Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

11–20 of 304 posts

Re: Lessons from last week’s cyberattack

#11
The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it.

This has similarities in type, if not in horror, to the development and subsequent spread of nuclear weapons. When we lost control of those secrets, it was a BFD [0].

[0] https://en.m.wikipedia.org/wiki/Atomic_spies

Re: Lessons from last week’s cyberattack

#12
No one in the UK seems to be tying this attack to the Conservative Party's desire for backdoors everywhere, which is a shame because it's a nice example for the public of how the government have got this very wrong.

Re: Lessons from last week’s cyberattack

#13
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Re: Lessons from last week’s cyberattack

#14
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility?

And how sure are we that they didn't install security updates out of sheer laziness or hubris?

People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News. I would never allow my my smartphone, let alone computers and servers to run unpatched software. Why is this acceptable for people who have critical systems and data?

Re: Lessons from last week’s cyberattack

#16
post #10

One thing that strikes me with this malware is that it hits pretty much every single country. Don't hackers try to follow the proverbial "don't shit where you eat" proverb? They have nowhere to hide if they are identified now.

Last time I checked, hackers used to follow the "lulz" principle. However some follow the money principle, which can be stolen from anyone.

Re: Lessons from last week’s cyberattack

#17
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

[deleted]

Re: Lessons from last week’s cyberattack

#18
post #13
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Your safest option then is to disable SMB.

Re: Lessons from last week’s cyberattack

#19
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence.

The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents.

It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

Re: Lessons from last week’s cyberattack

#20
Microsoft is feature and sales oriented not quality oriented. Security is an aspect of quality. So if you voluntarily like to put yourself at risk, by all means use their products.

Their product design doesn't emphasize security. For example, remember the extremely convenient AUTORUN.INF feature? That has probably resulted in billions of dollars lost and that number continues to grow every day.

Rendering fonts on the kernel... fantastic idea! What's the next great Microsoft idea? Continue to buy their products and figure it out.

Post reply on HN