Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

21–30 of 304 posts

Re: Lessons from last week’s cyberattack

#21
post #4

Earlier quoted context omitted.

This is public knowledge at this point.

Citation please?

The NSA hoarding / leaking aspect of this vulnerability has been reported by most major news outlets. Even the mainstream ones. Albeit most haven't expanded on that point to the level that Microsoft did here.

Re: Lessons from last week’s cyberattack

#23
post #13
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Why do you fear updating to Windows 10?

Re: Lessons from last week’s cyberattack

#24
post #4

Earlier quoted context omitted.

This is public knowledge at this point.

Citation please?

This (as far as I know) was one of hte first reports of details of the malware and clearly mentions it, and other analysts haven't said otherwise, which by now they would have if they disagreed: http://blog.talosintelligence.com/2017/05/wannacry.html

Re: Lessons from last week’s cyberattack

#25
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

The margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.

Re: Lessons from last week’s cyberattack

#26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative.

Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic.

Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts and propping up of another billionaire or two. I can hear the whisky glasses clinking.

Corporations do not get to set the agenda and the narrative. When they are allowed to, the results are very predictable - in this case Microsoft will make more than they loose. Who here disagrees that is going to happen? And who here believes that is right?

The answer is simple whether its Microsoft today or Facebook and Google tomorrow win-win should not be an option when such things happen.

Re: Lessons from last week’s cyberattack

#27

Earlier quoted context omitted.

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

The margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.

Unless the NSA reported it to MS back when XP was still supported, not much would change. People can (and do) reverse-engineer exploits from windows updates, and they could still take advantage of the large number of unpatched XP machines.

Re: Lessons from last week’s cyberattack

#28
post #13

Earlier quoted context omitted.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Your safest option then is to disable SMB.

Just SMBv1 in this case, here is how: https://support.microsoft.com/en-gb/help/2696547/how-to-enab...

Also, decent AV and anti spam and don't open email attachments without some prior analysis. Backups - good backups and check them at least weekly.

Actually just do all the boring stuff that IT Security have been recommending for years.

Re: Lessons from last week’s cyberattack

#29
post #13
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Disabled the SMB services yet? Win + R -> services.msc

I routinely disable services (until things stop working and I have to figure where I went too far) and luckily I'd disabled this one on my Win7 gaming box, even though the updates came through as well (I just manually vet updates, and have a bunch of them blacklisted for adding telemetry).

Re: Lessons from last week’s cyberattack

#30

Earlier quoted context omitted.

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

The margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.

Based on what?

The NSA likely gave MS months of lead once they determined what SB stole. A patch was pushed out before the release of the vulns.

There's no reason to suspect that people wouldn't have reverse engineered the vuln from the patch and had similar timelines of unpatched systems being exposed.

In fact, we see exactly that play out over and over with security patches.

Post reply on HN