Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

71–80 of 304 posts

Re: Lessons from last week’s cyberattack

#71
post #33

From the article: >A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. They stopped supporting Windows XP years ago, including with security updates. There are still around 100 million c…

How long should Microsoft be required to support XP? They extended the original support period TWICE. Why are customers entitled to support when they were informed prior to purchasing the product that support expired on a given date?

Maybe newer OS do not have any useful features for those customers? Maybe they are even worse for them because work slower, are not compatible with old drivers, contain spyware (telemetry)?

Re: Lessons from last week’s cyberattack

#72
post #10

One thing that strikes me with this malware is that it hits pretty much every single country. Don't hackers try to follow the proverbial "don't shit where you eat" proverb? They have nowhere to hide if they are identified now.

You're assuming it was released on purpose and worked on the intended scale, I'm not sure either are true.

Re: Lessons from last week’s cyberattack

#73

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

Maybe they should not have connected all of the computers across the country into a single network.

Maybe they should have kept their systems up to date instead of running XP.

Re: Lessons from last week’s cyberattack

#74
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

Well a US government agency in charge of US Security decided that keeping the US and its allies vulnerable. They definitively need to answer if the benefit was really worth it.

Re: Lessons from last week’s cyberattack

#75
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

> The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents.

The problem is corporate IT (or management) think they can create some sort of stable environment, driven by fear of having things break. Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app breaking on a windows patch.

Re: Lessons from last week’s cyberattack

#76
post #47
post #33

From the article: >A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. They stopped supporting Windows XP years ago, including with security updates. There are still around 100 million c…

They didn't leave Xp users out to dry. Remember those forced free windows 10 updates they pushed out? The xp support schedule was available from day one. These companies knew exactly what they were getting into. Microsoft even extended the support period for xp on several occasions. It's galling that we as software professionals see this as malfeasance by the entities running xp still. They've had close to a decade t…

I dont really have any opinion here but as a correction the "forced free windows 10 updates" only included Windows 8 and 8.1 not vista and XP.

Re: Lessons from last week’s cyberattack

#77
post #74

Earlier quoted context omitted.

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

Well a US government agency in charge of US Security decided that keeping the US and its allies vulnerable. They definitively need to answer if the benefit was really worth it.

How many times do people need to be told that XP machines should not be connected to the internet, especially if they're not keeping up with patches?

Re: Lessons from last week’s cyberattack

#78
post #53

Earlier quoted context omitted.

It'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.

Let's be clear on this. No matter how secure the operating system initially, if it stays unpatched then over time it will become more and more vulnerable as uncovered exploits go unfixed. The reason a machine might go unpatched is because it might support some critical hardware (eg medical) for which there is only one or two vendors and only a particular combination of HW and SW are supported (eg due to a specific cu…

True, but I'm sure there are a lot of cases where the OS wasn't updated because of the necessary investment to jump to a new Windows version.

Re: Lessons from last week’s cyberattack

#79
post #75

Earlier quoted context omitted.

MS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.

> The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. The problem is corporate IT (or management) think they can create some sort of stable environment, driven by fear of having things break. Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app brea…

Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app breaking on a windows patch.

Except it's not. The account used by the hackers has supposedly earned about 4 Bitcoins so far. Meanwhile, many people from home users to professional IT personnel can recall incidents where Windows Update has broken something that worked fine before. Up to and including installing a completely new version of Windows, force-fed to unwilling customers with intentionally-deceptive practices.

Re: Lessons from last week’s cyberattack

#80
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

> Instead what will happen is more tightening of the walled garden

You know what? I'm starting to get excited for the walled garden to get more walls.

Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applications and download my contacts list, all without my permission. We don't let web apps do that, because web app developers aren't trusted by default. We don't let mobile apps do that, because mobile app developers aren't trusted by default. Why on earth do we implicitly trust any executable file run on the desktop so much?

Telling users not to double click on executables is obviously not working. Even for experienced users I have no idea whether some random app on the internet is trustworthy. Its a reverse lottery. I also suspect ransomware like this one would have been slowed down if it needed explicit user permission to read & modify files on disk.

We even know what the sandbox should look like, because we have two working examples in the form of the web and mobile. And we have sandboxing support & APIs in most operating systems. We're just missing the UI part.

I'm imagining something like:

- All apps get signed by the developer (Lean on SSL? Not sure the chain here.)

- The app needs to request capabilities from the user, like on iOS. "App X by Y developer wants permission to read the files in your home directory". (/ Read your contacts / Register at startup / Take screenshots / Modify these files).

- Capabilities can be viewed and revoked at a system-wide level in the control panel / system preferences.

Post reply on HN