Live data from Hacker News

Iran-backed hackers claim wiper attack on medtech firm Stryker

krebsonsecurity.com

121–130 of 342 posts

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#122
post #92

Earlier quoted context omitted.

Well, all the machines in the current outfit are Linux as far as I know. Services are self hosted. Seems to be fine, teams et al run adequately in a browser for talking to people on other stacks. Previous place had a corporate controlled windows laptop that made a very poor thin client for accessing dev machines. One before that had a somewhat centrally managed macbook that made a very poor thin client for accessing…

I don't see how Linux would prevent anything if company wants similar controls on their machines. Like tracking update status, forcing updates when needed, potentially wiping entire device when stolen and so on. Fault really is not the OS but the control corporate wants over their devices. And it does make some sense.

Indeed. You'd expect a corporate IT system to be able to ssh as root into all their devices. And the cloud is even worse: if you get hold of the right IAM role, you can simply delete everything! That does usually get locked behind proper 2FA, but it's not impossible to phish even experienced admins once in a while.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#123

Earlier quoted context omitted.

The company should have known better than to trust their IT infrastructure to Microslop. This is their own fault.

[flagged]

All the Linux kernel development work is organized around a mailing list, and some private IRC chats for the core people. It's the technology of the nineties but it works for them.

A lot of corporate stuff seems to be much worse than even a random vibe coded web app. I have to book holiday through something called "HR Connect", watching pages load laboriously and redirect every login through several very long URLs. Slowly.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#124
post #5

Earlier quoted context omitted.

>My only knowledge this company is as a manufacturer of gurneys for ambulances. they have a tremendous catalog[0]. spend time in a hospital, dental office, rehab, etc and you'll see the logo plastered across everything. [0]: https://www.stryker.com/us/en/portfolios/medical-surgical-eq...

yeah that is a lot of tech, but it’s all B2B- no consumer breach, right?

That second B has alot of customers. Sick and dying customers that arent very flexible on demand

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#126
post #36

Earlier quoted context omitted.

That’s not the motivation for these attacks at all. They’re waging asymmetric warfare against a much larger and more exposed opponent. Their goal is to make it too troublesome for the US/Israel to continue attacking them, like a swarm of bees attacking a bear to keep it away from their honey. Iran is in it to win it and the US is so very obviously not. The question is if the pressure that Israel can put on the curren…

Trump and republicans are now all-in in this war and this administration can tolerate a huge amount of chaos if it allows them to keep winning. It doesn't matter wether Israel pressures the administration or not. I'm not confident that the regime will fall but I am confident that it will be put in its place internationally even if it means closing the iranian borders from the outside indefinitely. BTW the US and Isra…

Trump is never all in on anything. There's a reason that "TACO" became a meme. This administration is much more likely to lose interest and declare victory while oil facilities in the gulf states are still on fire.

> closing the iranian borders from the outside indefinitely

Are you proposing to disrupt China-Iran shipping? Intercept even Chinese-flagged oil vessels? (not that there are many, most are still under flags of convenience)

Shoot down China-Iran civilian airliners? (again)

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#127

I wonder if there was some confusion between Stryker the Army infantry vehicle and Stryker the medtech company. It seems a really weird target for Iran otherwise.

Medtech company males complete sense. Iran's strategy seems to be to tighten the screws on US citizens so they put pressure on the government to stop the war. They seem to be doing that with things like higher gas prices, and now delays at hospitals with this stryker hit

Makes sense given that US citizens tend not to be too supportive of american wars, but tolerate them because it doesnt really affect them. So iran can get this to affect them then people might come out to the streets. Which would be especially effective in a midterms year like now.

Man itll be ironic as fuck if iran manages to enact regime change in the us before the us does in iran

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#128

So US and Israel wipe out a school filled with children and Iranian hackers delete some data as retaliation?

There's an awful lot more involved on both sides of this. I don't think Iran gets enough criticism from the "non-rightwing" faction for its role in both supplying Russia with weapons against Ukraine and for escalating the conflict around Israel resulting in reprisals against Palenstinian and Lebanese civilians.

It would take some unpleasant searching but I'm sure one can find the most recent incident of Hezbollah (not Hamas, Hezbollah are explicitly backed by Iran) either carrying out a missile or suicide bombing attach with the loss of Israeli civilian lives.

(disclaimer: the war of aggression against Iran by Israel and its decapitation attacks are also wrong)

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#129

Earlier quoted context omitted.

[flagged]

Well, all the machines in the current outfit are Linux as far as I know. Services are self hosted. Seems to be fine, teams et al run adequately in a browser for talking to people on other stacks. Previous place had a corporate controlled windows laptop that made a very poor thin client for accessing dev machines. One before that had a somewhat centrally managed macbook that made a very poor thin client for accessing…

That is all well and good but how do you:

- Ensure the Linux machines are up-to-date and users are not just indefinitely postponing OS updates?

- Same as above but with programs/software

- How do you ensure correct settings configuration in terms of security? Say default browser, extensions, program access etc?

- Re-image or reinstall the OS when there are issues or PC handover to another employee? Manually with a USB stick?

This kind of control exists and is needed for Linux and MacOS too. RMM is not a Windows only thing...

The critics here see Intune but what if they used another RMM and they compromised another cloud RMM account? Same issue.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#130

Earlier quoted context omitted.

[flagged]

An alternative is people install the software they choose to on the machines they're using. Optionally write a list of suggested programs down somewhere. In that world, there is no central IT team pushing changes to machines and arguing with developers about whether they really need to be able to run a debugger. I don't know how to keep windows machines alive. It's probably harder.

That is all well and good but how do you:

- Ensure the machines are up-to-date and users are not just indefinitely postponing OS updates?

- Same as above but with programs/software

- How do you ensure correct settings configuration in terms of security? Say default browser, extensions, program access etc?

- Re-image or reinstall the OS when there are issues or PC handover to another employee? Manually with a USB stick?

This kind of control exists and is needed for Linux and MacOS too. RMM is not a Windows only thing...

The critics here see Intune but what if they used another RMM and they compromised another cloud RMM account? Same issue.

Also, here there is no "arguing". They order the software from our portal and it gets pushed into Company Portal via Intune...

Write down a list you say... idk what to say. You have only worked for small startups I gather? Nothing wrong with that but please recognize that these types of limits and programs are not deployed for fun or to ruin your day.

Post reply on HN