Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

11–20 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#11
post #8

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

If the property management company demanded that I use Insecure Brand locks on my front door, I'd have an issue with that. Of course that wouldn't excuse the robbers, but continuing to use Insecure Brand locks wouldn't be advisable. I'd also take exception if IB Locks or the property management company marketed themselves as a security oriented company.

> continuing to use Insecure Brand locks wouldn't be advisable.

Agreed. Microsoft should clarify how this happened and what measurements will take to prevent this incident from happening again. Still, the problem is with robbery and it should be condemned. Why changing the subject to Microsoft? I don't think whataboutism is the valid argument here.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#12
post #9

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

You can't sell doors unless there's clear low enforcement that prohibited criminal activities. You need an environment to operate.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#13
post #9

Earlier quoted context omitted.

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

You can't sell doors unless there's clear low enforcement that prohibited criminal activities. You need an environment to operate.

https://en.wikipedia.org/wiki/Portcullis

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#14
post #4

Earlier quoted context omitted.

The issue is not that a random guy on the internet hacks the software, but a _state_ actor.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.

> Don't use vulnerable software

Is there any widely used software that doesn't have any vulnerabilities?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#15
post #4

Earlier quoted context omitted.

The issue is not that a random guy on the internet hacks the software, but a _state_ actor.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.

> The solution is the same in both cases. Don't use vulnerable software.

So, basically, don't use software. Actually, given the horrific state of modern software, I can get behind that.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#16
post #9

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

Your analogy sucks - MS would would be more akin to a company that sells houses. When are developers responsible for housing secuity? if you're going to criticize an analogy and propose another it ought to be better rather a garbage one.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#17

Earlier quoted context omitted.

You can't sell doors unless there's clear low enforcement that prohibited criminal activities. You need an environment to operate.

https://en.wikipedia.org/wiki/Portcullis

> Portcullises fortified the entrances to many medieval castles, securely closing off the castle during time of attack or siege.

Is the US in a state of war with China? Do we need medieval tactics to deal with cyber security? Why insisting on blaming the victim.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#18
post #8

Earlier quoted context omitted.

If the property management company demanded that I use Insecure Brand locks on my front door, I'd have an issue with that. Of course that wouldn't excuse the robbers, but continuing to use Insecure Brand locks wouldn't be advisable. I'd also take exception if IB Locks or the property management company marketed themselves as a security oriented company.

> continuing to use Insecure Brand locks wouldn't be advisable. Agreed. Microsoft should clarify how this happened and what measurements will take to prevent this incident from happening again. Still, the problem is with robbery and it should be condemned. Why changing the subject to Microsoft? I don't think whataboutism is the valid argument here.

It is not whataboutism. It is about 3 decades of seemingly intentional inability to deliver secure product on the mildly evil calculation that the subscriber will need 'security updates' and 'support'.

There is a good argument to be made that Windows is a big target, but they should at least try not making it so easy.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#19
post #4

Earlier quoted context omitted.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.

> The solution is the same in both cases. Don't use vulnerable software. So, basically, don't use software. Actually, given the horrific state of modern software, I can get behind that.

You digress, but you're onto something here. I suspect I'm not the only one who cringes at bloated packages and sometimes rolls my own alternative.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#20
post #9

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

>A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility.

Actually most locks are susceptible to being picked (ie. a known exploit), so what you're describing is already the case, minus the lawsuits.

Post reply on HN