Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

51–60 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#51
post #14

Earlier quoted context omitted.

While I’m opposed to using legal terms to weasel out of an insurance claim, it’s an interesting question. If Russia deliberately dropped a bomb on Merck’s factory, it would unquestionably be an act of war. Likewise if they dropped a bomb on a neighboring plant and also accidentally destroyed Merck’s plant. But dropping a bomb on a facility in Ukraine, with equally destructive shrapnel destroying facilities all over t…

Dropping a bomb is not an act of war because of the target itself. It is because to do it you have to violate the country's whole security system and cause damage to the country's real state, which is an act of war, whereas to invade a company's cluster of computers you don't have to compromise the country's whole cybernetwork. It is interesting though to think about aftermath. If it is not an act of war, one can com…

>Dropping a bomb is not an act of war because of the target itself. It is because to do it you have to violate the country's whole security system and cause damage to the country's real state, which is an act of war, whereas to invade a company's cluster of computers you don't have to compromise the country's whole cybernetwork.

I would counter that you don't need to violate all of the US's defense to bomb Hawaii and we all know how that was received. So yes, a state sending assets to go destroy some other state's property within the borders of said state is generally considered an act of war. That said, details matter a lot and these situations are basically handled on a case by case basis.

Re: Merck’s NotPetya attack: Was it an act of war?

#52
post #14

Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…

While I’m opposed to using legal terms to weasel out of an insurance claim, it’s an interesting question. If Russia deliberately dropped a bomb on Merck’s factory, it would unquestionably be an act of war. Likewise if they dropped a bomb on a neighboring plant and also accidentally destroyed Merck’s plant. But dropping a bomb on a facility in Ukraine, with equally destructive shrapnel destroying facilities all over t…

>If Russia deliberately dropped a bomb on Merck’s factory, it would unquestionably be an act of war.

The US does this all the time and it is not labeled an act of war. The most famous incident is the Al-Shifa medical facility, but this is common practice in the "war on terror."

Re: Merck’s NotPetya attack: Was it an act of war?

#53

> One researcher told a colleague she’d lost 15 years of work. You're telling me that you had never backed up anything in the span of 15 years?

It could be that the backups were "online" and therefore also wiped out by the malware.

Re: Merck’s NotPetya attack: Was it an act of war?

#54
post #42
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

I'm not familiar with their environment but depending on the software and vendors who support aspects of software, those patches may be held at their request. That is people like Rockwell, Emmerson, whatever, may not “release” a patch because it can have implications for GxP environments. So not saying this is the case, but there are times when that is the case and companies have to sit on fixes. However in these sit…

Unless you do development where a Windows patch could break a complex environment, most people in the workplace are always using all Microsoft products anyway so they should just be on auto-update. All it takes is for some IT manager to sit on a critical patch for too long. If auto-updates break your setup, then you could opt-out and be moved to a sandboxed environment where you still get patches but only after they are verified. I remember when some vcredist patch broke a very expensive development suite. Despite all the engineers affected complaining to IT, it took them weeks to roll it back for us. In the mean time, we had figured out ways to debug the tool with Visual Studio, catch the error, and continue past it without crashing everything. The patch must have broke quite a lot of things because there was another one that came shortly after that seemed to avoid the problems.

Re: Merck’s NotPetya attack: Was it an act of war?

#55
post #50

Earlier quoted context omitted.

Just as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.

Laws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.

Espionage/sabotage is not a war crime https://ihl-databases.icrc.org/customary-ihl/eng/docs/v2_rul...

Re: Merck’s NotPetya attack: Was it an act of war?

#57
I really enjoyed this despite insurance usually being billed as dull. A few points I don't see anyone else making:

* Act of war is poorly defined (and gets more poorly defined by the year). Since insurers use this term and (I assume) wrote the contracts, any reasonable question over its definition should be interpreted in the insured favour. That's how most contract law works since otherwise the contract writer has a perverse incentive to make their contract language unclear and then argue definitions and technicalities. That's not just dishonest, it creates unnecessary uncertainty and excess court cases and those cost everyone.

* I was sort of amazed by mention of the presidents pronouncements as if they mattered. Do they matter legally? They shouldn't: presidents are in no way a reliable source of information on geopolitical matters. Quite the opposite, they have the most motive to lie and its literally often illegal to expose that (if an NSA employee leaked classified proof it was NOT the Russians, they'd be imprisoned under the espionage act). Leaving aside the current presidents reliability, Obama pronounced on the Sony hack, blaming North Korea. Almost 5 years later and no evidence has been produced and plenty of people doubt that. Its also worth noting that no president should be empowered to effectively decide billion (trillion?) dollar lawsuits without oversight or scrutiny, they're not kings after all.

* Finally I thought how adult and reasonable Lloyds' response was. Both in settling the claim (assuming they did so for a reasonable fraction of what was owed) and requiring explicit cyber policies going forwards. That's the act of a group that is reasonable and wishes to take a long term, useful, role in the economy. Any bozo can sell "insurance" policies and then quibble over ever claim, the result is people stop buying. But honouring your commitments and correcting yourself going forwards is exactly what we need in insurers. I wonder what can be done to get US Corporate structures to follow a similar model?

Re: Merck’s NotPetya attack: Was it an act of war?

#58
post #48
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

Is this related? Merck has a new IT Head - joined on Nov 2018. The attack happened on Jun 2017 (i.e., 1.5 years earlier). Jim Scholefield - https://www.linkedin.com/in/jimscholefield/ Great pedigree: Nike, Coca Cola etc. [Edit] Seems to be: He will also have oversight of cyber-security – a big issue for the company after a ransomware attack in June 2017 brought the company to a grinding halt. Scholefield will be part…

Probably. The whole time I was there, IT was a disaster. I did not know if the people at top were incompetent or they were just woefully underfunded like IT is in many companies. After a billion dollar loss, I would hope Merck came at it from both angles just to be sure.

My favorite memory was a mandatory security training for all employees. They had a couple of slides on how to make a good password, and one recommendation was to use "keyboard encryption". This is a technique to take a bad password like "ClevelandIndians" and shift the keys to the right (or other direction) to get "V;rbr;smfOmfosmd", a supposedly better password. I stood up at the Q&A time and "asked" how this meaningfully improved passwords given that it added at most two bits of entropy. I also responded to the "how was the training" survey with a recommendation to teach people correcthorsebatterystaple-style passwords instead. Colleagues who had been assigned to a later session said that a slide containing the XKCD comic had been inserted into the deck.

Re: Merck’s NotPetya attack: Was it an act of war?

#59
post #42
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

I'm not familiar with their environment but depending on the software and vendors who support aspects of software, those patches may be held at their request. That is people like Rockwell, Emmerson, whatever, may not “release” a patch because it can have implications for GxP environments. So not saying this is the case, but there are times when that is the case and companies have to sit on fixes. However in these sit…

In many cases unpatched systems automatically fail GxP by not being patched but pharmaceutical organisations still run operations like it's the 90s and they just don't acknowledge the problems. Have worked in pharma IT for 10 years.

Re: Merck’s NotPetya attack: Was it an act of war?

#60

Earlier quoted context omitted.

Did that military agency plan for it to damage Merck? Or was that an accident?

Are you serious? They planned to launch the equivalent of a digital bomb, knowing full well there would be plenty of collateral damage. Hell no it isn't an "accident" I will put it another way. I feel quite confident the 9/11 bombers did not know, or specifically target, my friends and acquaintances who died in those towers. Therefore, are you going to claim 9-11 was an accident? If I intend to rob a convenience stor…

Not arguing with you. But I think a digital bioweapon is a better analogy than a bomb. Since it spreads without control after release, like a... well... virus. If a country released a bioweapon somewhere and it affected "un-intended targets" there's going to be a lot of international problems with that.

I kind of feel, and I'm not going to pretend I'm an expert, that digital warfare should be treated closer to biological warfare than just your typical bombs and bullets kind. Generally, and holy shit I know someone is going to flip their shit for me saying this, but generally a regular bomb (not nuke) is an acute type of problem. After it goes off, it's GENERALLY harmless after that. Yes, structure collapse, contamination, gas leaks and other after effects. But not really more booms from the bomb. Weaponized ebloa can still make more people sick, not affected by the original release. Same with NotPetya and other cyber attacks. After deployed, it can affect more and more targets as time goes on.

Post reply on HN