The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…
Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…
Lessons from last week’s cyberattack
101–110 of 304 posts
Re: Lessons from last week’s cyberattack
#102Earlier quoted context omitted.
> The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. The problem is corporate IT (or management) think they can create some sort of stable environment, driven by fear of having things break. Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app brea…
Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app breaking on a windows patch. Except it's not. The account used by the hackers has supposedly earned about 4 Bitcoins so far. Meanwhile, many people from home users to professional IT personnel can recall incidents where Windows Update has broken somethin…
I do agree MS needs to shoulder a lot of the blame here, but would they have acted differently if IT departments didn't block updates?
Re: Lessons from last week’s cyberattack
#103Earlier quoted context omitted.
You're assuming it was released on purpose and worked on the intended scale, I'm not sure either are true.
This malware was first released as part of a massive spam campaign, and then from there wormed its way onto other systems. It was definitely released on purpose.
Re: Lessons from last week’s cyberattack
#104Re: Lessons from last week’s cyberattack
#105Why not use Linux or MacOS?
Re: Lessons from last week’s cyberattack
#106Earlier quoted context omitted.
Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…
Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…
Thing is, the more of that data they have, the more likely they are to prioritise testing those use cases.
So it's a trade-off - do you want telemetry, or do you want a higher risk of bugs - you have to pick one.
Re: Lessons from last week’s cyberattack
#107Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.
It'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.
I hear tell that server wise NHS IT will also support OpenSUSE, and their record of keeping that patched is almost as good as their record for doing so with windows.
Re: Lessons from last week’s cyberattack
#108Earlier quoted context omitted.
> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…
Walled garden is fine only if you build the walls. Please let the iOS stay the only such corporate build travesty. It is good to have the ability to raise the walls. It is not good for apple and MS to decide what to use their OS for...
But I strongly believe that right now apps get too much access by default (read, write all my files is crazy). And if they need anything beyond that they just ask for root. There needs to be much more granular permissions, with more restrictive defaults and nice informative dialogs.
It's unsexy, and inconvenient for developers. But it's the right thing for our users. It's how I want random programs downloaded from the internet to behave.
Re: Lessons from last week’s cyberattack
#109Re: Lessons from last week’s cyberattack
#110Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.
I always had auto updates turned on until Windows' malicious behaviors in recent years: https://thenextweb.com/microsoft/2015/09/11/microsoft-is-aut... This one consumes me several gigabytes on my C drive without my permission. https://www.tenforums.com/windows-updates-activation/55185-w... This one acts like malware. And this one: http://www.pcworld.com/article/3039827/windows/7-ways-window... I don't know why I'd c…