Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

301–310 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#301
post #231

Earlier quoted context omitted.

> Let's hope it's not XP BMJ released a report[0] just two days ago alleging that up to 90% of the NHS's computers are still running XP. > Many hospitals use proprietary software that runs on ancient operating systems. Barts Health NHS Trust’s computers attacked by ransomware in January ran Windows XP. Released in 2001, it is now obsolete, yet 90% of NHS trusts run this version of Windows. [0] http://www.bmj.com/cont…

It appears the Theresa May is trying to deflect attention from the fact that there has been massive under investment in NHS IT infrastructure by reinforcing that it is a 'international attack on a number of countries and organisations'. Whilst this is true, it's probably also true that the impact of this attack is highly concentrated across organisations with chronic under-investment and a laissez-faire attitude to s…

In fairness, massive over-investment in NHS IT infrastructure hasn't gone so well either:

https://amp.theguardian.com/society/2013/sep/18/nhs-records-...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#302

Earlier quoted context omitted.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

He is not talking about the actual flaws as being the example as to why we shouldn't give the NSA backdoor access; he is saying that the leaks prove that even the NSA can't keep their stuff secret. If they couldn't keep their hacking tools secret, why should we think they can keep their backdoor access secret?

In case anyone has been living under a rock for the past 3 years:

FBI's (recently fired) James Comey has been asking for an encryption backdoor for the past 3 years:

2014: https://www.fbi.gov/news/speeches/going-dark-are-technology-...

At that time, he said unbreakable encryption should be illegal: http://www.newsweek.com/going-not-so-bright-fbi-director-jam...

2015 (asking for a backdoor): https://www.theguardian.com/technology/2015/jul/08/fbi-chief...

2016 (same): https://arstechnica.com/tech-policy/2016/03/fbi-is-asking-co...

2016 (tried to force apple to create a backdoor for the iphone): https://www.apple.com/customer-letter/

And then here recently, he's upped it to an international agreement to create a backdoor: https://www.techdirt.com/articles/20170327/10121437009/james...

He's not the first, only, or last person to ask for it.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#303

There's no evidence that this attack targeted the NHS or other health systems, right? Just spreading randomly by email, highest infection probabilities certain older Microsoft OSs?

This definitely wasn't targeted. Check here - https://intel.malwaretech.com/botnet/wcrypt/?t=24h&bid=all

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#304

Earlier quoted context omitted.

>To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The NSA has a specific mission to secure the nation's infrastructure. In witholding key information from US companies, it's failing that mission.

That's half the NSA's mission. Tt has another half and that is eavesdropping and getting into things. Those two missions are at odds with each other, and so the NSA has to make decisions about trade-offs. As these incidents show, the trade-offs the NSA has chosen to make have turned out to have been bad ideas.

This is why the NCSC was split from GCHQ in the UK. https://en.wikipedia.org/wiki/National_Cyber_Security_Centre...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#305
post #231

Earlier quoted context omitted.

I would be curious about this too. I'd assume many of them would be running Windows 7, maybe? (Let's hope it's not XP). Also, does Windows 10 Pro attached to a domain controller still have the same aggressive updates? Or do domain admins dictate that policy? At one company I worked at, everyone in IT could volunteer for the patch group to get security patches a few days before the rest of the machines. That seems to…

> Let's hope it's not XP BMJ released a report[0] just two days ago alleging that up to 90% of the NHS's computers are still running XP. > Many hospitals use proprietary software that runs on ancient operating systems. Barts Health NHS Trust’s computers attacked by ransomware in January ran Windows XP. Released in 2001, it is now obsolete, yet 90% of NHS trusts run this version of Windows. [0] http://www.bmj.com/cont…

https://m.theregister.co.uk/2012/01/12/drone_consoles_linux_...

Military drones were using XP until they just had too much spyware on the machines to operate the drones.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#306

Earlier quoted context omitted.

It appears the Theresa May is trying to deflect attention from the fact that there has been massive under investment in NHS IT infrastructure by reinforcing that it is a 'international attack on a number of countries and organisations'. Whilst this is true, it's probably also true that the impact of this attack is highly concentrated across organisations with chronic under-investment and a laissez-faire attitude to s…

In fairness, massive over-investment in NHS IT infrastructure hasn't gone so well either: https://amp.theguardian.com/society/2013/sep/18/nhs-records-...

Fair point. Good example of death march project!

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#308

Earlier quoted context omitted.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

He has backups of his data. I personally use linux and my github repo is here[1] where i have a bunch of encryption related projects(zuluCrypt,SiriKali and lxqt_wallet). The last windows computer i used was windows xp. I dont want to move him to linux because i am not always around and he can ask other people for help when he is on windows. [1] https://github.com/mhogomchungu

Are macOS or ChromeOS options?

Heck, some of my relatives are good with an iPad for 90% of their online activities.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#309

Going through their wallets it looks like they've gotten 32 pay outs, some for more than 300 USD. Are there any addresses that they are using outside of the four listed int he article? It'd be an interesting project to try and track where these funds go and where they came from. https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N... - 11 https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... - 4 htt…

where did you get these addresses from? I only get the 115p address on a retweeted photo from an NHS computer

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#310

Earlier quoted context omitted.

If you explicitly ask someone with the form "are there are organizations that are infalliable to leaks?" they're likely to say "no of course not. Humans make errors" But if you phrase it to something like "Can the government be trusted with backdoors to protect us from terrorists and Chinese hackers", then suddenly public sentiment will change dramatically.

To quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by feari…

> Patriotism is both a wonderful and terrible thing

I found that hypothesis widely accepted, without so much for it.

Patriotism fuses core values like freedom or solidarity with a flag. That's why it is easier to pervert.

Patriotism tells people that because there are people born in the same line limits that you, you should be proud of what they do, and you should help them first.

Patriotism distorts history.

> "Fourteen thousand years ago, Sweden was still covered by a thick ice cap." https://sweden.se/society/history-of-sweden/

Bullshit. Sweden didn't exist 14000 years ago. All history is learned as if the current countries were an inevitable result thousands of years ago. World history, human history, gets displaced to be able to build a national sentiment.

> "The colonial history of the United States covers the history of European settlements from the start of colonization until their incorporation into the United States of America" https://en.wikipedia.org/wiki/Colonial_history_of_the_United...

Again, we get that feeling of pre-determination. As if those people weren't free to choose their future as if they weren't individuals but just a means to create a country.

Patriotism narrows the mindset of populations. I don't see that usefulness. Anything that people does for patriotism will be better done for freedom, equality, fraternity, etc.

Why is patriotism a wonderful thing? What arguments am I missing?

Post reply on HN