Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

451–460 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#451

Earlier quoted context omitted.

So your workstation is next to a bed and is attached to a machine which feeds a drip to keep a little girl alive and it gets your untested patch or whole OS upgrade and the dosage is increased or the driver stops and the patient dies. Only non-critical machines can just automatically apply software patches from Redmond (or anybody). This is not laziness or incompetence - only a few weeks ago military grade exploits f…

The IV drip machine is not plugged into the CoW (Computer on Wheels). That workstation is running a version of enterprise Windows primarily to allow the medical professional to view and update patient records. The IV drip machine is plugged into the wall, and is operated by buttons on the front.

In reality, a huge number of modern IV drip machines plug into the wall for power and get their network connectivity via 802.11. This is to allow remote configuration and status monitoring.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#452

The real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.

Wikileaks should have disclosed before dumping publicly.

Burning down the house to prove that there are fire safety issues is the wrong approach.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#454

Earlier quoted context omitted.

OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.

How widely is LibreSSL used, compared to OpenSSL?

Working fine on FreeBSD 10 for me, but it's not default yet as far as I know.

My thoughts on the matter are, this is all a pointless waste of time/effort, or otherwise said, an arms race of exploits/bugs that will go on and on and produce nothing of value, except justifying a military budget in various govs.

If they truly were doing their jobs and being of benefit, we wouldn't have the corruption we do, the paedo rings, the drug cartels etc.

To be secure, you have to beat the smartest people on the planet I would have thought, and unless you have a nation's resources, that's tricky. Tightening laws I'm not sure is the answer either, it feels like human nature expressed in Internet terms.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#455
post #403
post #399

Earlier quoted context omitted.

Should that apply only to NSA or also to the writers of e.g. Metasploit exploits?

NSA made a weapon with the purpose of harming someone. In court, intent matters.

So does being able to enforce it. No one is going to sue the US DoD and come out winning.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#456

It's not 12 nations.... it's all over the world...

Yes, 70+ countries.

Botnets don't care about countries. It's not an attack against 70+ countries, it's an attack against everyone on the internet.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#457
post #108

Earlier quoted context omitted.

Gotcha. So yeah, we're seeing it wake up. The first little increase (up to 600) was about the time the article was published.

Where are you seeing this? This isn't historical data.

Yeah it scrolls off to the left. So you came an hour after my comment and it was gone. Heck it was almost gone by my second comment.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#458

Earlier quoted context omitted.

The main one is to have _all_ machines patched through windows update. That is what will protect you. SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time. That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.

If you are working with SCCM and 20,000+ clients (computers), you will know that all machines will never be patched. It just does not happen. On any given large network there will always be a certain number of unpatched clients. There are a myriad of reasons for patching to fail, from advertisement errors to installation issues, to machines simply being offline (and later coming back online).

You are right that this is often the reality of things. Some systems also will just never be patched because the software running on them stops working if you do and the vendor cannot or will not provide an update that addresses this.

However, in such cases it becomes crucial to have e.g. proper network segmentation in place to help mitigate the risk.

Unfortunately, at this time, there are seldom perfect solutions when it comes to security and a patching scenario can only do so much. In this case, patches are available, but the day a ransomware starts using proper 0-day we'll see a different scenario play out.

It therefore remains important to also keep focus on the reduction of attack surface, and the reduction of software complexity, besides resolving individual technical vulnerabilities.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#459
post #439

Earlier quoted context omitted.

So you propose a separate, isolated network linking all the medical facilities, doctor's offices and private practices nationwide? Even the military doesn't do that for most of their offices. Also, the doctor's computer pretty much needs to interface with the system(s) that handles patient billing (and thus non-medical companies) and the system(s) that handle patient scheduling, reminders, etc.

> patient billing Not really an issue in the NHS, apart from the occasional non-resident foreign national. (The "fundholding" system does mean there's a certain amount of internal billing which the patient is never aware of, but the beating Bevinist heart of the free-at-point-of-use system is still in place)

Free-at-point-of use process tend to be ones that require integration with a billing service, namely, to send information about the performed procedures to whatever system is paying for them, no matter if it's some state agency, private insurance, or whatever else - that's what I meant by non-medical companies that would need to be on the network.

A private practice where everything is paid by the patient in full by cash or CC could do without any integration with external systems (just run a standard cash register), but as soon as someone else is paying for it, you generally need to link the doctor's office systems to that in some way.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#460

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

MalwareTech found the kill switch for WannaCrypt too. https://www.theguardian.com/technology/2017/may/13/accidenta... https://twitter.com/MalwareTechBlog/status/86318710471668531... https://twitter.com/MalwareTechBlog/status/86318907784311603...

MalwareTech wrote a blog about it: https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
Post reply on HN