Live data from Hacker News

Oakland declares state of emergency due to ransomware attack

nbcbayarea.com

11–20 of 86 posts

Re: Oakland declares state of emergency due to ransomware attack

#11
post #5

I don’t get why any user has the ability to cause so much damage. Sure they can lock their own files out and need to restore from backup, but how can that knock out other departments, let alone things like email.

When ransomware attacks began, it was more typical to see the blast radius centered around a single user who did something stupid, like run an exe or enable macros.

But that’s not how it’s done on these large enterprise networks. Ransomware gangs will still use single user entry points, but the hackers will work quietly inside the network to escalate privileges and determine key servers that should be targeted first.

Re: Oakland declares state of emergency due to ransomware attack

#12
post #10
post #5

I don’t get why any user has the ability to cause so much damage. Sure they can lock their own files out and need to restore from backup, but how can that knock out other departments, let alone things like email.

Security is expensive.

surely less expensive than the fallout from this

Re: Oakland declares state of emergency due to ransomware attack

#13
post #9
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…

But, isn't that backwards? 20 year old systems have been thoroughly exploited and usually do not benefit from more recent updates. It's true you can't patch every single vulnerability, but probability is a huge factor in risk. If many of the common exploits have been patched, it's simply harder for your average hacker, the difficulty and opportunity cost just go up.

Re: Oakland declares state of emergency due to ransomware attack

#14
post #10

Earlier quoted context omitted.

Security is expensive.

surely less expensive than the fallout from this

True, but not always. Also, until something happens nobody would approve budget anyway. Exceptions from this rule are rare.

Re: Oakland declares state of emergency due to ransomware attack

#15
post #10

Earlier quoted context omitted.

Security is expensive.

surely less expensive than the fallout from this

Prevention is orders of magnitude less expensive than dealing with the fallout from an eventually inevitable atack.

The tragedy is that in the absence of attacks, local governments don't always allocate the necessary funds to employing competent admins who take a proactive approach to security.

Even more importantly, these admins need to be given authority to block attempts at lowering defenses in the name of convenience or "money-saving".

Re: Oakland declares state of emergency due to ransomware attack

#16
post #9
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…

Microsoft have 122k employees. Assuming that every one of them takes the upgrade, it uses an extra 61TB of storage. I can buy 61TB of NVMe storage from a high street retailer for under $5000. It's less than half that for a normal SSD. It costs more than that for the electricity to install the updates to 120k people I would bet.

> there's really no way to keep anything secure unless you use a machine that's over 20 years old.

This is nonsense. Security isnt a binary thing, and even if it was, you're still vulnerable to wrench-ops. If your threat model is that you suspect your procedure manufacture have backdoored your CPU, you better be running your own fab, air gapping your machines, and desoldering input ports.

Meanwhile for probably 95% of people and businesses out there, keeping windows up to date, 2FA required, encryption in transit and at rest, and regular tested backups is enough.

Re: Oakland declares state of emergency due to ransomware attack

#17
post #15

Earlier quoted context omitted.

surely less expensive than the fallout from this

Prevention is orders of magnitude less expensive than dealing with the fallout from an eventually inevitable atack. The tragedy is that in the absence of attacks, local governments don't always allocate the necessary funds to employing competent admins who take a proactive approach to security. Even more importantly, these admins need to be given authority to block attempts at lowering defenses in the name of conveni…

[deleted]

Re: Oakland declares state of emergency due to ransomware attack

#18
post #9
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…

Windows 1.0 was pretty secure by todays standards. /s

Re: Oakland declares state of emergency due to ransomware attack

#20

Are there no agencies that can help out? CISA is, I guess, more of an advisory agency than operative? Or maybe there are but on federal level?

I don’t think there’s much to be done retroactively. I’m sure there’s an option for proactive help (trainings, advice) but it is a big country, some attacks will slip through.
Post reply on HN