Live data from Hacker News

Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

theage.com.au

21–30 of 57 posts

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#21

Earlier quoted context omitted.

The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

Reporting them would trigger normal processes, Microsoft would have time to work on patches during which time bad guys wouldn't be writing WannaCry.

Normally full disclosure happens after about 45 days (I'm not an expert, I don't know exactly) but in special cases the time is extended.

This would probably be considered as a special case as Microsoft exceptionally released updates to unsupported, old versions of Windows and the hole itself was critical.

Please note that WannaCry hit in mid May - not that long time ago.

Shadow Brokers Group public disclosure of stolen tools from NSA happened in April.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#22

Earlier quoted context omitted.

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

Reporting them would trigger normal processes, Microsoft would have time to work on patches during which time bad guys wouldn't be writing WannaCry. Normally full disclosure happens after about 45 days (I'm not an expert, I don't know exactly) but in special cases the time is extended. This would probably be considered as a special case as Microsoft exceptionally released updates to unsupported, old versions of Windo…

[deleted]

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#24
post #6

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

> No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. This is irrelevant in this case. The infection happened months after the security holes had been made public and patches had been released. The same could have happened if the US government had immediately reported the security holes instead of keeping them secret. > Many setups requir…

In this case it wasn't networked, operators infected the cameras using USB sneaker-net.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#25
post #6

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

> No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. This is irrelevant in this case. The infection happened months after the security holes had been made public and patches had been released. The same could have happened if the US government had immediately reported the security holes instead of keeping them secret. > Many setups requir…

It doesn't matter if it's utterly useless if it's legally required.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#26
post #8

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

First mover advantage goes to those with already formed opinions. Or, shoot first, ask questions later.

It would be nice to see HN do some A/B testing. Divide viewers randomly into two bins: those who see posts in FIFO, vs those who see posts LIFO; see if there is correlation between which comments are upvoted.

Also, it may be that contentious comments push a thread comment rate up, more partisan opinions cause article upvoting too, collectively pushing the article up in rankings. Less emotive topics/replies let an article slide down into the bitbucket.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#27
post #8

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

>The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost on the readers here

Not remotely the same thing. The Army hoards guns in case we enter a war and need them. The NSA hoards vulnerabilities so they can spend more time using them on our allies, fellow citizens, anf our enemies.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#28
post #23

And what about having a firewall on the devices? I could understand slow patching, crappy or processes and all. But if the cameras are networked, why is there no firewall on them?

They might not be networked; could have been infected while an operator was collecting photos. But probably networked.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#29
post #14

I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

Iran's nuclear fuel processing systems weren't connected to the internet either...

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#30
post #8

Earlier quoted context omitted.

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

One possible argument: You can't get "mutually assured destruction" from vulnerabilities. With guns you can say if you invade here I'll shoot you, if you were to bomb me, I'd bomb you back. But with vulnerabilities you can't even say you have them as that would help the other party find them. You can't say unleash a cyber attack on me and I'll do the same back in the same way. It seems rather than being both an offen…

The point is not to use them#, the point is that the opposition believes that you have them, they are effective and that you will use them. In that sense the Snowden leaks have been a powerful propaganda win for NSA offensive cyber: everyone knows they have real capability. Likewise we know that the Russians have offensive capability against civilians (DNC, Ukraine power grid, etc), a propaganda machine, and a counter-cyber team (Shadow Brokers). What we don't know is how good the Russian/* military cyber capability is, and how strong the defence would be.

Personally I think most defences are rubbish, it is MAD, and the financial implications would be dire.

It reminds me of a classic line from Spies Like Us: "A weapon unused is a useless weapon."

#Except against dissidents.

Post reply on HN