Live data from Hacker News

Iran-backed hackers claim wiper attack on medtech firm Stryker

krebsonsecurity.com

241–250 of 342 posts

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#241
post #165
post #153

I absolutely think there should be ramifications for such acts. What I find bizarre, is that China and Russia do this daily, and "oh well". If such states sent over people to, you know, do damage using a bomb instead of a hack, there'd be trouble. As in, two towers were damaged, and it set off 20 years of war ... mostly against the wrong states. Yet if you cause death via subtle means, such as reducing hospital infra…

The only reason the US government doesn't make a big deal about hacking is because they dont want blowback from their own intelligence collection operations. It's like how every country knows embassies are full of spies but they let them operate as diplomats anyway because they do the same thing.

> It's like how every country knows embassies are full of spies but they let them operate as diplomats anyway

Or in Iran’s case, they don’t.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#242
post #149

Earlier quoted context omitted.

What about a company that killed 20000 to 30000 protestors with machine guns?

The US can't even confirm how many detainees have died in custody in immigration detention around the country, yet they have precise numbers on how many people the Iranian regime has killed? Give me a break.

If Iran is unwilling to let neutral international observers confirm the number, that suggests they are trying to hide a number they don't want the world to know.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#243
post #238
post #237

Earlier quoted context omitted.

>I'm saying that the media suddenly covering stories like this isn't a coincidence. The media is a tool of the state to manufacture consent [...] What do you mean "suddenly"? Per the reddit thread, they just got hacked yesterday. It's not like they were sitting on the story until the war broke out. Moreover I see hacks covered in the media all the time, even if there's no obvious russia/iran/north korea "manufacture…

> Per the reddit thread, they just got hacked yesterday. There are constant hacks of companies. Most of them don't get covered. So there's that. But it's also how it's framed. It's an "Iranian cyberattack". Interesting. Couldn't an equally valid headline be "Lax security results in Stryker getting hacked"? Probably (just guessing). It's a bit like all the stories about the Chinese stealing IP and jobs. Ok, let's assu…

>There are constant hacks of companies. Most of them don't get covered. So there's that.

Source? You can't just be like "some hacks don't get covered, this hack got covered, therefore there must be some ulterior motive behind this". If the baseline rate for reporting hacks is like 50% (random number), then the fact that it got reported doesn't tell us much. Moreover Stryker Corporation is a S&P 500 company, and this hack had major impact on their business. It's not just some data that got leaked, all their laptops/phones got wiped. It's exactly the type of hack that I'd expect to not get swept under the rug.

>It's an "Iranian cyberattack". Interesting.

Again, unless you're going for the false flag or inside job excuse, the hacker's note makes it pretty clear that it's Iranian backed, or at least by Iranian sympathizers.

>Couldn't an equally valid headline be "Lax security results in Stryker getting hacked"? Probably (just guessing).

>It's a bit like all the stories about the Chinese stealing IP and jobs. Ok, let's assume those claims are true and have been for decades. So why do companies keep offshoring there knowing this will happen? At what point do you blame short-term cost-cutting by bonus-hunting executives?

Same reason we don't put out headlines saying "women going to seedy club results in rape".

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#244
post #110

Earlier quoted context omitted.

How does that look exactly? Someone has to be able to use MDM to manage devices or there’s no point in having it. This scenario is firmly in rubber hose/crescent wrench cryptanalysis territory. Can updates have delays with approval gates built in? Does MDM need a break glass capability?

"Principle of least privilege" as MS calls it. Do not use global admin or admin account as daily driver for one. Dont save it in browser etc either. Limit roles, even within the application, here Intune. Office 365 also has conditional access and many policy leavers to tweak, many cases of people locking themselves OUT of 365. So the gates work but you need to configure them. "Break glass" global admin accounts now a…

Ok and who has access to the global admin and how resistant are they to Iranian operatives?

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#245
post #240
post #146

Earlier quoted context omitted.

Americans don't need any encouragement from foreign powers to do that. Congress has seen fit to keep letting it happen by pointing to ancient scripture about the right to develop one's own organized militia....

Difficult to be sure what would happen in a counter factual universe without foreign interference. We do know that Russia et al sow division online as part of their anti western efforts, a strategy detailed in their "Foundations of Geopolitics" manual.

Someone commented, and I paraphrase poorly, "Imagine if Russia didn't influence the voters in 2016; all the racism and bigotry in the USA would disappear!"...

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#246
post #29

Earlier quoted context omitted.

I think this refers to "bombing for peace". Sure the West should have just let Iran nuke whoever it wanted.

Iran wasn't going to nuke anyone. They want Islam to dominate the world, that can't happen if there isn't a world left to dominate .

I agree with the first part of what you said. Mostly because they didn't have nukes to begin with.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#247
post #242
post #149

Earlier quoted context omitted.

The US can't even confirm how many detainees have died in custody in immigration detention around the country, yet they have precise numbers on how many people the Iranian regime has killed? Give me a break.

If Iran is unwilling to let neutral international observers confirm the number, that suggests they are trying to hide a number they don't want the world to know.

Who gets to define what "neutral" is? According to the US, the International Criminal Court is not fit for this purpose. It certainly can't be a nation-state that's in a military alliance with the US.

Human Rights Watch, MSF, UNICEF? Woke grievance factories, the lot of them /s . World Health Organization? US just left it. It's slim pickings out there.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#249

Earlier quoted context omitted.

No, most companies use MS authenticator now for Office 365... https://support.microsoft.com/en-us/account-billing/download...

In the company I used to work they shipped you a chromium os computer and a yubikey

Most companies are definitely NOT using Yubikeys. Did you work for Google? Nice man :)

MFA in general had to be forced on companies, and then it is most often in software on a phone.

Here are some rough numbers.

  google_workspace:
    total_active_users: "3 billion (includes free/consumer Gmail)"
    paid_business_customers: "11 million companies (2024)"
    paid_customer_growth: "+1 million companies in under 1 year (2023-2024)"
    global_business_market_share: "~50%"
    fortune_500_presence: "minority share, weaker than Microsoft in enterprise"
    mfa_with_yubikeys:
      internal_google_employees: "100% use hardware keys (Yubikey/Titan) — since 2017"
      fido_u2f_origin: "Google co-created U2F standard with Yubico post-Operation Aurora"
      estimated_user_adoption_pct: "~1-3% of all Workspace users (inference, not published)"
      concentration: "Highest in finance, government, tech/security-conscious orgs"
      typical_majority_mfa_method: "TOTP apps (Google Authenticator) or SMS"
      enterprise_passkey_deployment_2025: "87% of US/UK enterprises deploying or have deployed passkeys (FIDO Alliance — includes all hardware key types, not Yubikey-specific)"

  microsoft_365:
    total_active_users: "~270 million (commercial)"
    paid_business_customers_us: "~1 million active US business customers"
    us_company_penetration: "~3% of all US companies"
    global_business_market_share: "~45%"
    fortune_500_presence: "~75% of Fortune 500"
    mfa_with_yubikeys:
      exact_stat_available: false
      note: "Same data gap as Workspace — no published breakdown"

  caveats:
    - "Google's 3B user figure conflates consumer and business — not comparable to Microsoft's 270M commercial figure"
    - "Market share figures vary by methodology (seats vs revenue vs orgs)"
    - "Yubikey adoption % is an industry inference; treat as directional only"
    - "Passkey != Yubikey — FIDO Alliance 87% figure covers all FIDO2/passkey methods"

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#250
post #149

Earlier quoted context omitted.

What about a company that killed 20000 to 30000 protestors with machine guns?

The US can't even confirm how many detainees have died in custody in immigration detention around the country, yet they have precise numbers on how many people the Iranian regime has killed? Give me a break.

[flagged]
Post reply on HN