Live data from Hacker News

Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

theage.com.au

11–20 of 57 posts

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#11
post #8

Earlier quoted context omitted.

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#14

I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#15
post #8

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

One possible argument: You can't get "mutually assured destruction" from vulnerabilities. With guns you can say if you invade here I'll shoot you, if you were to bomb me, I'd bomb you back. But with vulnerabilities you can't even say you have them as that would help the other party find them. You can't say unleash a cyber attack on me and I'll do the same back in the same way. It seems rather than being both an offence AND defence like guns, they are an offence at the expense of your defence.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#16

Earlier quoted context omitted.

The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware.

Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#17
post #16

Earlier quoted context omitted.

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.

It sounds as if your argument is a variant on 'security by obscurity', here hoping that malware creators don't reverse engineer bug fixes (they do).

As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#18

"I cancelled the fines because I think it's important the pubic has 100 per cent confidence in the system" [emphasis added] o_O

The Age is giving the Graudian a run for its money. There is almost nobody left working at Fairfax outside of management that was born last century.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#19
post #16

Earlier quoted context omitted.

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.

Wait, so when it's your (side's) turn, you(r side) start(s) claiming "vulnerabilities can be independently discovered", but when it's my (side's) turn, your argument is "but there'd be no proof of concept"?

So are you arguing people going to discover these independently anyway, or not? Pick one and stick with it. You can't have it both ways...

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#20
post #17
post #16

Earlier quoted context omitted.

If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.

It sounds as if your argument is a variant on 'security by obscurity', here hoping that malware creators don't reverse engineer bug fixes (they do). As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?

Sometimes, a bit of obscurity will improve security. To get something like WannaCry to work from a security patch, you'd have to do the following:

  1. Analyze the update, determining what parts of the system it changes
  2. Analyze how the system behaved before the update (i.e. find the vulnerability)
  3. Find suitable parameters for the vulnerability to reliably work
  4. Build a proof of concept exploit
  5. Integrate it into your ransomware
Getting a working proof of concept from a leak saves you 4 out of 5 steps. If you are a financially motivated cyber criminal (and if you are distributing ransomware, you are), that can mean the difference between a waste of your time and a juicy return on investment.
Post reply on HN