Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

351–360 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#351

Earlier quoted context omitted.

Thank God for backups! And thank you for making sure people make backups. My mother is in a similar situation. She is an elementary school teacher, and has little time for unrelated endeavors like this. What time she does have, is spent in the garden, as it should be. Nevertheless, we are now seeing that the time-cost of closed source software, is greater than that of open-source software. My solution has been to pre…

How quickly some forget heartbleed. The solution to malware is obscurity. Have an OS that no one wants to break into, and you won't be broken into.

Quick, migrate to TempleOS!

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#352
post #338

Earlier quoted context omitted.

You don't have to worry about tumbling anymore. You can use XMR.to, Shapeshift.io, or Changelly.com over TOR to move funds directly into another another blockchain currency. So have fun following things around Bitcoin blockchain like some high tech sleuth, but thats a wild goose chase. I buy all my cryptocurrencies through those kind of services nowadays, because there's no risk or temptation to keep coins on custodi…

> I'm actually surprised that the ransomware isn't taking Monero directly yet as some exchanges have direct Monero/USD markets already. Buying Bitcoin is much easier

Marginally.

And the malware controllers can just as easily add instruction to users to shapeshift bitcoin to their Monero address

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#353
post #18

Earlier quoted context omitted.

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

> Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying. Unfortunately, I think the active hours period cannot be set to more than twelve hours, which is less than the time required for some surgical interventions. I can almost imagine it: OK everyone, ten-minute break while Windows installs its updates, this guy who's been on life support for the last ten hours can wait a lit…

Surgeries are scheduled in advance except for the most urgent procedures; most surgeons and surgical nurses don't work on weekends.

Surgeon workstations can absolutely be restarted once per month to install the monthly roll-up.

The article mentions patient records servers and receptionist computers being affected by the ransomware. Not life support equipment.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#354

I am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

There is at least one cryptolocker variant that supports Linux.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#355

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

You are right but I'm not pleased that your comment has hijacked all discussion on this article.

(Not that it's your fault, it's somewhat germane to the overall issue of government, I'm just whining)

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#357

Earlier quoted context omitted.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

Just make sure whatever email provider you use offers IMAP and use a client like Thunderbird to keep a local copy in sync. Back that up somewhere safe and you're fine. If you need good, fast search, use something like X1.

That will protect you from data loss, but not data theft.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#358
post #71

Maybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software. Here is the BBC news update about the NHS Cyber attack: "NHS trusts 'ran outdated software' Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated…

A simple patching policy would have fixed this

https://youtu.be/VjfaCoA2sQk Hitler rants about cloud security. Sorry couldn't resist...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#359
post #310

Earlier quoted context omitted.

To quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by feari…

> Patriotism is both a wonderful and terrible thing I found that hypothesis widely accepted, without so much for it. Patriotism fuses core values like freedom or solidarity with a flag. That's why it is easier to pervert. Patriotism tells people that because there are people born in the same line limits that you, you should be proud of what they do, and you should help them first. Patriotism distorts history. > "Four…

Patriotism can be a way to align the interests of a group ahead of those of the individuals in the group.

This can be a wonderful and terrible thing.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#360

Earlier quoted context omitted.

He is not talking about the actual flaws as being the example as to why we shouldn't give the NSA backdoor access; he is saying that the leaks prove that even the NSA can't keep their stuff secret. If they couldn't keep their hacking tools secret, why should we think they can keep their backdoor access secret?

In case anyone has been living under a rock for the past 3 years: FBI's (recently fired) James Comey has been asking for an encryption backdoor for the past 3 years: 2014: https://www.fbi.gov/news/speeches/going-dark-are-technology-... At that time, he said unbreakable encryption should be illegal: http://www.newsweek.com/going-not-so-bright-fbi-director-jam... 2015 (asking for a backdoor): https://www.theguardian.co…

The UK's doing it, http://www.theregister.co.uk/2017/05/04/uk_bulk_surveillance...
Post reply on HN