Earlier quoted context omitted.
This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…
Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
221–230 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#222Earlier quoted context omitted.
That's my point, as I type this on fully patched Win 10 Pro. Certainly Windows has its issues, but it's biggest 'flaw' when it comes to malware isn't that it's closed-source, but that it's ubiquitous and therefore a highly attractive target.
Linux is ubiquitous in the data center. We are not a low-value target. Also, corporations with cloud-based infrastructure are more likely to pay large ransoms for their data, especially if it is the backup/archive system that is attacked.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#223Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#224Earlier quoted context omitted.
all software is vulnerable This is false, and spreads FUD. It does a great disservice to those who do meticulously maintain their systems, to those who sacrifice convenience and beauty for stability and security, to those who take the time to scrutinize other people's work. It is possible to build and deploy secure software. Linux dominates the datacenter; we are a high value target, and have been for quite some time…
>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#225Earlier quoted context omitted.
It isn't more eloquent, because it's wrong. Wouldn't saying: "The new mafia." or "The new shake-down" be more accurate? Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The…
Ah sorry, I got it wrong twice. But you got me thinking again: because this ransomware is targeting the infrastructure itself (national healthcare service) isn't this playing with fear too? If I was in hospital, or my friends/family, I would be acutely paranoid that medical devices will go wrong, medicine administration will go wrong, the A&E will go bonkers et cetra. I've worked in healthcare before, and this kind o…
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#226Earlier quoted context omitted.
I don't understand. What exactly do the live map points represents and where does the data come from?
https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...
This would just discover supernodes though right? Or any node at some point broadcasts as a supernode?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#227Earlier quoted context omitted.
Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…
The problem is that the technology stack required by modern equipment is too large to be satisfied by anything but a general-purpose OS. Good luck trying to get a mathematically proven OS.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#228Cyber attacks use patched exploit to attack systems running out of date software, even in large enterprises handling sensitive data? I give a pass to individuals (bandwidth for updates can be expensive, regular users don't know about patch Tuesday etc), but enterprise scale deployment should have IT for this, and IT should have been well aware of this kind of thing happening.
https://www.cs.columbia.edu/~smb/blog/2017-05/2017-05-12.htm...
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#229Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#230Earlier quoted context omitted.
Surely that's the point of hooking them up to the network, so you can e.g. get the pictures out of your CT scanner on to the doctor's PC?
The doctors' PC can run just fine on an isolated network and doesn't have to be connected to the internet.