Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

161–170 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#161
post #18

Earlier quoted context omitted.

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

> Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying. Unfortunately, I think the active hours period cannot be set to more than twelve hours, which is less than the time required for some surgical interventions. I can almost imagine it: OK everyone, ten-minute break while Windows installs its updates, this guy who's been on life support for the last ten hours can wait a lit…

Windows is not a real time OS. Neither is Linux (except for perhaps a limited number of forks/distros).

If someone is going to die if a computer stops working for any reason at all, it should not be running Windows, or Linux, or macOS. It certainly shouldn't be connected to the internet or to any other network.

When we treat computers as nice-to-have mixed-use machines with all the bells and whistles, you need to treat them like nice-to-haves and not need-to-haves.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#162

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

also that it is very unethical for the US government to find some vulnerability in android/windows/whatever and not report it

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#163

Earlier quoted context omitted.

I definitely agree wrt intentional exploits ("backdoors") to be added. To me this news highlights the need for fundamentally safe software. Just like we might have safety laws in the automotive or airline industry.

If the NHS has been significantly crippled by this, and the NSA is partly at fault, could the NHS successfully sue the NSA in the UK? (edit: my logic and phrasing was really bad)

At least in the US, there is limited ability to sue foreign sovereigns in our courts - not sure if that's the case in the UK too. Beyond that, I doubt this is a rabbit hole any government, much less the UK - which has a fairly imperialistic past - wants to go down. Glass houses and all.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#164

Isn't it peculiar that Russia remains the least hit or not even hit at all? It seems like the West was a clear target. Connecting the dots here, it's suffice to say Shadow Brokers serves Russian interests. We are seeing bullet holes from what seem to have been cyber warfare between the former cold war foes.

Time of day, come back in 12 hours and check again.

That said the Russian government is trying to move people to local distributions of Linux, like Astra Linux, but I don't think the uptake is enough to explain low infection rate in Russia.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#165
post #107

Earlier quoted context omitted.

But the hospital management shouldn't be plugging them onto the same network where end-users have access, no?

Surely that's the point of hooking them up to the network, so you can e.g. get the pictures out of your CT scanner on to the doctor's PC?

The doctors' PC can run just fine on an isolated network and doesn't have to be connected to the internet.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#166
post #22
post #11

Earlier quoted context omitted.

If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…

That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…

> Also in this specific case, the people who run IT at NHS are completely incompetent

That's what you get when you defund critical services.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#167

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

Why would the people reaping the rewards of ransomware use encryption that has backdoors if backdoorless encryption already exists.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#168
While I can understand WikiLeaks position, I feel like it was incredibly short sighted and uninformed of them to release the code itself. Unless you believe that they are working with the Russian (and other?) governments to destabilize the west. Personally, I wouldn't be surprised if this was the case.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#169
post #18

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

Not all patches require reboots on many OSs. Some OS's even apply kernel patches live. :) They could have taken a more user friendly approach. I understand they were boxed in a little technically, but they built the box.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#170

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

I'm sure this sort of stuff doesn't help with speedy updates. https://arstechnica.com/tech-policy/2017/03/public-universit...

I saw this at work from the inside of a big telco that did this. They replaced one guy who needed only vague instructions to configure complex software replaced by a team of five who needed detailed step-by-step manuals written out by the vendor and still took twice as long and couldn't cope with any hiccups along the way.

I do not believe outsourcing saves money. It only does so either by cutting quality of service, or in cases where the IT department was heavily mismanaged anyway. Bring in capable management and you don't need to outsource.

Post reply on HN