Live data from Hacker News

Iran-backed hackers claim wiper attack on medtech firm Stryker

krebsonsecurity.com

301–310 of 342 posts

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#301
post #27

Never add your personal device to a companies MDM…

I believe Android Work profile[0] would have limited the damage to the work profile rather than also impact the personal profile on a personal device. Does anyone know if this is correct? [0] https://www.android.com/enterprise/work-profile/

Exactly. BYOD cannot be wiped [0], neither on iOS, nor on Android. Only company-owned devices are affected.

edit: 0 - on iOS this means enrolled via User Enrollment

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#302
post #121

Patriot of Persia https://www.goodreads.com/book/show/12202123-patriot-of-pers... An important book to read. So many people think this started with the islamic revolution of the 70s. The meddling goes further in time.

Zionists have been meddling in the Middle East since their ideology was created in the late 1800s.

The current Middle East situation dates back to at least the second millenium BCE.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#303
post #221

If Intune wiped personal devices that’s a serious failure. BYOD setups are supposed to wipe only the work container, not the whole phone. Either those devices were fully enrolled in MDM without people realizing or someone pushed the wrong wipe policy during incident response. Would be good to see confirmation from affected employees.

This isn't true for iOS at least. You can include device erase capabilities in the MDM profile without enrolling as a managed device.

Apple introduced User Enrollment from iOS 13 onwards, which is the preferred way to do BYOD enrollments. This enrollment type does not support the erase capability.

What you mean is the device enrollment on non-supervised devices, however and to my knowledge, enterprises do not use this, or if they do, it is very rare. (edit: And if they do, it's apparently a grave mistake.)

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#304

Earlier quoted context omitted.

No, the extremely nasty Islamic Theocracy that runs Iran is fighting for its survival after killing 20,000 protestors. Iran police chief has said that anti-government protesters will be treated as 'enemies'. "And we will do to them what we do to an enemy. We will deal with them in the same way we deal with enemies," he added. https://www.rnz.co.nz/news/world/589307/iran-police-chief-sa...

Bombing the crap out of their country doesn't help normal Irianians though. It only helps Isreal. The Isrealies want a broken Iran in chaos, and the nasty Islamic Theocracy would prefer a bit of destruction to being overthrown by organized internal resistance. The Iranian regime was on it's way out. A government can't survive killing that many of its own people. But as has been shown many times, the average person wi…

I agree the attack is very stupid but it is very ironic that the Hamas attack on Israel on Oct 7 2023 helped get Trump elected.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#306

Earlier quoted context omitted.

Most companies are definitely NOT using Yubikeys. Did you work for Google? Nice man :) MFA in general had to be forced on companies, and then it is most often in software on a phone. Here are some rough numbers. google_workspace: total_active_users: "3 billion (includes free/consumer Gmail)" paid_business_customers: "11 million companies (2024)" paid_customer_growth: "+1 million companies in under 1 year (2023-2024)"…

I worked for Amazon they used the open source version of chrome os (chromium os). And mini PCs, I think this is the best setup, If I ever have to manage a company I will do this.

Ok good for you. Can you see now that most companies are not using Yubikeys?

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#307

Earlier quoted context omitted.

That is all well and good but how do you: - Ensure the machines are up-to-date and users are not just indefinitely postponing OS updates? - Same as above but with programs/software - How do you ensure correct settings configuration in terms of security? Say default browser, extensions, program access etc? - Re-image or reinstall the OS when there are issues or PC handover to another employee? Manually with a USB stic…

I hear zero-trust is a trendy buzzword at the moment, so let's apply the basic idea here: having a hard shell and a soft and chewy center is not a security posture that works, in practice. You need to harden at every level. RMM uber-admin credentials are the ultimate soft center: you compromise those, you can kill the entire IT infrastructure. The only alternative is to distribute access: have multiple smaller IT tea…

Can you like I did name a company or technology that works like this?

Companies use M365 or Gsuite. Go.

I can type words too but they dont mean anything.

"Make it good zero trust wowo"

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#308
post #122
post #92

Earlier quoted context omitted.

I don't see how Linux would prevent anything if company wants similar controls on their machines. Like tracking update status, forcing updates when needed, potentially wiping entire device when stolen and so on. Fault really is not the OS but the control corporate wants over their devices. And it does make some sense.

Indeed. You'd expect a corporate IT system to be able to ssh as root into all their devices. And the cloud is even worse: if you get hold of the right IAM role, you can simply delete everything! That does usually get locked behind proper 2FA, but it's not impossible to phish even experienced admins once in a while.

Compare to the Facebook global BGP breakage and the amount of hands-on authorization that needed to happen to recover.

And no, there are plenty systems you don't want to have root ssh on.

Mainframes require 4-eyes administration to do more nuanced "root" things than picking up a sledgehammer and physically smashing drives.

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#309

Does InTune have some sort of check that goes "if over 1% of devices are wiped within a certain timeframe, stop all new device wipe requests"? Seems like it should be a feature, especially if these kinda attacks pick up.

This raises the question: Are mass layoffs less frequent than a company's MS administrator account getting hacked?

Question the concept of mass layoffs?

Re: Iran-backed hackers claim wiper attack on medtech firm Stryker

#310

It appears personal devices were also impacted by this via Microsoft Intune. That app is presented to employees as a way to get their email/slack on their personal device without giving IT systems access to it. IT systems around the country say that they have no access to your personal data and there they can only block access to Intune apps. But the linked reddit thread[1] in this article notes personal devices gett…

MDM enrollment has colloquially meant your device could be wiped for the security|incompetency of your firm for quite some time.

[deleted]
Post reply on HN