Earlier quoted context omitted.
Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…
The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…
Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
11–20 of 57 posts
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#12"I cancelled the fines because I think it's important the pubic has 100 per cent confidence in the system" [emphasis added] o_O
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#13Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#14I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#15No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…
Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#16Earlier quoted context omitted.
The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…
Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.
Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#17Earlier quoted context omitted.
Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.
If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.
As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#18"I cancelled the fines because I think it's important the pubic has 100 per cent confidence in the system" [emphasis added] o_O
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#19Earlier quoted context omitted.
Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.
If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.
So are you arguing people going to discover these independently anyway, or not? Pick one and stick with it. You can't have it both ways...
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#20Earlier quoted context omitted.
If the bug were responsibly disclosed to Microsoft, there'd be no proof of concept in the wild, available for anyone to integrate into their ransomware. Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.
It sounds as if your argument is a variant on 'security by obscurity', here hoping that malware creators don't reverse engineer bug fixes (they do). As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?
1. Analyze the update, determining what parts of the system it changes
2. Analyze how the system behaved before the update (i.e. find the vulnerability)
3. Find suitable parameters for the vulnerability to reliably work
4. Build a proof of concept exploit
5. Integrate it into your ransomware
Getting a working proof of concept from a leak saves you 4 out of 5 steps. If you are a financially motivated cyber criminal (and if you are distributing ransomware, you are), that can mean the difference between a waste of your time and a juicy return on investment.