Earlier quoted context omitted.
Just that? No click somehwhere?
If someone connects to a network which has been infected and they've not applied the appropriate patch (MS17-010) it looks like they're in trouble if they're running Windows and don't have a firewall blocking incoming connections. So first person in a network has to have fallen for the phishing attack, but once it's in the network it can spread via the ETERNALBLUE exploit.
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
81–90 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#82I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#83> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…
Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.
https://docs.microsoft.com/en-us/windows/deployment/update/w...
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#84Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#85Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#86Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#87Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#88Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#89Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#90Earlier quoted context omitted.
If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…
That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…
Again, the problem is that rolling out patches quickly often leads to unplanned problems that can't be easily detected or rolled back from. That can cause problems worse than leaving security issues unpatched.