Earlier quoted context omitted.
So your workstation is next to a bed and is attached to a machine which feeds a drip to keep a little girl alive and it gets your untested patch or whole OS upgrade and the dosage is increased or the driver stops and the patient dies. Only non-critical machines can just automatically apply software patches from Redmond (or anybody). This is not laziness or incompetence - only a few weeks ago military grade exploits f…
The IV drip machine is not plugged into the CoW (Computer on Wheels). That workstation is running a version of enterprise Windows primarily to allow the medical professional to view and update patient records. The IV drip machine is plugged into the wall, and is operated by buttons on the front.
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
451–460 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#452The real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.
Burning down the house to prove that there are fire safety issues is the wrong approach.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#453Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#454Earlier quoted context omitted.
OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.
How widely is LibreSSL used, compared to OpenSSL?
My thoughts on the matter are, this is all a pointless waste of time/effort, or otherwise said, an arms race of exploits/bugs that will go on and on and produce nothing of value, except justifying a military budget in various govs.
If they truly were doing their jobs and being of benefit, we wouldn't have the corruption we do, the paedo rings, the drug cartels etc.
To be secure, you have to beat the smartest people on the planet I would have thought, and unless you have a nation's resources, that's tricky. Tightening laws I'm not sure is the answer either, it feels like human nature expressed in Internet terms.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#455Earlier quoted context omitted.
Should that apply only to NSA or also to the writers of e.g. Metasploit exploits?
NSA made a weapon with the purpose of harming someone. In court, intent matters.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#456Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#457Earlier quoted context omitted.
Gotcha. So yeah, we're seeing it wake up. The first little increase (up to 600) was about the time the article was published.
Where are you seeing this? This isn't historical data.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#458Earlier quoted context omitted.
The main one is to have _all_ machines patched through windows update. That is what will protect you. SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time. That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.
If you are working with SCCM and 20,000+ clients (computers), you will know that all machines will never be patched. It just does not happen. On any given large network there will always be a certain number of unpatched clients. There are a myriad of reasons for patching to fail, from advertisement errors to installation issues, to machines simply being offline (and later coming back online).
However, in such cases it becomes crucial to have e.g. proper network segmentation in place to help mitigate the risk.
Unfortunately, at this time, there are seldom perfect solutions when it comes to security and a patching scenario can only do so much. In this case, patches are available, but the day a ransomware starts using proper 0-day we'll see a different scenario play out.
It therefore remains important to also keep focus on the reduction of attack surface, and the reduction of software complexity, besides resolving individual technical vulnerabilities.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#459Earlier quoted context omitted.
So you propose a separate, isolated network linking all the medical facilities, doctor's offices and private practices nationwide? Even the military doesn't do that for most of their offices. Also, the doctor's computer pretty much needs to interface with the system(s) that handles patient billing (and thus non-medical companies) and the system(s) that handle patient scheduling, reminders, etc.
> patient billing Not really an issue in the NHS, apart from the occasional non-resident foreign national. (The "fundholding" system does mean there's a certain amount of internal billing which the patient is never aware of, but the beating Bevinist heart of the free-at-point-of-use system is still in place)
A private practice where everything is paid by the patient in full by cash or CC could do without any integration with external systems (just run a standard cash register), but as soon as someone else is paying for it, you generally need to link the doctor's office systems to that in some way.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#460Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...
MalwareTech found the kill switch for WannaCrypt too. https://www.theguardian.com/technology/2017/may/13/accidenta... https://twitter.com/MalwareTechBlog/status/86318710471668531... https://twitter.com/MalwareTechBlog/status/86318907784311603...