Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

101–110 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#101
post #97

Earlier quoted context omitted.

The thread is not about whether or not whoever did it gets punished. The question is whether or not it was accidental or if damaging Merck was an intentional act. Based on the evidence so far, it sure seems like damaging Merck was a result of negligence and not intentional.

Releasing a computer virus intended to replicate and spread on any machine it can... like... wtf are you arguing for? The whole point to the thing was to cause massive damage to whoever the intended target was, with little care for collateral damage. It was meant to spread hard and fast and cause damage. If you infected a Merck employee with weaponized ebola and that employee traveled to the USA while the strain was…

like... wtf are you arguing for? You seem to be upset that negligence is a word that describes irresponsible behavior with unintentional results. It's still an accident. It wasn't planned. That is my initial and only point.

Re: Merck’s NotPetya attack: Was it an act of war?

#102

Earlier quoted context omitted.

Yes I am serious. Are you? How about we keep this respectful and do away with the condescending tone, which is not really welcome here on Hacker News? 9/11 was presumably intended to damage as much property and kill as many people as possible. So no, the people who died as a result of that terrorist attack against the US were not killed by accident. Yes, if your gun accidentally goes off during a robbery, that is by…

I never said the gun went off "accidentally", you added that word to support your otherwise baseless argument. Guns go off during robberies because the robber got nervous or impatient, because there was a melee, because a third party got involved. By deliberately bringing the gun into the situation, the subsequent claim of an "accidental" firing is nullified. A guy drinks two quarts of whisky at his favorite bar then…

Great example. Killing someone while drunk is called involuntary manslaughter. Because it's an accident. It was not planned. It wasn't intentional. I never once claimed that accidents can't be horrible. Or that reckless behavior that results in an accident should not be punished. I never said it was "just" an accident. That's you putting words in my mouth. What I said is very simple: if it wasn't part of the plan, it was an accident.

Re: Merck’s NotPetya attack: Was it an act of war?

#103

Earlier quoted context omitted.

I never said the gun went off "accidentally", you added that word to support your otherwise baseless argument. Guns go off during robberies because the robber got nervous or impatient, because there was a melee, because a third party got involved. By deliberately bringing the gun into the situation, the subsequent claim of an "accidental" firing is nullified. A guy drinks two quarts of whisky at his favorite bar then…

Great example. Killing someone while drunk is called involuntary manslaughter. Because it's an accident. It was not planned. It wasn't intentional. I never once claimed that accidents can't be horrible. Or that reckless behavior that results in an accident should not be punished. I never said it was "just" an accident. That's you putting words in my mouth. What I said is very simple: if it wasn't part of the plan, it…

Absolutely false.

Dec. 2: https://www.oregonlive.com/crime/2019/12/drunk-driver-who-ki...

Nov 14: https://www.inquirer.com/news/david-strowhouer-sentence-dui-...

Nov 8: https://eccalifornian.com/drunk-driver-given-second-degree-m...

Nov 15: https://www.pressconnects.com/story/news/public-safety/2019/...

first-degree manslaughter, third-degree murder, second-degree murder, first-degree vehicular manslaughter

"Involuntary" isn't in any of these. And these are just the first few search results.

Re: Merck’s NotPetya attack: Was it an act of war?

#104

Earlier quoted context omitted.

Wait, didn't even reach the absurd final paragraph. If I have a bomb with a blast radius of say, 200 meters, which I drop 50 meters inside an Italian border, knowing full well the blast radius extends into France, you are still claiming deaths in France from my bomb are just an accident?

Please point out where I said you know the blast radius and which direction it heads. Not to mention it's an analogy and I'm not a bombing expert. You can probably figure out my point.

>> a bomb dropped on an Italian border in WWII might accidentally kill ally French citizens

"On an Italian border." Where else could the blast possibly go, except on both sides of the border?

Re: Merck’s NotPetya attack: Was it an act of war?

#105

Earlier quoted context omitted.

Did that military agency plan for it to damage Merck? Or was that an accident?

Are you serious? They planned to launch the equivalent of a digital bomb, knowing full well there would be plenty of collateral damage. Hell no it isn't an "accident" I will put it another way. I feel quite confident the 9/11 bombers did not know, or specifically target, my friends and acquaintances who died in those towers. Therefore, are you going to claim 9-11 was an accident? If I intend to rob a convenience stor…

[deleted]

Re: Merck’s NotPetya attack: Was it an act of war?

#106

Earlier quoted context omitted.

Please point out where I said you know the blast radius and which direction it heads. Not to mention it's an analogy and I'm not a bombing expert. You can probably figure out my point.

>> a bomb dropped on an Italian border in WWII might accidentally kill ally French citizens "On an Italian border." Where else could the blast possibly go, except on both sides of the border?

The other possibility is one side of the border.

Re: Merck’s NotPetya attack: Was it an act of war?

#107

Earlier quoted context omitted.

>> a bomb dropped on an Italian border in WWII might accidentally kill ally French citizens "On an Italian border." Where else could the blast possibly go, except on both sides of the border?

The other possibility is one side of the border.

That would be an impossibility with WWII technology. It's irrelevant -- the scenario you described already acknowledged the bomb crossing the border and killing French citizens on the other side.

Re: Merck’s NotPetya attack: Was it an act of war?

#108
post #10

Earlier quoted context omitted.

The claim in the article is that the target was Ukraine, the attacker Russia, and Merck a collateral casualty at an attempt to disguise a state-sponsored cyber-attack as a criminal extortion attempt. One would need to dig deeper to get a really informed opinion. I do believe Russia to be able and willing to do that, I do believe the so-called "Western intelligence agencies" to blame any malware on Russia or China on…

If you analyze the NotPetya attack, it differs from other ransomware attempts in two respects. First, it was specifically targetting Ukraine. Second, the attackers didn't actually take any money but rendered all systems defunct. If you are a criminal, you aim to make money, right? Why give up on that possibility? It makes no sense. So, even if in the infosec world you can never say never, but just as Stuxnet is gener…

Oh I did not know that. The attack was behaving differently on Ukrainian targets? That's a pretty damning thing indeed and makes the question of the act of war very relevant.

Note that it could make sense to a pro-Russia Ukranian group to extort money abroad and to hurt economically on the target. That seems to be the Russian MO to not be directly implicated in the Ukrainian operations: help with tools, weapons and money the groups that are already in place.

They give up direct control over the actions in exchange of deniability.

Re: Merck’s NotPetya attack: Was it an act of war?

#109

Earlier quoted context omitted.

>"And how are you so sure Merck's IT team didn't fail to have backups, redundancy, security patches, etc. to prevent an attack of any sort from being such a big deal?" If the insurance claim is ~$1.3bn, we can safely say that the NotPetya cleanup isn't a trivial thing for them. How many companies have we heard about who were totally screwed after a ransomware outbreak, because their only backups were online - network…

Any large organization that doesn't, at a bare minimum, implement NSA's Top Ten Cybersecurity Mitigation Strategies[1], ASD's Essential Eight[2], etc. is grossly negligent; and an insurance carrier willing to write a policy not conditional on implementing those strategies is equally negligent. The insurance carriers in this case could very well be attempting to deny payment under the acts-of-war exclusion because the…

>> too incompetent or greedy to correctly write a cybersecurity policy

Don't discount the insurers just yet. The act of war exclusion is likely preferable for the insurers because it would seem to broadly cover the entire incident and because it really doesn't require a whole lot of detailed discovery into Merck's internal processes. But if that fails, then the insurers will, most likely, once again try to deny the claim, this time focusing on the details of the cybersecurity-based policy exclusions.

My guess, with no evidence to back it up, is that the policy is very detailed and specific, and upon investigating its application, the insurers will reveal a lack of proper defense and mitigation processes by Merck, just as you describe.

Re: Merck’s NotPetya attack: Was it an act of war?

#110

Earlier quoted context omitted.

The other possibility is one side of the border.

That would be an impossibility with WWII technology. It's irrelevant -- the scenario you described already acknowledged the bomb crossing the border and killing French citizens on the other side.

It's not impossible. Some of that border has steep mountains. Bombs don't always drop where you plan. Which is called an accident.
Post reply on HN