I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?
Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.
Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
31–40 of 57 posts
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#32No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…
Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…
The key difference is that we can't make the enemies guns ineffective by accumulating even more guns. The NSA could weaken the enemy's vulnerability stockpile by aggressively chasing and releasing vulnerability information to vendors.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#33Earlier quoted context omitted.
> No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. This is irrelevant in this case. The infection happened months after the security holes had been made public and patches had been released. The same could have happened if the US government had immediately reported the security holes instead of keeping them secret. > Many setups requir…
In this case it wasn't networked, operators infected the cameras using USB sneaker-net.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#34Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display?
Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#35No mention that this security hole has been kept secret by US government and leaked with devastating consequences around the world. You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole. Many setups require certification which is void after modifications which may include syste…
Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…
Nope! We know it's more complicated than that. But we think the NSA strikes the wrong balance between offense and defense. If you want to understand where people are coming from a little more you could start with some of Bruce Schneier's articles:
https://www.schneier.com/blog/archives/2016/08/the_nsa_is_ho...
https://www.schneier.com/blog/archives/2017/06/wannacry_and_...
... where, for example, Schneier proposes that NSA should keep vulnerabilities for no more than six months, based on how far ahead of adversaries it doesn't appear to be.
The general point Schneier tends to make is: we are a huge fat defensive target with limited offensive targets. Vulnerabilities hurt you in proportion to how much infrastructure you run; we run a lot. Sitting on a vuln so you can use it a dozen times, while powering your society with billions of machines that have the same vuln, is a bad tradeoff.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#36Earlier quoted context omitted.
In this case it wasn't networked, operators infected the cameras using USB sneaker-net.
I don't see any mention of USB in the article. Can you link a source?
> The department of justice said Victoria’s infection was not the result of a targeted attack, but was caused by a contractor mistakenly connecting infected hardware to cameras.
Some sources are calling this a USB stick, the Guardian is being a bit more cautious.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#37Earlier quoted context omitted.
Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…
The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#38I wonder if it has infected any critical military infrastructure at US? and any real way to know about it?
Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#39Why do so many commercial embedded devices use Window OS, and generally old versions like NT or XP? Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display? Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.
Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
#40Why do so many commercial embedded devices use Window OS, and generally old versions like NT or XP? Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display? Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.