Live data from Hacker News

Iran-backed hackers claim wiper attack on medtech firm Stryker

krebsonsecurity.com

281–290 of 342 posts

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#281

[flagged]

No, the extremely nasty Islamic Theocracy that runs Iran is fighting for its survival after killing 20,000 protestors. Iran police chief has said that anti-government protesters will be treated as 'enemies'. "And we will do to them what we do to an enemy. We will deal with them in the same way we deal with enemies," he added.

https://www.rnz.co.nz/news/world/589307/iran-police-chief-sa...

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#282

Earlier quoted context omitted.

If by "survival" you mean surviving against a bloodthirsty regime that killed 10,000 people in January alone, then yes: the people of Iran are fighting for survival.

That's pure Israeli propaganda, and as you see there is absolutely no "up rising" from Iranian citizens. They are however, uniformly against Israel and the US given that we started this illegal war by bombing a girls school and murdering over 170 children. Much like Israel has been doing since its creation in 1948.

"there is absolutely no "up rising" from Iranian citizens"

This is an extremely bold lie. There have been many uprisings by Iranians against their horrible government that are extremely brutally suppressed by said government.

https://www.rnz.co.nz/news/world/589307/iran-police-chief-sa...

Iranian protesters will be treated as enemies if they support Tehran's foes, the country's top police officer warned, as the Middle East war sparked fears mass anti-government rallies could reignite.

"If anyone comes forward in line with the wishes of the enemy, we will no longer see them as merely a protester, we will see them as an enemy," said national police chief Ahmad-Reza Radan in comments aired by state broadcaster IRIB late on Tuesday.

"And we will do to them what we do to an enemy. We will deal with them in the same way we deal with enemies," he added.

"All our forces are also ready, with their hands on the trigger, prepared to defend their revolution."

His warning comes after the government cracked down on anti-government protests in January, sparked a month before over economic grievances in the sanctions-hit country.

The authorities deemed the protests to be "riots" and Radan at one point issued an ultimatum to protesters to hand themselves in or face the full force of the law.

Iranian authorities acknowledge more than 3000 deaths in the unrest, including members of the security forces and bystanders, but say the violence was caused by "terrorist acts" fuelled by Iran's enemies.

The US-based Human Rights Activists News Agency (HRANA), however, has recorded more than 7,000 killings in the crackdown, the vast majority protesters, though the toll may be far higher. More than 50,000 have been arrested, it says.

US President Donald Trump had initially cheered on the protesters, threatening to intervene on their behalf as authorities launched a deadly crackdown, but his threats soon shifted to Iran's nuclear programme.

Washington launched strikes with Israel on Iran on February 28, sparking retaliatory strikes by Tehran against Israel and US bases across the Gulf region.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#283

Earlier quoted context omitted.

An alternative is people install the software they choose to on the machines they're using. Optionally write a list of suggested programs down somewhere. In that world, there is no central IT team pushing changes to machines and arguing with developers about whether they really need to be able to run a debugger. I don't know how to keep windows machines alive. It's probably harder.

That is all well and good but how do you: - Ensure the machines are up-to-date and users are not just indefinitely postponing OS updates? - Same as above but with programs/software - How do you ensure correct settings configuration in terms of security? Say default browser, extensions, program access etc? - Re-image or reinstall the OS when there are issues or PC handover to another employee? Manually with a USB stic…

I hear zero-trust is a trendy buzzword at the moment, so let's apply the basic idea here: having a hard shell and a soft and chewy center is not a security posture that works, in practice. You need to harden at every level. RMM uber-admin credentials are the ultimate soft center: you compromise those, you can kill the entire IT infrastructure. The only alternative is to distribute access: have multiple smaller IT teams that adminster small parts of the system, with more 'central' roles providing services but not having full control of most machines. It's not a fun option, but it might also work a lot better if each team can actually adjust policies for the environment they're working in as opposed to trying to have one completely unified policy for an entire multi-thousand employee company. And, for critical systems, I would seriously consider the wisdom of having a remote 'wipe and reformat' button at all.

At a bare minimum, your backup systems should have a completely disjoint set of credentials to your main systems, stored and controlled differently, ideally by a seperate team, if you have the resources.

(And the arguing becomes a problem when IT ceases to consider their job to be solving problems for users within some constraints, and just starts to consider their job to be enforcing those constraints. This also mixes badly with incompetence, which tends to turn everything into a tedious tick-box exercise that neither improves security nor solves user's problems. It's not a good time to have an IT department that can't resist any new security checkbox a vendor offers but can't figure out how to work any of their fancy tools to make life even the slightest bit smoother for their users)

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#284

It appears personal devices were also impacted by this via Microsoft Intune. That app is presented to employees as a way to get their email/slack on their personal device without giving IT systems access to it. IT systems around the country say that they have no access to your personal data and there they can only block access to Intune apps. But the linked reddit thread[1] in this article notes personal devices gett…

Intune has two modes. Device registration and User registration. And two kinds of wipes, retire and wipe. Retire means only delete your work profile and is only available for User registration mdm. Sounds like Stryker didn't configure intune properly for byod to force users with personal devices to use User registration.

Beyond that there are so many other things in intune you can use to prevent this sort of thing. Short lived / JIT credentials with MFA, ip restrictions, multi admin approval, rbac (role based fine tuned permissions eg help desk can't wipe, only retire ) etc. sounds like there were some big misses here.

Also sounds like they were in the system long enough to exfiltrate 50+ TB of data without setting off alarm bells.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#285

Earlier quoted context omitted.

I used to work in test automation for a huge company with terribly annoying IT. I can tell you for a fact that our entire department had well-developed workarounds for the most annoying policies. We even had a few intune 0-days that we literally kept to ourselves to be able to do our jobs properly. Because in the end, it’s not IT on the line for their odious policies causing late delivery, it was us.

What was so annoying? Having to reboot for Windows updates/programs and MS Defender running? Also, if the company is certified in some way there are audits for these things, you understand? Such as updates, backups, security, PAM, antivirus etc :) Subvert these controls intentionally, especially security ones = bye bye. Logs don't lie. We see you.

We never got caught or fired. I won’t detail the 0-days we used because I’m pretty sure the team is still using them, but I can assure you that the logs DID lie.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#287
post #244

Earlier quoted context omitted.

Ok and who has access to the global admin and how resistant are they to Iranian operatives?

What are you asking? For Stryker specifically? We don't and probably won't know details. For companies in general? Background checks, security clearance etc are done if the company determines this necessary and are willing to pay for the process and higher salary.

I’m asking if it’s possible to secure the MDM process in a way that Iranian operatives can’t simply torture an administrator into pushing the big red MDM button.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#288

[flagged]

No, the extremely nasty Islamic Theocracy that runs Iran is fighting for its survival after killing 20,000 protestors. Iran police chief has said that anti-government protesters will be treated as 'enemies'. "And we will do to them what we do to an enemy. We will deal with them in the same way we deal with enemies," he added. https://www.rnz.co.nz/news/world/589307/iran-police-chief-sa...

Bombing the crap out of their country doesn't help normal Irianians though. It only helps Isreal. The Isrealies want a broken Iran in chaos, and the nasty Islamic Theocracy would prefer a bit of destruction to being overthrown by organized internal resistance.

The Iranian regime was on it's way out. A government can't survive killing that many of its own people. But as has been shown many times, the average person will choose opressive order over chaos.

The Iranian people were dangerously close to taking their country back, Isreal made sure that won't happen.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#289
post #204

Earlier quoted context omitted.

They were flying over military installations, if they were anyone else's drones, they would have been shot down like the weather balloons that spook the government from time to time.

Foreign drones surveilled a military base here and they didn't shoot any down. Maybe the US reacts differently, but in Europe most military bases have been scouted by Russian drones, and afaik none were shot down.

I've seen the reaction to people flying their toy drones too close to military assets, they send men out with machine guns and megaphones, confiscate the drone and sometimes press charges.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#290
post #246

Earlier quoted context omitted.

Iran wasn't going to nuke anyone. They want Islam to dominate the world, that can't happen if there isn't a world left to dominate .

I agree with the first part of what you said. Mostly because they didn't have nukes to begin with.

I think it’s possible they already have nukes and want to wait for Israel to over extend themselves so that they can use them for a first strike with maximum efficacy. They’ve done a lot for Russia. The idea that they don’t have nuclear armament is somewhat hard for me to believe.
Post reply on HN