Live data from Hacker News

Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

theage.com.au

31–40 of 57 posts

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#31
post #14

I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

But it is collected to an internet, which might be just as good.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#32
post #8

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

> The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too.

The key difference is that we can't make the enemies guns ineffective by accumulating even more guns. The NSA could weaken the enemy's vulnerability stockpile by aggressively chasing and releasing vulnerability information to vendors.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#33
post #24
post #6

Earlier quoted context omitted.

> No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. This is irrelevant in this case. The infection happened months after the security holes had been made public and patches had been released. The same could have happened if the US government had immediately reported the security holes instead of keeping them secret. > Many setups requir…

In this case it wasn't networked, operators infected the cameras using USB sneaker-net.

I don't see any mention of USB in the article. Can you link a source?

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#34
Why do so many commercial embedded devices use Window OS, and generally old versions like NT or XP?

Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display?

Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#35
post #8

No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

> Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities?

Nope! We know it's more complicated than that. But we think the NSA strikes the wrong balance between offense and defense. If you want to understand where people are coming from a little more you could start with some of Bruce Schneier's articles:

https://www.schneier.com/blog/archives/2016/08/the_nsa_is_ho...

https://www.schneier.com/blog/archives/2017/06/wannacry_and_...

... where, for example, Schneier proposes that NSA should keep vulnerabilities for no more than six months, based on how far ahead of adversaries it doesn't appear to be.

The general point Schneier tends to make is: we are a huge fat defensive target with limited offensive targets. Vulnerabilities hurt you in proportion to how much infrastructure you run; we run a lot. Sitting on a vuln so you can use it a dozen times, while powering your society with billions of machines that have the same vuln, is a bad tradeoff.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#36
post #33
post #24

Earlier quoted context omitted.

In this case it wasn't networked, operators infected the cameras using USB sneaker-net.

I don't see any mention of USB in the article. Can you link a source?

https://www.theguardian.com/australia-news/2017/jun/22/traff...

> The department of justice said Victoria’s infection was not the result of a targeted attack, but was caused by a contractor mistakenly connecting infected hardware to cameras.

Some sources are calling this a USB stick, the Guardian is being a bit more cautious.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#37
post #8

Earlier quoted context omitted.

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…

... and sometimes it makes new guns in other places.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#38
post #14

I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

[serious] wasn't the Internet basically invented to support critical military infrastructure? Or do their have their own parallel thing?

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#39
post #34

Why do so many commercial embedded devices use Window OS, and generally old versions like NT or XP? Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display? Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.

I have extensive experience in the embedded field and the answer is that most programmers and technicians know Windows and don't know Linux. Then of course there might be a few benefits to Windows in specific cases, but it's mostly the case of simply being familiar with it.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#40
post #34

Why do so many commercial embedded devices use Window OS, and generally old versions like NT or XP? Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display? Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.

I think a lot of it is programmer expertise. There's a lot of people out there who only use Windows and have never used a Unix and wouldn't know where to begin programming for it. Especially when you get into lowest-bidder and outsourcing situations, where the technology used isn't even a consideration when planning the project.
Post reply on HN