Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

481–490 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#481
post #11

Earlier quoted context omitted.

If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…

Downloading Microsoft security updates is simple and safe. You just download the monthly rollup: http://www.catalog.update.microsoft.com/search.aspx?q=401221... Any competent sysadmin will have these available on their internal update server and push updates+restart during off-peak hours. Receptionist computers that can open websites with untrusted JavaScript can't reasonably be held to this certification. Certificat…

Some vertical markets use a lot of software that integrates with Microsoft Office applications. The result is that there is a much higher change of a Microsoft update breaking a critical application. [0] is a recent (September 2015) example of two Microsoft patches that were widely blocked in the legal industry until Microsoft released a follow up patch. iManage and Workshare, the products mentioned in the blog entry, are considered critical applications in any law firm that uses them. iManage is a widely used document management system (think primitive VCS with Office add-ins). All documents are stored in the DMS so access to it is critical to the business. Workshare is used for document comparison and metadata scrubbing. Metadata scrubbing is used on all outgoing emails.

[0] http://www.kraftkennedy.com/block-2-microsoft-patches-preven...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#482

Q: does anyone know how to disable regular internet access in Windows except through a virtual machine (VMware or Virtualbox)? I have set up my mom to use a live debian cd through VMware, but I would also like to disable networking through Windows Edge and Explorer. I don't know how to do this however. Myself, I follow a similar scheme but using a linux virtual guest and host. Is it easy to disable networking for all…

This site [1] discusses pretty much what you are asking (all networking going through a virtualbox pfSense) however it's written for windows 7, not sure if this still works for 8-10 http://timita.org/wordpress/2011/07/29/protect-your-windows-... I would think if you set up the VM to deny everything coming from windows, and allow anything coming from the other linux VM it should work fine (just set up multiple NICs in…

Hello. Thanks for this. This is very close to what I was looking for. Security is a long journey, but it seems we can't avoid the task any more.

Hopefully we will find a way to be connected but not vulnerable to all these threats.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#483

Medical offices are notorious for having machines out of date, not properly secured, and not backed up. Just recently I wanted to get test results from a few years earlier from a previous doctor. Nope, the machine they were on runs a proprietary GE setup and it crashed. The same test a few years earlier? The hospital lost them and had no record of them being done. A different test I had done a month ago was hooked up…

I recently went to a consultancy sales meeting with a GP who wanted me to port the MS Dos Patient Record Management system used by his medical centre to the cloud. While I'm sure with a suitable budget it could have been figured out the fact that I could only find a handful of references to the database file format when searching google didn't bode well. It looked like I would have to reverse engineer the parsing and…

You likely preserved your own sanity and theirs.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#484

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

What is the significance of the time span indicators? Does the 1M selection indicate how many computers remain infected or how many that were infected within that time span?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#485

Isn't it peculiar that Russia remains the least hit or not even hit at all? It seems like the West was a clear target. Connecting the dots here, it's suffice to say Shadow Brokers serves Russian interests. We are seeing bullet holes from what seem to have been cyber warfare between the former cold war foes.

According to Kaspersky, Russia was by far the worst hit: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

(Ukraine, India, and Taiwan were also unusually heavily affected.)

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#486
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

The computer systems affected by the NHS ransomware incident weren't medical devices; they were patient records servers and emergency receptionist workstations. No excuse for failure to patch.

Don't blame the NHS IT staff. The decision to not pay for XP security updates came from the highest level, the UK Tory government: https://www.benthamsgaze.org/2017/05/13/the-politics-of-the-...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#487
post #473

Earlier quoted context omitted.

I'd like to hear r/sysadmin opinion on that.

Translation: "My feelings make me feel that the statement isn't right. Instead of finding out, I'm just going to say that I wish someone would tell this commenter they're wrong."

Translation: "Microsoft has lied about the content of their updates before."

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#488

Earlier quoted context omitted.

This sounds like something straight out of a James Bond movie.

That was a dumb move by the malware coder ;) Wouldn't you want to hide a kill switch?

The MalwareTech write up gives a plausible reason for the developer having accidentally added the kill switch: > I believe they were trying to query an intentionally unregistered domain which would appear registered in certain sandbox environments, then once they see the domain responding, they know they’re in a sandbox the malware exits to prevent further analysis.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#489

Earlier quoted context omitted.

Just make sure whatever email provider you use offers IMAP and use a client like Thunderbird to keep a local copy in sync. Back that up somewhere safe and you're fine. If you need good, fast search, use something like X1.

That will protect you from data loss, but not data theft.

Data theft is a separate issue. Whether your using gmail, your own mail server or an account with your ISP; if you're machine is compromised all bets are off (including all your other files, not just email). At least with a backup you wont lose your data as a result of the theft.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#490
post #145

Earlier quoted context omitted.

The problem is that the technology stack required by modern equipment is too large to be satisfied by anything but a general-purpose OS. Good luck trying to get a mathematically proven OS.

Pretty sure you can build an X-Ray/MRI control software in Rust on top of seL4, and do lightweight verification (or, even better: hardware breakers of some sort) around issues like "will output lethal doses of radiation". That is a general purpose enough kernel and a general purpose enough programming language, without having to drag in tens of millions of lines of code intended for personal GUI systems... Then for m…

Rust has a lot of nice safety features, but the compiler hasn't been formally verified at all.
Post reply on HN