Live data from Hacker News

Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

theage.com.au

51–57 of 57 posts

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#51
post #8

Earlier quoted context omitted.

Why is a comment like this always at the top of one of these HN threads? Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? I find it hard to believe that people here would collectively be that naive and simple-minded in their thinking. The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. This is too obvious a point to be lost…

Another analogy is, NSA has find vaccine for Zika virus, but they haven't released it to public because as if now only they have weaponized it. If some rogue group manages to weaponize Zika, they release the vaccine. Though vaccinating whole world will take few years, US can do so in a matter of months. May cost millions of people in poor countries and 1000s in first world, that's just cost of business. Unfortunately…

Bad analogy if you consider reality of Zika vaccine:

"Army is planning to grant exclusive rights to this potentially groundbreaking medicine–along with as much as $173 million in funding from the Department of Health and Human Services—to the French pharmaceutical corporation Sanofi Pasteur. "

https://www.thenation.com/article/the-government-created-thi...

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#52
post #20
post #17

Earlier quoted context omitted.

It sounds as if your argument is a variant on 'security by obscurity', here hoping that malware creators don't reverse engineer bug fixes (they do). As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?

Sometimes, a bit of obscurity will improve security. To get something like WannaCry to work from a security patch, you'd have to do the following: 1. Analyze the update, determining what parts of the system it changes 2. Analyze how the system behaved before the update (i.e. find the vulnerability) 3. Find suitable parameters for the vulnerability to reliably work 4. Build a proof of concept exploit 5. Integrate it i…

Slippery slope though, tools like Metasploit are extremely important for security auditing and are generally regarded as a good thing for that reason, but your logic would apply to it as well.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#53

Earlier quoted context omitted.

Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.

Reporting them would trigger normal processes, Microsoft would have time to work on patches during which time bad guys wouldn't be writing WannaCry. Normally full disclosure happens after about 45 days (I'm not an expert, I don't know exactly) but in special cases the time is extended. This would probably be considered as a special case as Microsoft exceptionally released updates to unsupported, old versions of Windo…

Microsoft pushed out fixes in March, so WannaCry occurred two months later.

There would have been even less time if this was indeed a security researcher using a 30-45 day time period.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#54
post #38
post #14

Earlier quoted context omitted.

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

[serious] wasn't the Internet basically invented to support critical military infrastructure? Or do their have their own parallel thing?

Not "parallel" but a few networks.

NIPR - Unclassified DoD internet plus powerful defensive capabilities when traffic goes between the intranet and public internet.

SIPR - Private "internet" for military and defense contractors and such to allow for handling SECRET and below. Dedicated circuits.

JWICS - Like SIPR but for TS and SCI channels.

Then other dedicated networks for international partnerships which run on dedicated circuits and using sats.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#55
post #48

Earlier quoted context omitted.

> The NSA hoards vulnerabilities for the same reason the military has guns. Because other countries have guns too. The key difference is that we can't make the enemies guns ineffective by accumulating even more guns. The NSA could weaken the enemy's vulnerability stockpile by aggressively chasing and releasing vulnerability information to vendors.

Sure, but as you well know, two distinct sets of actors working to find vulnerabilities are going to find some non-overlapping sets of vulnerabilities. We can't know which ones they've found. In fact, one good way to know what the enemy has is to have some of our own, so we can do some espionage. Which, of course, requires us to possess unpatched vulnerabilities.

Vulnerabilities go to the highest bidder. With our military budget being what it is, I'm pretty sure we could outspend anybody out there. If you start offering millions of dollars for serious vulnerabilities, people will turn them in, including employees of foreign intelligence agencies.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#56
post #38
post #14

Earlier quoted context omitted.

Critical military infrastructure isn't connected to the Internet, so it's unlikely as part of this regular epidemic.

[serious] wasn't the Internet basically invented to support critical military infrastructure? Or do their have their own parallel thing?

The technology of the internet was definitely invented to support it (i.e resilient networks). The public internet that we use is separate though.

Re: Victoria Police cancel hundreds of speeding fines after WannaCry virus attack

#57
post #20

Earlier quoted context omitted.

Sometimes, a bit of obscurity will improve security. To get something like WannaCry to work from a security patch, you'd have to do the following: 1. Analyze the update, determining what parts of the system it changes 2. Analyze how the system behaved before the update (i.e. find the vulnerability) 3. Find suitable parameters for the vulnerability to reliably work 4. Build a proof of concept exploit 5. Integrate it i…

Slippery slope though, tools like Metasploit are extremely important for security auditing and are generally regarded as a good thing for that reason, but your logic would apply to it as well.

Metasploit is a bit like a knife. You can use it to chop vegetables or stab people, and depending on who wields it, and in what circumstances, either of the outcomes is more likely.

I'm not arguing against the development on Metasploit though, and neither do I want to make an argument against vulnerability research. Every time Tavis Ormandy takes a shower, an AV vendor runs for cover; and on Christmas each year, Karsten Nohl cancels the vacations for some legacy system developers. That's a good thing, because those guys report their findings. They push vendors to fix the vulnerabilities, and they improve the security of systems we all depend on, every day.

Governments should do the same thing. I am all in favor of investing more in vulnerability research, but we need a process of disclosure. Stockpiling vulnerabilities puts everyone at risk, with little benefits.

Circling back to Metasploit: Yes, it makes work easier for cybercriminals. But even just the knowledge that a vulnerability will be available as a module quickly may be enough to make some vendors think twice about not reacting to a disclosure email, whether it's from Project Zero, independent researchers, or (hopefully more often) government CERTs.

Post reply on HN