Live data from Hacker News

Oakland declares state of emergency due to ransomware attack

nbcbayarea.com

21–30 of 86 posts

Re: Oakland declares state of emergency due to ransomware attack

#21
post #18
post #9

Earlier quoted context omitted.

I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…

Windows 1.0 was pretty secure by todays standards. /s

No networking, right? I guess it was pretty good.

Re: Oakland declares state of emergency due to ransomware attack

#22
post #9
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…

I love people that believe there exists a version of any operating system with C code on it, that can be deemed secure.

https://en.wikipedia.org/wiki/Morris_worm

Re: Oakland declares state of emergency due to ransomware attack

#23
post #7

Earlier quoted context omitted.

Monero https://cointelegraph.com/news/monero-crypto-of-choice-as-ra...

Thanks! That is from 2021; is that still the case?

new mixers come around. there where some news about one called sinbad for btc recently which is being used to launder money by the NK hackers

Re: Oakland declares state of emergency due to ransomware attack

#25
post #10

Earlier quoted context omitted.

Security is expensive.

surely less expensive than the fallout from this

Depends, but usually the problem is that it is difficult to properly assess the probability of a successful attack and to get decision makers to believe that number.

Re: Oakland declares state of emergency due to ransomware attack

#26
post #15

Earlier quoted context omitted.

surely less expensive than the fallout from this

Prevention is orders of magnitude less expensive than dealing with the fallout from an eventually inevitable atack. The tragedy is that in the absence of attacks, local governments don't always allocate the necessary funds to employing competent admins who take a proactive approach to security. Even more importantly, these admins need to be given authority to block attempts at lowering defenses in the name of conveni…

The problem is that lowering security expenditure is a good gamble for managers/executives: Chances are it will take a while before things blow-up.

In the meantime, you get the credit for "saving money", you will get promoted, perhaps move to another company, and the bomb will explode in the hands of your successor.

Re: Oakland declares state of emergency due to ransomware attack

#27

Are there no agencies that can help out? CISA is, I guess, more of an advisory agency than operative? Or maybe there are but on federal level?

Hardly anyone is interested in defensive security because if you do it well your job looks unnecessary. This goes both at the national security level and the individual organisation.

Re: Oakland declares state of emergency due to ransomware attack

#28
post #2

This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…

If its really important. Airgap. Or VM-Wrapped with restore points. I completely understand that somebody does not want to upgrade into the warp-abyss-abomination of modern windows, especially if huge expenses software was written once, that needs backwards compatability or contains sensitive data. You can not use windows if you work for anything with sensitive data. In todays world the legacy is the good stuff. Just…

An airgapped system is one that's basically unusable because you can't communicate with other systems.

Re: Oakland declares state of emergency due to ransomware attack

#29

Are there no agencies that can help out? CISA is, I guess, more of an advisory agency than operative? Or maybe there are but on federal level?

At this point it's too late, and before that they didn't really need advice or some fancy technology, they needed to dedicate enough resources/people/effort to simply do proper maintenance of their IT infrastructure. It's also plausible they simply couldn't afford the required resources, but that's not something fixable by CISA or other federal agencies.
Post reply on HN