Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

221–230 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#221
post #78

Earlier quoted context omitted.

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…

Maybe you really think it's just as simple as mandating exactly what you wrote here. But I'd imagine you'd agree that even doing this would have real and significant costs, which means tradeoffs are going to have to be made, e.g. some people won't receive medical care they otherwise would.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#222

Earlier quoted context omitted.

That's my point, as I type this on fully patched Win 10 Pro. Certainly Windows has its issues, but it's biggest 'flaw' when it comes to malware isn't that it's closed-source, but that it's ubiquitous and therefore a highly attractive target.

Linux is ubiquitous in the data center. We are not a low-value target. Also, corporations with cloud-based infrastructure are more likely to pay large ransoms for their data, especially if it is the backup/archive system that is attacked.

Data centers are dwarfed in size by the consumer and business markets, while also being much less vulnerable due to their more specialised nature and therefore ease of update. Case in point: there are plenty of windows data centres out there, but its not likely any of them were effected by this incident.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#224

Earlier quoted context omitted.

all software is vulnerable This is false, and spreads FUD. It does a great disservice to those who do meticulously maintain their systems, to those who sacrifice convenience and beauty for stability and security, to those who take the time to scrutinize other people's work. It is possible to build and deploy secure software. Linux dominates the datacenter; we are a high value target, and have been for quite some time…

>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?

I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#225
post #190

Earlier quoted context omitted.

It isn't more eloquent, because it's wrong. Wouldn't saying: "The new mafia." or "The new shake-down" be more accurate? Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The…

Ah sorry, I got it wrong twice. But you got me thinking again: because this ransomware is targeting the infrastructure itself (national healthcare service) isn't this playing with fear too? If I was in hospital, or my friends/family, I would be acutely paranoid that medical devices will go wrong, medicine administration will go wrong, the A&E will go bonkers et cetra. I've worked in healthcare before, and this kind o…

Hmmm, that's a fair point. And now I'm wondering what my primary care last security report turned up. There's also some things that I still haven't told me doctors-- because I really don't believe in their ability to not disclose it somehow. And I want to remind everyone that you will pay for computer security no matter what--- you can either pay for it upfront, or you can pay ransoms in the future.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#226

Earlier quoted context omitted.

I don't understand. What exactly do the live map points represents and where does the data come from?

https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...

>To ensure the entire network is discovered, we should start the crawler off with multiple supernode IPs and store all IPs found into a database, then each time we restart the crawler we seed it with the list of IPs found during the previous crawler; repeating this process for a couple of hours ensure all online nodes are found.

This would just discover supernodes though right? Or any node at some point broadcasts as a supernode?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#227
post #145

Earlier quoted context omitted.

Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…

The problem is that the technology stack required by modern equipment is too large to be satisfied by anything but a general-purpose OS. Good luck trying to get a mathematically proven OS.

[deleted]

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#228
post #13

Cyber attacks use patched exploit to attack systems running out of date software, even in large enterprises handling sensitive data? I give a pass to individuals (bandwidth for updates can be expensive, regular users don't know about patch Tuesday etc), but enterprise scale deployment should have IT for this, and IT should have been well aware of this kind of thing happening.

Strangely enough, people like Matt Blaze are out beating the "don't blame the victim" drum by stating the exact opposite, giving a pass to large enterprises under the "patching is hard" mantra:

https://www.cs.columbia.edu/~smb/blog/2017-05/2017-05-12.htm...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#230
post #107

Earlier quoted context omitted.

Surely that's the point of hooking them up to the network, so you can e.g. get the pictures out of your CT scanner on to the doctor's PC?

The doctors' PC can run just fine on an isolated network and doesn't have to be connected to the internet.

That's the idea behind N3, the NHS's internal network. The idea of a hard shell with a soft centre. With N3 as large as it is, the idea breaks down. Security in depth is required, secure at every level. The hard shell idea is outdated, and N3 is scheduled to be turned off in 2019.
Post reply on HN