One thing that strikes me with this malware is that it hits pretty much every single country. Don't hackers try to follow the proverbial "don't shit where you eat" proverb? They have nowhere to hide if they are identified now.
Lessons from last week’s cyberattack
81–90 of 304 posts
Re: Lessons from last week’s cyberattack
#82Earlier quoted context omitted.
No system is perfect. Remember Heartbleed? Microsoft released a patch to correct this particular issue in March, however the IT infrastructure in companies is slow, the whole process is convoluted, yada yada. The point is: the NSA caused this particular problem. Steps should be taken be everyone to ensure something like this doesn't happen ever again.
Just because the media (including Microsoft) tagged those projects (that were maintained by small groups of core develops and are free (unpaid) software) with fancy names - those problems weren't anything like the massive, global impact of just one of Microsoft's ticking timebombs due to poor software design and lack of emphasis on security in their products. OpenSSL doesn't and didn't have the PR powerhouse of Micro…
I assume you know nothing about software with flippant comments like this.
Completely securing software is an incredibly difficult thing to do and merely throwing resources isn't going to change that. It is just as likely to affect well designed software as it is poorly designed. Especially given that all of us rely heavily on third party libraries and underlying infrastructure.
Re: Lessons from last week’s cyberattack
#83Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.
Servers are much less vulnerable for a number of reasons:
1) People managing and configuring them are more security conscious than the vast majority people. Come on, nobody downloads an email attachment or connects an USB they found in the parking lot to a server.
2) It's much cheaper to keep a server updated than a thousand Windows clients.
3) Like whitefish pointed out, even in the worst case scenario you can restore a backup and keep on truckin'.
Re: Lessons from last week’s cyberattack
#84Earlier quoted context omitted.
Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…
> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…
But they are much hated.
Re: Lessons from last week’s cyberattack
#85Why not use Linux or MacOS?
Re: Lessons from last week’s cyberattack
#86Earlier quoted context omitted.
Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…
how much do you think it would cost Microsoft to support XP forever?
At some point companies need to cough up the money and upgrade their technology.
Re: Lessons from last week’s cyberattack
#87Earlier quoted context omitted.
And who do we fine for all the bugs in Open Source software then. The most serious vulnerabilities of late have all been in Open Source packages: - ShellShock - Heartbleed - etc Do we fine the person who committed the faulty logic, the reviewers, the entire community who "peer reviewed" it?
I'd be happy enough to go with "you fine whoever wrote the invoice or cashed the cheque". You wanna sell it? Take responsibility for it. You scratch your own itch and give it away for free? Good on you.
If I give away "free lemonade", but people get sick because I've made it in dirty conditions, I will not get away just because it's free.
Re: Lessons from last week’s cyberattack
#88Earlier quoted context omitted.
> The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. The problem is corporate IT (or management) think they can create some sort of stable environment, driven by fear of having things break. Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app brea…
Organizationally they need to accept that they are operating in a dynamic and hostile ecosystem and that the risk of worms is higher than the risk of some random app breaking on a windows patch. Except it's not. The account used by the hackers has supposedly earned about 4 Bitcoins so far. Meanwhile, many people from home users to professional IT personnel can recall incidents where Windows Update has broken somethin…
Re: Lessons from last week’s cyberattack
#89Earlier quoted context omitted.
> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…
I'm not sure if you know, but Windows already has that - Metro apps (or whatever the name is now) are sandboxed and with a permission system. But they are much hated.
Most people wouldn't even know that they are sandboxed.
But we will see for sure with Windows 10S and its optional upgrade to Pro policy.
Re: Lessons from last week’s cyberattack
#90Earlier quoted context omitted.
how much do you think it would cost Microsoft to support XP forever?
There's a big argument for only releasing evergreen style software, and giving the middle finger to IT orgs that want more control