I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
101–110 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#102Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#103You can keep an eye on their bitcoin wallet (or at least one of them): https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#104I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#105> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…
Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.
Only non-critical machines can just automatically apply software patches from Redmond (or anybody). This is not laziness or incompetence - only a few weeks ago military grade exploits from the USG were leaked onto the internet and are currently being re-purposed for non-spying applications. Does anyone think any organisation is prepared for this? Chinese chatter indicates that ms17-010smb doesn't even fix all cases! Many organisations will have been saved by infra guys making sure ms17-010smb was rushed through and that McAfee sigs were updated 'just because'.
edit: fixed CVE (Eternalblue)
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#106Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#107Earlier quoted context omitted.
As is commonly the case, hardware vendors are more concerned with selling you the hardware and probably spend bottom-dollar for their software developers. I can't say that I've worked in such an environment, but my impression is that management at such companies probably see software dev as a cost-centre rather than something to actually spend money on for quality.
But the hospital management shouldn't be plugging them onto the same network where end-users have access, no?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#108Earlier quoted context omitted.
Are we watching this thing wake up right now?
We are seeing new requests from existing bots, the historical data is not shown on this map.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#109Earlier quoted context omitted.
If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…
That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#110Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.