Earlier quoted context omitted.
got anything from the past 50 years?
stuxnet...
FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
121–130 of 357 posts
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#122Earlier quoted context omitted.
“Deserve” doesn’t do anything for the people hurt by this, and it doesn’t justify the behavior of the hackers.
Pay the ransom and nobody gets hurt. It's actually tiny price to pay compared to proper infrastructure. Insurers make trillions, it's nothing to them. The happy ending of this would be continuing to pay terrorists who keep you IT top notch...
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#123This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.
If a hospital had random power cables everywhere and someone tripped over one and unplugged an important device, that would be far far more on the side of the hospitals fault than an attack on the computer systems.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#124Earlier quoted context omitted.
Do you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.
At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.
WRT engineering- if someone walks into a production cell and a robot swings and hits them in the head, guess who generally gets the blame in an investigation? The group that somehow didn't put safety scanners or a cell wall with door interlocks or didn't use safety-rated equipment.
There's a big difference between "guys, please get out of the way before I make the bot move" and "guys, I can't make the bot move until you're out of the way and the door is closed and latched" and worst-case scenario, that difference can be any number of human lives.
Surely things can improve, but it'll take time, dedication, and sucking it up and rewriting legacy code and probably being slower at pushing features out. (Keep in mind this isn't a universal guidebook- and should mostly be for companies that create software and infrastructure that is or can be life-critical.)
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#125Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#126Earlier quoted context omitted.
The problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.
Of course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case…
Absence of evidence is not evidence of absence.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#127This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#128If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…
If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#129It would certainly make them less efficient and result in more errors, but hopefully they wouldn’t grind to a complete halt.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#130Earlier quoted context omitted.
True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)
Takes a goofy definition of terrorism to get Bay of Pigs to fit. A military attempt to overthrow a violent leader of another country doesn’t really land in the same category of shutting down hospitals and killing sick people with no political power.