disclaimer: i hope no b/c it's like any other military tech being leaked and used, but am not sold either way.
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
381–390 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#382Earlier quoted context omitted.
Yes, it actually is. Life critical systems should be small, fully open stack, fully audited, and mathematically proven to be correct. Non-critical systems, secondary information reporting, and possibly even remote control interfaces for those systems should follow industry best practices and try to do their best to stay up to date and updated. Most likely many modern pieces of medical technology have not been designe…
Does this distinction between critical and non-critical systems make sense for medical equipment? Displaying the information to humans (doctors and nurses) is probably life-critical. If the display is broken, it's not working. It's not like medical devices have an entertainment system like cars and airplanes.
This is all doable, but it adds a bit of BOM cost and changes the development model.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#383Earlier quoted context omitted.
I disabled SMBv1 on the server. Good enough to protect our network share? Or is there some reason/benefit to disabling SMBv1 on client machines too? (I ran the simple powershell command on server: https://support.microsoft.com/en-us/help/2696547/how-to-enab... )
The main one is to have _all_ machines patched through windows update. That is what will protect you. SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time. That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#384While I can understand WikiLeaks position, I feel like it was incredibly short sighted and uninformed of them to release the code itself. Unless you believe that they are working with the Russian (and other?) governments to destabilize the west. Personally, I wouldn't be surprised if this was the case.
My impression was hat the Shadow Brokers already had, or were about to release the tools which Wikileaks ended up leaking. Regardless, these should've been disclosed to the manufacturers under Obama's policies.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#385> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…
If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…
There is such a thing as staged rollouts for this exact type of scenario.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#386Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#387In the US, you have to manage your own healthcare. Get every result as a hard copy or on disk (in the case of MRI etc) and save it yourself. And back it up. That way you're prepared.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#388> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…
Karen Sandler has an interesting story about medical devices and how they are, literally, putting her life on the line. She's both a lawyer and a hacker, and you should hear the stories she tells about how people distrust her for this and think she's trying to trick them when all she wants to do is learn about the software and hardware that is keeping her alive: https://www.youtube.com/watch?v=iMKHqO28FcI
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#389Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#390Earlier quoted context omitted.
Patriotism was temporarily necessary while we rapidly increased standard of living for ourselves, and didn't have enough resources to do it globally. In the early 21st century it was still a zero sum game on subdecade timescales. Now we have more than enough resources to provide basics for all 10 billion of us (and decreasing) so patriotism has largely been confined to friendly rivalry around sports and regional cuis…
16s? No Neuralink?