Earlier quoted context omitted.
To be more specific, involuntary manslaughter. Which is broadly speaking an accident that occurred while committing a crime. Or due to some other negligence. We are still firmly in the territory of accident, regardless of the legal consequences.
You still get punished for it... That's the whole argument. Even it's an accident, it's not the same kind of accident as turning a corner and spilling coffee on them.
Merck’s NotPetya attack: Was it an act of war?
81–90 of 115 posts
Re: Merck’s NotPetya attack: Was it an act of war?
#82Earlier quoted context omitted.
Espionage/sabotage is not a war crime https://ihl-databases.icrc.org/customary-ihl/eng/docs/v2_rul...
Informational war is not a espionage, nor sabotage. It similar to sabotage, but, unlike sabotage, it's done from withing territory of attacker. If someone will destroy a factory behind enemy line, then it's sabotage. If someone will launch a rocket from their country to factory in another country, then it's not. If it done by state military agency, then it's act of war. If it done by civilians without support of and…
Re: Merck’s NotPetya attack: Was it an act of war?
#83Yes it was. I think everyone from Five Eyes to private cyber-security experts have said this already for the past two years.
Oh wait, here we are. Hope your bunker is ready! https://www.zdnet.com/article/in-a-first-israel-responds-to-...
Re: Merck’s NotPetya attack: Was it an act of war?
#84Earlier quoted context omitted.
Just as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.
Laws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.
What may be the source of confusion is that the Geneva convention requires wearing uniforms... to get the protections afforded by Geneva convention. If your troops violate that requirement, then that means that if they're captured without uniforms, the enemy is free to not fulfil the prisoner of war treatment required by Geneva conventions, but summarily execute all of them as spies; which was also often the practical consequence in WW2 if such troops were cought. A parricular example may be the trial after WW2 of Otto Scorzeny and other officers for Nazi troops wearing USA uniforms during Operation Greif in Battle of Bulge, where they were acquitted on the claimed charges of war crimes because these actions were considered by the court as 'legitimate ruse of war'.
If I recall correctly, masquerading as Red Cross could be a war crime, there are specific provisions for that, but the international treaties do not prohibit to masquerade as civilians or enemy troops, or to perform all kinds of other misinformation.
For most members in most militaries, it's a legal requirement set by their command to wear uniforms - but it's a requirement that the commanders can alter if they deem it necessary.
Re: Merck’s NotPetya attack: Was it an act of war?
#85Earlier quoted context omitted.
Probably. The whole time I was there, IT was a disaster. I did not know if the people at top were incompetent or they were just woefully underfunded like IT is in many companies. After a billion dollar loss, I would hope Merck came at it from both angles just to be sure. My favorite memory was a mandatory security training for all employees. They had a couple of slides on how to make a good password, and one recommen…
"correcthorsebatterystaple-style" Are you saying those are better than the 'keyboard encryption'? Because they're not, every password cracker has functionality to string dictionary words together in various permutations.
Dictionary has a lot of words. Even if you knew I chose 4 of them, gonna take you a little bit of time to get through those combos.
Re: Merck’s NotPetya attack: Was it an act of war?
#86I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…
Having every machine in the company three months out of date on critical security patches is just negligence. I'm surprised the insurance companies didn't take that tack.
Re: Merck’s NotPetya attack: Was it an act of war?
#87I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…
A targeted attack is also expensive and the victim would need to have something worth this kind of money and attention. "Nation state actor" just isn't a reasonable risk assumption for a great many organizations.
> The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data.
When the "nation state actor" comes looking for you with some motivation, all that and the air gap won't mean much. See Stuxnet.
Like J. Mickens said: "Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good pass-word and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT."
Re: Merck’s NotPetya attack: Was it an act of war?
#88Earlier quoted context omitted.
Laws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.
You're misinformed, laws of war do not prohibit intentionally not wearing uniforms, and the (many!) cases of war operations performed without uniform or wearing enemy uniforms (sometimes on large unit scale, e.g. in WW2) were not considered war crimes. What may be the source of confusion is that the Geneva convention requires wearing uniforms... to get the protections afforded by Geneva convention. If your troops vio…
[0] https://ihl-databases.icrc.org/ihl/WebART/470-750111 (paragraph 3.f)
Re: Merck’s NotPetya attack: Was it an act of war?
#89I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…
Re: Merck’s NotPetya attack: Was it an act of war?
#90Earlier quoted context omitted.
While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…
> In a targeted attack, it's likely the foreign agency would be using a 0-day attack. A targeted attack is also expensive and the victim would need to have something worth this kind of money and attention. "Nation state actor" just isn't a reasonable risk assumption for a great many organizations. > The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on…