Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

71–80 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#71

Maybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software. Here is the BBC news update about the NHS Cyber attack: "NHS trusts 'ran outdated software' Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated…

A simple patching policy would have fixed this

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#72

Earlier quoted context omitted.

From everything I read last year... as long as someone has write access to a shared network resource, your network is vulnerable. I read about ways to detect it early with FSRM, but never tried it: https://chrisreinking.com/stop-cryptolocker-from-hitting-win... Experts, chime in? What is out there in 2017 (paid or not paid) as a way to protect network drives from ransomware?

Proper backup system?

Well yes that's obvious, I meant more along the lines of:

Are there any ways to detect and stop it from happening in 2017? Third party software? New group policies from MS?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#75

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#76
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Right, I'm sure the NSA doesn't currently take any effort to secure their trove of 0-days. It's not like they're valuable assets or anything. Edit: My point is that thinking that requiring the NSA to keep them "as secure as possible" as though that would eliminate risk is just silly. There will always be risk of breach or insider theft, as well as the requirement that the exploits actually be put to use outside some…

Wasn't the story behind the NSA leak that it explicitly wasn't well protected, and was passed relatively freely between contractors and without much in the way of oversight?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#77
post #22
post #11

Earlier quoted context omitted.

If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…

That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…

Easy for your to say. I have been unable to do my job for a several days because some update broke a service I was using. Sure the service was badly written, but we didn't know that until the patch was applied.

The phone company used to have (they still might, I'm not in the business anymore) large labs that were small replications of their network. I've been in meetings where the goal was to decide if we should try to get our latest release through their process - if yes and we were successful they would pay big for the latest features, but if yes and it failed [I can't remember, I think we had to pay them for test time, but the contract was complex]. A lot of time was spent looking at every known bug to decide if it was important.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#78
post #34

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anything but the certified software load in accessing it the vendor puts all blame on us.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#79

Earlier quoted context omitted.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

He has backups of his data. I personally use linux and my github repo is here[1] where i have a bunch of encryption related projects(zuluCrypt,SiriKali and lxqt_wallet). The last windows computer i used was windows xp. I dont want to move him to linux because i am not always around and he can ask other people for help when he is on windows. [1] https://github.com/mhogomchungu

Thank God for backups! And thank you for making sure people make backups.

My mother is in a similar situation. She is an elementary school teacher, and has little time for unrelated endeavors like this. What time she does have, is spent in the garden, as it should be.

Nevertheless, we are now seeing that the time-cost of closed source software, is greater than that of open-source software. My solution has been to prepare a KDE based distro for her, to work with her, side by side, whenever she needs to learn new tools. It is a good bonding experience, when both people can maintain a positive attitude about it.

The solution to the problem of malware, is education.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#80

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

well I suspect that such devices should not be connected I was on dialysis at a clinic from one of the effected trusts and boy am I glad that my hemo dialysis machine was not connected to the network.

sobering.
Post reply on HN