Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

261–270 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#261

Earlier quoted context omitted.

Machines like that, which cannot shoulder the risk of applying updates to a network-connected general purpose OS designed to run third party (potentially malicious) code on a non-deterministic non-realtime system... probably should not be using such a system. Patching is risky, not patching is risky. They should have formally validated software running on formally validated deterministic realtime hardware, running in…

I agree. A mission critical MRI machine should not be running an off the shelf OS (Win, Mac, Linux). If you're paying $5 million for a machine, it better have its own real time operating system that had been independently audited. Now the machine that you pull up the images on is most likely going to be a general purpose PC/Mac. You still need to patch that. Your IT dept needs to have patch cycles that deploy in sets…

Custom operating systems would require higher development costs and extremely rare sysadmin skills, which would mean larger hospital budgets, which would mean higher taxes or premiums.

Yeah, not gonna happen.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#262
post #237

Earlier quoted context omitted.

If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…

> Only zero-days. The exploits released by Wikileaks' Vault 7 dump went public months ago. They're as much a 0-day as JFK's assassination was just a few days ago.

Small correction: Nearly everything in WikiLeaks Vault 7 material was already patched (With the exception of something Cisco related which has since been patched I believe). The Vault 7 content was from CIA.

This issue is apparently based on a more recent leak by the Shadow Brokers, containing content from NSA and some other DoD elements who worked on offensive cyber operations.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#264
post #78
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

It's fine to certify devices for certain software, but a device must either be free to maintain and secure or it's not connected to a network.

If someone has a computer hooked to an MRI machine and to the hospital network, and it runs outdated/insecure software then someone made a mistake somewhere.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#268
post #236

It looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.

It doesnt involve only pdf.js file, the key is a bug in samba that means that all you need to get infected is to connect to an infected network.

Not in Samba, in the SMB protocol implementation on Windows.

Samba servers are safe.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#269

Earlier quoted context omitted.

I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.

How could you ever possibly verify that?

By simplifying the design, until your team can verify its security without throwing up their arms in frustration at the mere prospect. When people's lives are on the line, security is more important than features or convenience.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#270

There's no evidence that this attack targeted the NHS or other health systems, right? Just spreading randomly by email, highest infection probabilities certain older Microsoft OSs?

Yeah it looks like "large public institutions" were affected simply because that's where you'll find more unpatched (or unpatchable, in the case of XP) machines.
Post reply on HN