Earlier quoted context omitted.
This is public knowledge at this point.
Citation please?
Lessons from last week’s cyberattack
21–30 of 304 posts
Re: Lessons from last week’s cyberattack
#22Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.
Re: Lessons from last week’s cyberattack
#23Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
Re: Lessons from last week’s cyberattack
#24Earlier quoted context omitted.
This is public knowledge at this point.
Citation please?
Re: Lessons from last week’s cyberattack
#25The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…
MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.
Re: Lessons from last week’s cyberattack
#26The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…
Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic.
Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts and propping up of another billionaire or two. I can hear the whisky glasses clinking.
Corporations do not get to set the agenda and the narrative. When they are allowed to, the results are very predictable - in this case Microsoft will make more than they loose. Who here disagrees that is going to happen? And who here believes that is right?
The answer is simple whether its Microsoft today or Facebook and Google tomorrow win-win should not be an option when such things happen.
Re: Lessons from last week’s cyberattack
#27Earlier quoted context omitted.
MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.
The margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.
Re: Lessons from last week’s cyberattack
#28Earlier quoted context omitted.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
Your safest option then is to disable SMB.
Also, decent AV and anti spam and don't open email attachments without some prior analysis. Backups - good backups and check them at least weekly.
Actually just do all the boring stuff that IT Security have been recommending for years.
Re: Lessons from last week’s cyberattack
#29Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
I routinely disable services (until things stop working and I have to figure where I went too far) and luckily I'd disabled this one on my Win7 gaming box, even though the updates came through as well (I just manually vet updates, and have a bunch of them blacklisted for adding telemetry).
Re: Lessons from last week’s cyberattack
#30Earlier quoted context omitted.
MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.
The margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.
The NSA likely gave MS months of lead once they determined what SB stole. A patch was pushed out before the release of the vulns.
There's no reason to suspect that people wouldn't have reverse engineered the vuln from the patch and had similar timelines of unpatched systems being exposed.
In fact, we see exactly that play out over and over with security patches.