Live data from Hacker News

Oakland declares state of emergency due to ransomware attack

nbcbayarea.com

51–60 of 86 posts

Re: Oakland declares state of emergency due to ransomware attack

#51

imho we have to look at what limited set of tools and functionality we really use. The days where we didn't know what computers were used for are long gone and the justification for doing everything in software along with it. You want to exchange strings of text with video and images. Not much more than morse code offered. Direction of dataflow can be easily enforced in hardware. The backup drive takes input that you…

> A completely finished os can be stored on a read only device.

ChromeOS has entered the chat

Seriously, if it's good enough for school children, it surely is good enough for government. I love my Chromebook, and while I cannot yet do my day-job on it, I did interview at a crypto company that did do their day jobs on it, so I believe it's possible

Re: Oakland declares state of emergency due to ransomware attack

#52

It's been quite a few years since I did this kind of stuff for a living, so this may be an antiquated notion... "In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for an…

The big change is that many places now send data to an offsite location (or cloud!) through a network instead of physically moving tapes, and the attacker can often use the same network connection to destroy backups.

Re: Oakland declares state of emergency due to ransomware attack

#53
post #50

Earlier quoted context omitted.

It's generally professional services that set up these deployments at scale. MS's PS team is extremely competent and does push best practices in my experience. The issue is organizations that cheap out and decide to have an IT Service Desk guy manage everything from deployment to network architecture to security - these are extremely hard problems that require a large team of SME, not a single guy doing the best he c…

The lesson here is that the City of Oakland and similar organizations shouldn't be deploying such systems at all. They should lay off most of their IT staff and outsource their entire IT infrastructure to one of the large vendors who has the resources and technical competence to deal with advanced persistent security threats. Blaming the OS vendor won't accomplish anything.

IMHO the core issue is a lack of resources - they can't afford an outsourced vendor that will do stuff properly just as much as they can't afford to do the same thing in-house. There's barely a budget to get hardware, and definitely not to deploy it properly; there's barely a budget to replace what dies of old age, and definitely not to do proper maintenance and updates.

Re: Oakland declares state of emergency due to ransomware attack

#54
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

If its really important. Airgap. Or VM-Wrapped with restore points. I completely understand that somebody does not want to upgrade into the warp-abyss-abomination of modern windows, especially if huge expenses software was written once, that needs backwards compatability or contains sensitive data. You can not use windows if you work for anything with sensitive data. In todays world the legacy is the good stuff. Just…

It doesn't look like Oakland would have the IT people, time and skills to deploy and maintain a VM-wrapped infrastructure - which has all the same issues with needing to keep it up to date; e.g. I know people for whom this VMWare ESXi attack https://www.crn.com/news/security/vmware-esxi-ransomware-att... managed to ransom-encrypt both their main virtualization environment and also the backup one.

Re: Oakland declares state of emergency due to ransomware attack

#55

It's been quite a few years since I did this kind of stuff for a living, so this may be an antiquated notion... "In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for an…

The big change is that many places now send data to an offsite location (or cloud!) through a network instead of physically moving tapes, and the attacker can often use the same network connection to destroy backups.

[deleted]

Re: Oakland declares state of emergency due to ransomware attack

#56
post #26
post #15

Earlier quoted context omitted.

Prevention is orders of magnitude less expensive than dealing with the fallout from an eventually inevitable atack. The tragedy is that in the absence of attacks, local governments don't always allocate the necessary funds to employing competent admins who take a proactive approach to security. Even more importantly, these admins need to be given authority to block attempts at lowering defenses in the name of conveni…

The problem is that lowering security expenditure is a good gamble for managers/executives: Chances are it will take a while before things blow-up. In the meantime, you get the credit for "saving money", you will get promoted, perhaps move to another company, and the bomb will explode in the hands of your successor.

Here the solution is personal liability, including CEO and board of directors.

Re: Oakland declares state of emergency due to ransomware attack

#57
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

If its really important. Airgap. Or VM-Wrapped with restore points. I completely understand that somebody does not want to upgrade into the warp-abyss-abomination of modern windows, especially if huge expenses software was written once, that needs backwards compatability or contains sensitive data. You can not use windows if you work for anything with sensitive data. In todays world the legacy is the good stuff. Just…

I witnessed a ransomware attack where somebody in operations had a SMB share on their desktop to the backend storage for the VMWare ESXi cluster. So the ransomware was able to encrypt many of the vdisks.

Re: Oakland declares state of emergency due to ransomware attack

#58

It's been quite a few years since I did this kind of stuff for a living, so this may be an antiquated notion... "In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for an…

The big change is that many places now send data to an offsite location (or cloud!) through a network instead of physically moving tapes, and the attacker can often use the same network connection to destroy backups.

I think most backup providers (e.g. rsync.net) allow and encourage read-only backups.

The bigger issue is that nowadays organizations have lots of interdependent systems, and if you seize the data of one, you basically cripple the entire organization. So for each system you need to institutionally require both backups and backup testing procedures, which is easier said than done.

Re: Oakland declares state of emergency due to ransomware attack

#59
post #50

Earlier quoted context omitted.

It's generally professional services that set up these deployments at scale. MS's PS team is extremely competent and does push best practices in my experience. The issue is organizations that cheap out and decide to have an IT Service Desk guy manage everything from deployment to network architecture to security - these are extremely hard problems that require a large team of SME, not a single guy doing the best he c…

The lesson here is that the City of Oakland and similar organizations shouldn't be deploying such systems at all. They should lay off most of their IT staff and outsource their entire IT infrastructure to one of the large vendors who has the resources and technical competence to deal with advanced persistent security threats. Blaming the OS vendor won't accomplish anything.

Microsoft is an MSSP as well. And they are one of the multiple vendors the City of Oakland uses. But vendors can only do so much for organizations like Oakland as the final decision and implementation ends up getting stuck in red tape and bureaucratic hell between multiple disjointed teams.

Re: Oakland declares state of emergency due to ransomware attack

#60
post #41

In the modern threat environment it's no longer viable for small and medium enterprises to maintain their own IT infrastructure. This includes city governments. They should outsource infrastructure to one of the major cloud vendors with the scale and technical competence necessary to counter advanced persistent threats. It's a shame that we all have to pay this "tax" and give more control to a few big tech companies,…

They already have for at least 15 years.
Post reply on HN