Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

141–150 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#141
post #18

Earlier quoted context omitted.

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

So your workstation is next to a bed and is attached to a machine which feeds a drip to keep a little girl alive and it gets your untested patch or whole OS upgrade and the dosage is increased or the driver stops and the patient dies. Only non-critical machines can just automatically apply software patches from Redmond (or anybody). This is not laziness or incompetence - only a few weeks ago military grade exploits f…

Machines like that, which cannot shoulder the risk of applying updates to a network-connected general purpose OS designed to run third party (potentially malicious) code on a non-deterministic non-realtime system... probably should not be using such a system. Patching is risky, not patching is risky.

They should have formally validated software running on formally validated deterministic realtime hardware, running in non-networked environments (But with telemetry and remote control from networked computers if that's convenient) we just don't bother because it's cheaper and legal to get away with selling hacky nonsense.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#142
post #108

Earlier quoted context omitted.

We are seeing new requests from existing bots, the historical data is not shown on this map.

Gotcha. So yeah, we're seeing it wake up. The first little increase (up to 600) was about the time the article was published.

Where are you seeing this? This isn't historical data.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#143

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

I don't understand. What exactly do the live map points represents and where does the data come from?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#145
post #78

Earlier quoted context omitted.

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…

The problem is that the technology stack required by modern equipment is too large to be satisfied by anything but a general-purpose OS. Good luck trying to get a mathematically proven OS.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#146

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

I don't think you can completely separate the issue from other gov't actions. When the NSA or other gov't agencies come knocking on the door requiring a backdoor or other system security compromises, I would argue that those actions become a broad discouragement for private industry invest in security beyond a certain point.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#147

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

> if encryption had a backdoor

This is the flaw in the logic. "Encryption" can't have a backdoor any more than math can have a back door.

Specific types of encryption can. But there's nothing to stop a malicious user from using a non-backdoored encryption algorithm or inventing their own.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#148

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

[deleted]

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#149
post #108

Earlier quoted context omitted.

Gotcha. So yeah, we're seeing it wake up. The first little increase (up to 600) was about the time the article was published.

Where are you seeing this? This isn't historical data.

Here's a page with more info

https://intel.malwaretech.com/botnet/wcrypt

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#150
post #118

Earlier quoted context omitted.

> ... it's not the NSA's fault that software has faults. But every time they ask for there to be legally mandated backdoors - they need to be reminded of these incidents. The NSA actively wants there to be "faults" like these. They just only want the "good" guys to have access to them.

I definitely agree wrt intentional exploits ("backdoors") to be added. To me this news highlights the need for fundamentally safe software. Just like we might have safety laws in the automotive or airline industry.

If the NHS has been significantly crippled by this, and the NSA is partly at fault, could the NHS successfully sue the NSA in the UK?

(edit: my logic and phrasing was really bad)

Post reply on HN