Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

21–30 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#21

Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…

That argument doesn't hold water. You don't need to be an intended target or a country for something to be an act of war.

If North Korea drops a nuclear bomb on China, and the nuclear cloud does collateral damage in India, that's still damage from an act of war.

Acts of war are excluded since insurance is designed to spread cost for isolated events. If my house burns down, everyone chips in to rebuild it. You can't reasonably insure widespread events. If an entire country is demolished, whether by war, flood, or other large-scale natural disaster, insurance would just go under.

Things are murky here. But not for those reasons. We can start with there not being a war, continue into covert ops not really being the same as war, and keep going for a while. I do think insurance SHOULD pay for this one. But it's not that simple.

Re: Merck’s NotPetya attack: Was it an act of war?

#22
post #20

Earlier quoted context omitted.

> which BTW isn't a country, so by definition, one can't go to war with it? Suppose North Korea shoots artillery on Samsung factories. Is that not an act of war because they were targeting a company's buildings? The US has some mixed messaging on cracking. On the one hand they reserve the right to consider attacks on them as acts of war (and to respond with bombs) on the other hand they have no reservations about cra…

I would say that it's not an act of war against Samsung but South Korea which should be a difference.

This was corporate property insurance, and it excluded "acts of war". It doesn't matter who the war is between; the fact that a cost was incurred due to war would mean that you cannot claim that cost on the insurance policy. If it only referred to acts against a specific state, then you would have no need to include the wording in the contract as it would be a no-op.

Insurance policies have often tried to exclude the highly-unlikely-but-ruiniously-costly coverage; hence the similar "acts of god" exclusions (and obvs there's rarely any disagreement about whether god was specifically the actor). A war is a usually a large-scale event causing a large amount of damage; without excluding it you would expect many insurers to be bankrupted. "Cyberwar" is something of a different matter and I could see why either side would want to litigate to clarify the definition.

Re: Merck’s NotPetya attack: Was it an act of war?

#23

Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…

Act of war against Ukraine, per the article.

Re: Merck’s NotPetya attack: Was it an act of war?

#26
post #8

The ransomware wanted $300 in Bitcoin per computer encrypted. This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.

Just as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.

Re: Merck’s NotPetya attack: Was it an act of war?

#27

It's really an act of not being prepared. $1.7B? They should be able to destroy and rebuild their entire infrastructure in less than a day. Have tested backup and restore processes. Ideally have all users in VMs. I don't see how this isn't entirely Merck's fault.

I work at a pharmaceutical company and this does not suprise me at all. Our IT infrastructure and support is atrocious.

Re: Merck’s NotPetya attack: Was it an act of war?

#28

It's really an act of not being prepared. $1.7B? They should be able to destroy and rebuild their entire infrastructure in less than a day. Have tested backup and restore processes. Ideally have all users in VMs. I don't see how this isn't entirely Merck's fault.

Not entirely Merck's fault. It wouldn't have happened (at this time) if Russia hadn't used their weaponized exploit.

There's also something to be said for being the first large-scale victim of a category of catastrophe that is known to be a real threat, but hasn't happened on this scale before.

But you do have a point. There were probably security or IT ops people who warned about this, and if Merck's shareholders take the full hit, organizations will properly feel the risk and adjust their backup & restore processes accordingly. Not so if insurance pays the full damages.

Re: Merck’s NotPetya attack: Was it an act of war?

#29

It's really an act of not being prepared. $1.7B? They should be able to destroy and rebuild their entire infrastructure in less than a day. Have tested backup and restore processes. Ideally have all users in VMs. I don't see how this isn't entirely Merck's fault.

If you cannot trust any of your existing infrastructure anymore, including servers, desktops, storage systems, directory services, and the backup systems themselves, you will not be rebuilding it all in a day...

Re: Merck’s NotPetya attack: Was it an act of war?

#30

Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…

>> This is the very definition of an accident

How is something deliberately planned and executed, by a military intelligence agency, for weeks or months, an accident?

And how are you so sure Merck's IT team didn't fail to have backups, redundancy, security patches, etc. to prevent an attack of any sort from being such a big deal?

Post reply on HN