Oakland declares state of emergency due to ransomware attack
41–50 of 86 posts
Re: Oakland declares state of emergency due to ransomware attack
#42Earlier quoted context omitted.
What specifically does a modern Windows installation include that is inappropriate or insecure in terms of default services or access rules?
Certainly a fair question, but a big part of the problem is I don't know the specifics of what is on a new installation anymore. Worse, I'm not sure where to find such a list. Just scanning on the things they are proud to list at https://learn.microsoft.com/en-us/windows/whats-new/windows-... , I'd be worried about Teams, Windows 365, and Widgets. I'd also be worried about all trial software that is on the machine. I…
Generally users in most enterprises are going to need instant messaging and online meeting tools, so if it's not Teams then it will be something else with an equivalent attack surface area. Windows 365 appears to be highly secure.
I'm not trying to defend Microsoft here. They have had many security flaws and there will be more to come. It's just not clear whether the alternatives are significantly better.
Re: Oakland declares state of emergency due to ransomware attack
#43Earlier quoted context omitted.
It's generally professional services that set up these deployments at scale. MS's PS team is extremely competent and does push best practices in my experience. The issue is organizations that cheap out and decide to have an IT Service Desk guy manage everything from deployment to network architecture to security - these are extremely hard problems that require a large team of SME, not a single guy doing the best he c…
I expect that pricing has made it so most all smaller places are these kinds of organizations. And the incentives are to keep it that way. As long as MS's PS team can make more money from one whale of a customer than they can supporting local districts, expect that this will remain. Such that I don't think it is excusable to say "if only they had paid the professional services."
Re: Oakland declares state of emergency due to ransomware attack
#44Earlier quoted context omitted.
Certainly a fair question, but a big part of the problem is I don't know the specifics of what is on a new installation anymore. Worse, I'm not sure where to find such a list. Just scanning on the things they are proud to list at https://learn.microsoft.com/en-us/windows/whats-new/windows-... , I'd be worried about Teams, Windows 365, and Widgets. I'd also be worried about all trial software that is on the machine. I…
Do the popular Linux distributions for both desktop and server environments provide such a list? Have Teams, Windows 365, or Widgets been used as attack vectors against real systems? Generally users in most enterprises are going to need instant messaging and online meeting tools, so if it's not Teams then it will be something else with an equivalent attack surface area. Windows 365 appears to be highly secure. I'm no…
I'd expect most attacks are still of the "what is your password" variety. That along with a giant shared drive that everyone just dumps everything into.
And I don't mean this as an offensive against just Microsoft. They are/were somewhat unique in the success they had with embrace/extend. That said, the blame almost as surely rests on typical "growth at all costs" mental model that is modern business.
Re: Oakland declares state of emergency due to ransomware attack
#45Earlier quoted context omitted.
I expect that pricing has made it so most all smaller places are these kinds of organizations. And the incentives are to keep it that way. As long as MS's PS team can make more money from one whale of a customer than they can supporting local districts, expect that this will remain. Such that I don't think it is excusable to say "if only they had paid the professional services."
You don't need professional services all the time, assuming you make sure to hire a large enough team of SMEs of your own, but a lot organization simply view tech as a cost center and try to spend almost nothing on it. That is the kind of issue City of Oakland faces (for everything btw - for example, starting salary for teachers in OUSD is $50k compared to $70-80k in the rest of the Bay Area). Also City of Oakland do…
I am concerned with "best practices" in our industry, though. Too many of them are not geared to wide adherence and have fantastically bad failure cases.
Re: Oakland declares state of emergency due to ransomware attack
#46Earlier quoted context omitted.
Certainly a fair question, but a big part of the problem is I don't know the specifics of what is on a new installation anymore. Worse, I'm not sure where to find such a list. Just scanning on the things they are proud to list at https://learn.microsoft.com/en-us/windows/whats-new/windows-... , I'd be worried about Teams, Windows 365, and Widgets. I'd also be worried about all trial software that is on the machine. I…
Do the popular Linux distributions for both desktop and server environments provide such a list? Have Teams, Windows 365, or Widgets been used as attack vectors against real systems? Generally users in most enterprises are going to need instant messaging and online meeting tools, so if it's not Teams then it will be something else with an equivalent attack surface area. Windows 365 appears to be highly secure. I'm no…
Yes, this is common. You are generally given the option at install how "minimal" you wish to go (do you even want a GUI installed, etc). These are often listed on the distributions website.
For example here is a few from Arch:
- Base (bare minimum) install: https://archlinux.org/packages/core/any/base/
- Base-devel (what you need to run makepkg): https://archlinux.org/packages/core/any/base-devel/
Re: Oakland declares state of emergency due to ransomware attack
#47Earlier quoted context omitted.
You don't need professional services all the time, assuming you make sure to hire a large enough team of SMEs of your own, but a lot organization simply view tech as a cost center and try to spend almost nothing on it. That is the kind of issue City of Oakland faces (for everything btw - for example, starting salary for teachers in OUSD is $50k compared to $70-80k in the rest of the Bay Area). Also City of Oakland do…
I clearly don't know all the specifics of their case. Such that, if you have closer information, I am not trying to gaslight you on what you know. I am concerned with "best practices" in our industry, though. Too many of them are not geared to wide adherence and have fantastically bad failure cases.
Random think tanks doing thought leadership on CNN or at Brookings will jack themselves off to the notion of "online warfare" and whatnot, but those guys can barely type, let alone write cohesive policy.
I've been on both sides of this - both in the policy making world and in the private sector tech world - and cases like Oakland keep happening in a daily basis everywhere and will keep happening forever.
Re: Oakland declares state of emergency due to ransomware attack
#48"In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for any apps running on servers; their data/databases would be backed up daily and the tapes/drives used for backup would be stored elsewhere.
What is this old guy missing? If a process like this were in place, nearly all of their data would be intact. Yes, it will take some time to do a full restore and you will be missing some amount of data that was created since the last backup. But it's survivable in many cases. And you're not negotiating with criminals.
Re: Oakland declares state of emergency due to ransomware attack
#49What crypto are Ransomware asking for these days? After all the Bitcoin mixers seem to be taken offline (have they?). Sorry, I'm kinda out of the loop and was wondering how these thugs were cashing their attacks.
Re: Oakland declares state of emergency due to ransomware attack
#50Earlier quoted context omitted.
I'm with you right up to the "infinitely more competent" line. The big thing that Microsoft and Windows have against them, is the crapshow that is all that they include on a standard installation. That said, from what I'm seeing, this is not really unique to Windows anymore. Seems everyone wants everything on the machine. So, yes, it is theoretically possible to setup all access rules correctly. But it is essentially…
It's generally professional services that set up these deployments at scale. MS's PS team is extremely competent and does push best practices in my experience. The issue is organizations that cheap out and decide to have an IT Service Desk guy manage everything from deployment to network architecture to security - these are extremely hard problems that require a large team of SME, not a single guy doing the best he c…