Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

31–40 of 304 posts

Re: Lessons from last week’s cyberattack

#31
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

No system is perfect. Remember Heartbleed? Microsoft released a patch to correct this particular issue in March, however the IT infrastructure in companies is slow, the whole process is convoluted, yada yada.

The point is: the NSA caused this particular problem. Steps should be taken be everyone to ensure something like this doesn't happen ever again.

Re: Lessons from last week’s cyberattack

#32
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

And who do we fine for all the bugs in Open Source software then. The most serious vulnerabilities of late have all been in Open Source packages: - ShellShock - Heartbleed - etc

Do we fine the person who committed the faulty logic, the reviewers, the entire community who "peer reviewed" it?

Re: Lessons from last week’s cyberattack

#33
From the article:

>A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally.

They stopped supporting Windows XP years ago, including with security updates.

There are still around 100 million computers around the world running XP.

It seems irresponsible to just leave them to hang out to dry when there are that many machines out there running it. A virus seems inevitable if they do. And shifting the blame onto the customers is not reasonable when there are still 100 million customers who are "doing it wrong" by not upgrading to a later version of Windows.

This entire article pertains to directly shifting the blame onto their customers, and the governments of the affected countries (!)

>The fact that so many computers remained vulnerable two months after the release of a patch illustrates this aspect

Again, XP systems are the most affected, and there was no patch released for XP. This is extremely irresponsible of Microsoft and this article shifting the blame onto everyone but themselves is reprehensible.

Re: Lessons from last week’s cyberattack

#34

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

It'd be a good start if they just didn't use Windows.

But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.

Re: Lessons from last week’s cyberattack

#35
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecure technology stack with no vendor to take responsibility and no source code to even take on the problem themselves.

There's plenty of blame to go around to be sure, but giving the NSA a pass for developing zero days is batshit insane. These guys are playing god instead of helping make infrastructure more secure overall, and it will not end well, even if they outcompete the Chinese or whatever other bogeyman they cook up to justify their power grab.

Re: Lessons from last week’s cyberattack

#36
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

I am not exactly sure what dark powers were US government using to force people to leave 3389 on public facing ips. I thought that CIA mind control experiments failed.

Re: Lessons from last week’s cyberattack

#37
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…

Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy)

Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w.... (Security)

I also wonder how long it will take before the shiny new anti-piracy instruments will be abused by a member of the intelligence community, a low-level politician or perhaps embedded into desktop OSes. http://pimg-fpiw.uspto.gov/fdd/50/148/096/0.pdf (You are not the owner of your files)

It's always easy to accuse the user rather than who exploited the vulnerability in the first place or who does not backport security patches when users obviously do not like the new versions of a software. - https://www.netmarketshare.com/operating-system-market-share... - https://www.extremetech.com/computing/227693-windows-drops-b...

Frankly speaking, Microsoft has gone too far into abuse, lock-ins and presumptions.

As a personal comment, I have an old Windows 7 laptop I use with some win32 software, I do not have the slightest intention of upgrading to Windows 10 (not for laziness or hubris, but because IMO the product is not worth the price). And if it was a critical system, than Microsoft Windows would not really be considered among the options.

Re: Lessons from last week’s cyberattack

#38
One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled.

Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService). Many of them are enabled by default and are listening on ports on external interface so the potential attack surface is large.

Microsoft uses programming languages like C++ that is very complicated and a little mistake can lead to vulnerabilities like stack overflow, use-after-free, etc.

Microsoft (and most companies) prefers to patch vulnerabilities with updates rather than take measures that would reduce attack surface.

Oh, and by the way Linux has similar problems. In a typical Linux distribution a program run with user privileges is able to encrypt all of the user's files, access user's cookies and saved passwords on all websites, listen to microphone and intercept kestrokes.

Re: Lessons from last week’s cyberattack

#39
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

And who do we fine for all the bugs in Open Source software then. The most serious vulnerabilities of late have all been in Open Source packages: - ShellShock - Heartbleed - etc Do we fine the person who committed the faulty logic, the reviewers, the entire community who "peer reviewed" it?

Heartbleed and ShellShock were serious but nowhere near the seriousness of WannaCrypt. Don't let the top headlines of HN and a fancy logo be how you rate vulnerabilities.

Re: Lessons from last week’s cyberattack

#40
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

I am not exactly sure what dark powers were US government using to force people to leave 3389 on public facing ips. I thought that CIA mind control experiments failed.

According to CERT [0], the original infection vector is still unclear but possibly phishing, however once a computer is infected, any vulnerable machines on the local network are targets.

[0] https://www.us-cert.gov/ncas/alerts/TA17-132A

Post reply on HN