Live data from Hacker News

Wannacry About Business Models

stratechery.com

11–20 of 33 posts

Re: Wannacry About Business Models

#11

>To put it another way, the alternative is not that the NSA would have Microsoft about EternalBlue years ago, but that the underlying bug would have remained un-patched for even longer than it was (perhaps to be discovered by other entities like China or Russia; the NSA is not the only organization searching for bugs). False dichotomy. The choices are not only: a) NSA pays lots of money to identify exploits and then…

>c) NSA recognizes that only State actors have the money or time for this kind of thing, and should invest the money to detect and report exploits because China and Russia are probably doing so.

China and Russia are reporting vulnerabilities? Got a source for that?

Re: Wannacry About Business Models

#12
post #2

This is a bizarre perspective. Microsoft isn't a victim here. They made decisions that made it difficult or impossible for customers to upgrade their software. They also print money. Is it a pain in the ass to support a bunch of old software? Yes. Should anyone, anywhere have any sympathy for them? No.

It doesn't seem to me that the is trying to paint microsoft as a victim. IT even says they are partially) to blame because of their poor security design.

The article suggested that most software should be delivered as a service, so that it would more directly connect the economic incentives with the bug fixing. Then they pointed out how this would have helped everyone involved in this one specific case.

Re: Wannacry About Business Models

#13

>To put it another way, the alternative is not that the NSA would have Microsoft about EternalBlue years ago, but that the underlying bug would have remained un-patched for even longer than it was (perhaps to be discovered by other entities like China or Russia; the NSA is not the only organization searching for bugs). False dichotomy. The choices are not only: a) NSA pays lots of money to identify exploits and then…

> They didn't.

How do we know? Presumably the NSA has used this exploit before, and we didn't know. Presumably Russia and China use their exploits in similar ways.

It's not about locking someone out of their computer and displaying a giant skull and crossbones to say "I was here". Isn't it more about getting information off computers without people knowing you were there?

That's why this event is so interesting. It's an obvious hazard we can point to from hording vulnerabilities. In contrast, isn't it pretty much impossible to point to some target having their system opened up so enemies can read information? It seems like there's no way for us to know how many NSA horded (or planted) vulnerabilities have been exploited by people they don't want to exploit them.

Re: Wannacry About Business Models

#14
Elephant in the room is that the vast majority of real-world privilege escalation and RCE is through buffer over-reads. Type errors are costing billions in damage.

Hacks like WannaCry don't exist because of the NSA, or consumers failing to update, they exist because programmers use languages that freely compile buffer over-reads in the first place.

The ugly truth is WannaCry and 90% of RCE is the fault of the programming industry for taking zero responsibility for their processes. Programmers choose to use extremely unsafe languages and it's costing the world billions in damage.

The only way we've gotten away with this is the public is largely ignorant to how culpable programmers actually are. They think hackers are demi-gods when it's really just the same damn buffer exploit over and over again.

Re: Wannacry About Business Models

#15
post #11

>To put it another way, the alternative is not that the NSA would have Microsoft about EternalBlue years ago, but that the underlying bug would have remained un-patched for even longer than it was (perhaps to be discovered by other entities like China or Russia; the NSA is not the only organization searching for bugs). False dichotomy. The choices are not only: a) NSA pays lots of money to identify exploits and then…

>c) NSA recognizes that only State actors have the money or time for this kind of thing, and should invest the money to detect and report exploits because China and Russia are probably doing so. China and Russia are reporting vulnerabilities? Got a source for that?

[deleted]

Re: Wannacry About Business Models

#16
post #11

>To put it another way, the alternative is not that the NSA would have Microsoft about EternalBlue years ago, but that the underlying bug would have remained un-patched for even longer than it was (perhaps to be discovered by other entities like China or Russia; the NSA is not the only organization searching for bugs). False dichotomy. The choices are not only: a) NSA pays lots of money to identify exploits and then…

>c) NSA recognizes that only State actors have the money or time for this kind of thing, and should invest the money to detect and report exploits because China and Russia are probably doing so. China and Russia are reporting vulnerabilities? Got a source for that?

I'm pretty sure they meant "because China and Russia are probably identifying exploits", not "because China and Russia are reporting exploits". I.e. it's a defensive measure.

Re: Wannacry About Business Models

#17

Elephant in the room is that the vast majority of real-world privilege escalation and RCE is through buffer over-reads. Type errors are costing billions in damage. Hacks like WannaCry don't exist because of the NSA, or consumers failing to update, they exist because programmers use languages that freely compile buffer over-reads in the first place. The ugly truth is WannaCry and 90% of RCE is the fault of the program…

You make some good points but it is lost in the rant.

Re: Wannacry About Business Models

#18

It is easy to say put everything in the cloud and charge a monthly fee. The reality is there are all sorts of regulatory requirements that prevent this. How are you going to make a SaaS model work with SCADA systems? Many of these systems are networked and running ancient windows versions. SaaS for these systems doesn't work.

The important part isn't moving your data to the cloud, the important part is updating your software and paying a subscription.

Re: Wannacry About Business Models

#19

Elephant in the room is that the vast majority of real-world privilege escalation and RCE is through buffer over-reads. Type errors are costing billions in damage. Hacks like WannaCry don't exist because of the NSA, or consumers failing to update, they exist because programmers use languages that freely compile buffer over-reads in the first place. The ugly truth is WannaCry and 90% of RCE is the fault of the program…

lol

Re: Wannacry About Business Models

#20

Earlier quoted context omitted.

How "old" is sufficient? Forever? Is fixing 0-days sufficient "support", or do you think Microsoft should be forced to actively invest in security updates for end-of-life software?

What do you mean by forced? Logically Microsoft should decide ahead of time how long they are going to support a given version and publish this information so that potential buyers can decide whether its sufficient before buying. They do this, and you can read online how long they intend to support the software you are buying today.

They never seem to get an outburst of positive emotion when they do extend support for a product well beyond its original end-of-life either. Damned if you do, damned if you don't.
Post reply on HN