Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

71–80 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#71
post #54
post #42

Earlier quoted context omitted.

I'm not familiar with their environment but depending on the software and vendors who support aspects of software, those patches may be held at their request. That is people like Rockwell, Emmerson, whatever, may not “release” a patch because it can have implications for GxP environments. So not saying this is the case, but there are times when that is the case and companies have to sit on fixes. However in these sit…

Unless you do development where a Windows patch could break a complex environment, most people in the workplace are always using all Microsoft products anyway so they should just be on auto-update. All it takes is for some IT manager to sit on a critical patch for too long. If auto-updates break your setup, then you could opt-out and be moved to a sandboxed environment where you still get patches but only after they…

If you’re in a large organization you do not want an auto-update to mess up something for 10,000+ people who are unable to work because the VPN or whatever other enterprise system/software stopped working.

I’ve seen enough issues this year with Azure and multi-factor sso being down. It makes me weary of Microsoft’s updates. Lots of customers screaming because they can’t access our portals.

Sometimes your vendors have to wait for Microsoft to fix something they broke which complicates it even more.

Re: Merck’s NotPetya attack: Was it an act of war?

#72
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

> One researcher told a colleague she’d lost 15 years of work.

Either IT or this person is grossly incompetent. Beyond patch policies, managing data this way is terrifying.

Re: Merck’s NotPetya attack: Was it an act of war?

#73
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

While patches would have helped in this specific case, that's only because Merck was collateral damage.

In a targeted attack, it's likely the foreign agency would be using a 0-day attack.

The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data.

But those practices are extremely rare in my experience.

If I was on unfriendly terms with the US, I'd use this as a case study on how to cripple the economy by taking advantage of the large monocultures created by lax IT in a hundred or so of the largest firms.

Re: Merck’s NotPetya attack: Was it an act of war?

#74
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

0days are precious and expensive. The odds of being targeted by one are incredibly low compared to those of being targeted by an exploit for which there is a patch.

Re: Merck’s NotPetya attack: Was it an act of war?

#75

Earlier quoted context omitted.

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

0days are precious and expensive. The odds of being targeted by one are incredibly low compared to those of being targeted by an exploit for which there is a patch.

True as that may be, let's keep in mind just how juicy of a target Merck is, being a gigantic multinational with a market cap roughly equivalent to the GDP of Portugal.

Re: Merck’s NotPetya attack: Was it an act of war?

#77
post #61
post #59

Earlier quoted context omitted.

In many cases unpatched systems automatically fail GxP by not being patched but pharmaceutical organisations still run operations like it's the 90s and they just don't acknowledge the problems. Have worked in pharma IT for 10 years.

I think the problem is that their vendors’ applications run like it's the ‘90s. Often the orgs will be waiting on a vendor’s patch to be released which has been qualified for the sec patch. This requirement is kind of dubious but if you patch before they release their patch you’re on your own.

You'd think so but most vendor security patches appear very quickly even for 90s style systems, the problem is almost always the customer's own processes. All vendors in the pharma business space maintain a dedicated support and patch team for all deployed and commercially supported products and or course charge customers for the privilege.

Re: Merck’s NotPetya attack: Was it an act of war?

#78

It's really an act of not being prepared. $1.7B? They should be able to destroy and rebuild their entire infrastructure in less than a day. Have tested backup and restore processes. Ideally have all users in VMs. I don't see how this isn't entirely Merck's fault.

You're living in a modern IT dreamworld if you believe that. The number of billion dollar companies out there with thousands of lines of VB6 code and Cobol on an AS/400 is a stupidly large number.

Re: Merck’s NotPetya attack: Was it an act of war?

#79
post #58
post #48

Earlier quoted context omitted.

Is this related? Merck has a new IT Head - joined on Nov 2018. The attack happened on Jun 2017 (i.e., 1.5 years earlier). Jim Scholefield - https://www.linkedin.com/in/jimscholefield/ Great pedigree: Nike, Coca Cola etc. [Edit] Seems to be: He will also have oversight of cyber-security – a big issue for the company after a ransomware attack in June 2017 brought the company to a grinding halt. Scholefield will be part…

Probably. The whole time I was there, IT was a disaster. I did not know if the people at top were incompetent or they were just woefully underfunded like IT is in many companies. After a billion dollar loss, I would hope Merck came at it from both angles just to be sure. My favorite memory was a mandatory security training for all employees. They had a couple of slides on how to make a good password, and one recommen…

"correcthorsebatterystaple-style"

Are you saying those are better than the 'keyboard encryption'? Because they're not, every password cracker has functionality to string dictionary words together in various permutations.

Re: Merck’s NotPetya attack: Was it an act of war?

#80
post #79
post #58

Earlier quoted context omitted.

Probably. The whole time I was there, IT was a disaster. I did not know if the people at top were incompetent or they were just woefully underfunded like IT is in many companies. After a billion dollar loss, I would hope Merck came at it from both angles just to be sure. My favorite memory was a mandatory security training for all employees. They had a couple of slides on how to make a good password, and one recommen…

"correcthorsebatterystaple-style" Are you saying those are better than the 'keyboard encryption'? Because they're not, every password cracker has functionality to string dictionary words together in various permutations.

Yes, they are (assuming the words are actually chosen at random).

The idea of "correcthorsebatterystaple-style" passwords is to randomly choose 4 words from a pool of about 2000 words. That gives about 11 bits of entropy per word, for a total of 44 bits.

With a 2-word "keyboard encryption", even if you choose the two words the same way, you only get 24 bits of entropy: 22 bits for the words plus 2 more bits for the choice of which direction to shift (up/down/left/right = 4 options = 2 bits).

Post reply on HN