Earlier quoted context omitted.
If its really important. Airgap. Or VM-Wrapped with restore points. I completely understand that somebody does not want to upgrade into the warp-abyss-abomination of modern windows, especially if huge expenses software was written once, that needs backwards compatability or contains sensitive data. You can not use windows if you work for anything with sensitive data. In todays world the legacy is the good stuff. Just…
An airgapped system is one that's basically unusable because you can't communicate with other systems.
Oakland declares state of emergency due to ransomware attack
71–80 of 86 posts
Re: Oakland declares state of emergency due to ransomware attack
#72Earlier quoted context omitted.
I'm with you right up to the "infinitely more competent" line. The big thing that Microsoft and Windows have against them, is the crapshow that is all that they include on a standard installation. That said, from what I'm seeing, this is not really unique to Windows anymore. Seems everyone wants everything on the machine. So, yes, it is theoretically possible to setup all access rules correctly. But it is essentially…
What specifically does a modern Windows installation include that is inappropriate or insecure in terms of default services or access rules?
Next, the NTLMv2 authentication protocol is on by default and vulnerable to relay attacks and offline password guessing attacks. Plus: pass-the-hash vulnerable. Huge problem in corporate networks.
I'd argue the broadcast domain name resolution protocols like NBNS or mDNS are unsafe as well.
Disclaimer: if you were just talking about Windows on your home desktop PC, then yeah nevermind.
Re: Oakland declares state of emergency due to ransomware attack
#73I don’t get why any user has the ability to cause so much damage. Sure they can lock their own files out and need to restore from backup, but how can that knock out other departments, let alone things like email.
Privilege escalation in Windows Active directory domains is really easy. Securing a large corporate network is really hard. Especially on a tight budget.
Re: Oakland declares state of emergency due to ransomware attack
#74Earlier quoted context omitted.
I expect that pricing has made it so most all smaller places are these kinds of organizations. And the incentives are to keep it that way. As long as MS's PS team can make more money from one whale of a customer than they can supporting local districts, expect that this will remain. Such that I don't think it is excusable to say "if only they had paid the professional services."
> Such that I don't think it is excusable to say "if only they had paid the professional services." Would you apply the same logic to road infrastructure? Why hire those licensed engineers...
Re: Oakland declares state of emergency due to ransomware attack
#75Are they ever going to hold the leadership accountable for sleeping on the job ?
Re: Oakland declares state of emergency due to ransomware attack
#76Re: Oakland declares state of emergency due to ransomware attack
#77Earlier quoted context omitted.
A lot of organizations also don't have the money or processes in place to manage backups. It's a huge cost outlay and in cash strapped SLGs, it simply ain't happening - especially when any half decent talent can make way more money working remotely for companies that respect Engineering.
That sounds completely self-inflicted. What are they spending their money on? Not Oakland, but across the bridge, last I heard, 16 millions for a few tents [0]. [0] https://www.nbcbayarea.com/news/local/san-francisco-paying-1...
Re: Oakland declares state of emergency due to ransomware attack
#78Earlier quoted context omitted.
I love people that believe there exists a version of any operating system with C code on it, that can be deemed secure. https://en.wikipedia.org/wiki/Morris_worm
It is true that C does not protect against a class of errors related to memory safety, but it disingenuous to imply writing an OS in any other language will make it secure. At best, it will only reduce the porosity of the attack surface.
Not wearing seatbelts and helmets doesn't save everyone, so it is worthless to use them as a vain attempt to save human lives.
Re: Oakland declares state of emergency due to ransomware attack
#79It's been quite a few years since I did this kind of stuff for a living, so this may be an antiquated notion... "In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for an…
The article does not say anything about Oakland negotiating. They may just be in the "it takes some time" phase at the moment. Tapes are not exactly the fastest medium. Plus, you may want to determine the exact time at which you were compromised, or else you'll be restoring potentially tainted backups. Depending on how well you're organized that alone will take quite some time, especially considering that your logs m…
We’re using their immutable storage option, with a 60 day window with multiple rotation intervals, and just biting the bullet on the cost of cold storage vs archival because of how slow tape is.
I could definitely see a larger entity having significantly more data and the restoration process can’t even start until they finish triage. No point in restoring until you know the source of the intrusion or at least have a plan to prevent it from recurring.
Re: Oakland declares state of emergency due to ransomware attack
#80This sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set…
I love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your…