsecure network? Surely they should have super limited data exchange features?

It has an ethernet port, someone will plug an ethernet cable into it. The problem is not so much that the users are idiots, the problem is that people get distracted some of the time and make mistakes some of the time.

And yes, surely they should have super limited network features. The important word is "should."

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#57
post #5

I am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.

Just that? No click somehwhere?

Clicks are for phishing and trojans, i.e. human vulnerabilities. This is due to an operating system bug, which is a technical vulnerability.

If you can get the right network packets to an unpatched machine, you can infect that machine.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#58
post #31

"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers? Could someone share a "What should I do now to protect myself" guide, please? Thanks!

For this, run Windows update and install all updates. Additionally, it's smart to disable SMBv1 on all machines.

I disabled SMBv1 on the server. Good enough to protect our network share? Or is there some reason/benefit to disabling SMBv1 on client machines too?

(I ran the simple powershell command on server: https://support.microsoft.com/en-us/help/2696547/how-to-enab...)

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#59
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Your last sentence seems to contradict your first, whereas what you would really prefer is to disarm the police. Sadly I don't think that's so practical, in the same way that it would be impractical for US police to go unarmed given the high incidence of gun ownership in the US. I grew up in a country where police are not normally armed (other than with a small baton or similar personal defense weapon) and much prefe…

I think we should have armed police, along with anyone else that's sane. All for the second amendment. Just in the cyber world, it just feels irresponsible because of the unlimited nature the internet has. Also probably the fact, I read posts that get popular on HN from time to time where the researcher does a responsible disclosure is probably influencing that feeling too.

I guess what's standard in the "tech world", is probably totally different in the intelligence community.

Like companies can't protect themselves, if there's no updates. There's basically no defense. Same reason I'm not a fan of nuclear power. Once you make the waste, it's hard to get rid of.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#60
I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc.

This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

Post reply on HN