Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

101–110 of 304 posts

Re: Lessons from last week’s cyberattack

#101
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

Fair enough but, like others have said, who do I fine when my Wordpress site gets pawned or for Shellshock, etc? I wish this problem was a simple as blaming/fining MS or Google.

Re: Lessons from last week’s cyberattack

#102
post #75

Earlier quoted context omitted.

> The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. The problem is corporate IT (or management) think they can create some sort of stable environment, driven by fear of having things break. Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app brea…

Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app breaking on a windows patch. Except it's not. The account used by the hackers has supposedly earned about 4 Bitcoins so far. Meanwhile, many people from home users to professional IT personnel can recall incidents where Windows Update has broken somethin…

This is only a single particularly large attack, the same sort of thing happens to machines everyday on a smaller scale. The future potential for attacks like this also go way beyond the current attack.

I do agree MS needs to shoulder a lot of the blame here, but would they have acted differently if IT departments didn't block updates?

Re: Lessons from last week’s cyberattack

#103
post #72

Earlier quoted context omitted.

You're assuming it was released on purpose and worked on the intended scale, I'm not sure either are true.

This malware was first released as part of a massive spam campaign, and then from there wormed its way onto other systems. It was definitely released on purpose.

Has any of that been confirmed? I thought patient zero's were still mostly speculation.

Re: Lessons from last week’s cyberattack

#106

Earlier quoted context omitted.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…

Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…

> Critical systems should not have installed an operating system that collects metadata on virtually anything the user does

Thing is, the more of that data they have, the more likely they are to prioritise testing those use cases.

So it's a trade-off - do you want telemetry, or do you want a higher risk of bugs - you have to pick one.

Re: Lessons from last week’s cyberattack

#107

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

It'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.

> It'd be a good start if they just didn't use Windows.

I hear tell that server wise NHS IT will also support OpenSUSE, and their record of keeping that patched is almost as good as their record for doing so with windows.

Re: Lessons from last week’s cyberattack

#108
post #80

Earlier quoted context omitted.

> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…

Walled garden is fine only if you build the walls. Please let the iOS stay the only such corporate build travesty. It is good to have the ability to raise the walls. It is not good for apple and MS to decide what to use their OS for...

Yeah I don't want the only distribution model to be an App Store. And I don't want to lose the ability to run things with root access.

But I strongly believe that right now apps get too much access by default (read, write all my files is crazy). And if they need anything beyond that they just ask for root. There needs to be much more granular permissions, with more restrictive defaults and nice informative dialogs.

It's unsexy, and inconvenient for developers. But it's the right thing for our users. It's how I want random programs downloaded from the internet to behave.

Re: Lessons from last week’s cyberattack

#110
post #63
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I always had auto updates turned on until Windows' malicious behaviors in recent years: https://thenextweb.com/microsoft/2015/09/11/microsoft-is-aut... This one consumes me several gigabytes on my C drive without my permission. https://www.tenforums.com/windows-updates-activation/55185-w... This one acts like malware. And this one: http://www.pcworld.com/article/3039827/windows/7-ways-window... I don't know why I'd c…

Yes, Microsoft is converting an operating system to a web page where they can track your usage. Have you tried with tweaking software like http://winaero.com ?
Post reply on HN