Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

81–90 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#81
post #66

Earlier quoted context omitted.

To be more specific, involuntary manslaughter. Which is broadly speaking an accident that occurred while committing a crime. Or due to some other negligence. We are still firmly in the territory of accident, regardless of the legal consequences.

You still get punished for it... That's the whole argument. Even it's an accident, it's not the same kind of accident as turning a corner and spilling coffee on them.

The thread is not about whether or not whoever did it gets punished. The question is whether or not it was accidental or if damaging Merck was an intentional act. Based on the evidence so far, it sure seems like damaging Merck was a result of negligence and not intentional.

Re: Merck’s NotPetya attack: Was it an act of war?

#82
post #67
post #55

Earlier quoted context omitted.

Espionage/sabotage is not a war crime https://ihl-databases.icrc.org/customary-ihl/eng/docs/v2_rul...

Informational war is not a espionage, nor sabotage. It similar to sabotage, but, unlike sabotage, it's done from withing territory of attacker. If someone will destroy a factory behind enemy line, then it's sabotage. If someone will launch a rocket from their country to factory in another country, then it's not. If it done by state military agency, then it's act of war. If it done by civilians without support of and…

Is there a legal basis for that argument or is that your opinion?

Re: Merck’s NotPetya attack: Was it an act of war?

#83
post #45

Yes it was. I think everyone from Five Eyes to private cyber-security experts have said this already for the past two years.

No, it wasn't. And this over-militarized diction of cybersecurity is dangerous. You want nation states to be bombing developers sitting in offices due to a perceived threat because this garbage rhetoric is how that happens.

Oh wait, here we are. Hope your bunker is ready! https://www.zdnet.com/article/in-a-first-israel-responds-to-...

Re: Merck’s NotPetya attack: Was it an act of war?

#84
post #50

Earlier quoted context omitted.

Just as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.

Laws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.

You're misinformed, laws of war do not prohibit intentionally not wearing uniforms, and the (many!) cases of war operations performed without uniform or wearing enemy uniforms (sometimes on large unit scale, e.g. in WW2) were not considered war crimes.

What may be the source of confusion is that the Geneva convention requires wearing uniforms... to get the protections afforded by Geneva convention. If your troops violate that requirement, then that means that if they're captured without uniforms, the enemy is free to not fulfil the prisoner of war treatment required by Geneva conventions, but summarily execute all of them as spies; which was also often the practical consequence in WW2 if such troops were cought. A parricular example may be the trial after WW2 of Otto Scorzeny and other officers for Nazi troops wearing USA uniforms during Operation Greif in Battle of Bulge, where they were acquitted on the claimed charges of war crimes because these actions were considered by the court as 'legitimate ruse of war'.

If I recall correctly, masquerading as Red Cross could be a war crime, there are specific provisions for that, but the international treaties do not prohibit to masquerade as civilians or enemy troops, or to perform all kinds of other misinformation.

For most members in most militaries, it's a legal requirement set by their command to wear uniforms - but it's a requirement that the commanders can alter if they deem it necessary.

Re: Merck’s NotPetya attack: Was it an act of war?

#85
post #79
post #58

Earlier quoted context omitted.

Probably. The whole time I was there, IT was a disaster. I did not know if the people at top were incompetent or they were just woefully underfunded like IT is in many companies. After a billion dollar loss, I would hope Merck came at it from both angles just to be sure. My favorite memory was a mandatory security training for all employees. They had a couple of slides on how to make a good password, and one recommen…

"correcthorsebatterystaple-style" Are you saying those are better than the 'keyboard encryption'? Because they're not, every password cracker has functionality to string dictionary words together in various permutations.

yes, it's mathematically better to have longer passwords than more complex character sets.

Dictionary has a lot of words. Even if you knew I chose 4 of them, gonna take you a little bit of time to get through those combos.

Re: Merck’s NotPetya attack: Was it an act of war?

#86
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

The fact that good is worse than perfect does not mean good is no better than bad.

Having every machine in the company three months out of date on critical security patches is just negligence. I'm surprised the insurance companies didn't take that tack.

Re: Merck’s NotPetya attack: Was it an act of war?

#87
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

> In a targeted attack, it's likely the foreign agency would be using a 0-day attack.

A targeted attack is also expensive and the victim would need to have something worth this kind of money and attention. "Nation state actor" just isn't a reasonable risk assumption for a great many organizations.

> The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data.

When the "nation state actor" comes looking for you with some motivation, all that and the air gap won't mean much. See Stuxnet.

Like J. Mickens said: "Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good pass-word and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT."

https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Re: Merck’s NotPetya attack: Was it an act of war?

#88
post #50

Earlier quoted context omitted.

Laws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.

You're misinformed, laws of war do not prohibit intentionally not wearing uniforms, and the (many!) cases of war operations performed without uniform or wearing enemy uniforms (sometimes on large unit scale, e.g. in WW2) were not considered war crimes. What may be the source of confusion is that the Geneva convention requires wearing uniforms... to get the protections afforded by Geneva convention. If your troops vio…

Masquerading as Red Cross can be a grave breach of Article 37 of the 1977 Additional Protocol I [0]

[0] https://ihl-databases.icrc.org/ihl/WebART/470-750111 (paragraph 3.f)

Re: Merck’s NotPetya attack: Was it an act of war?

#89
post #41

I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

Offline backups are about the easiest thing you can do, and they protect against pretty much everything. Air gaps are useful, but they're just a connection with unusually high latency. Network monitoring protects against zero-days.

Re: Merck’s NotPetya attack: Was it an act of war?

#90

Earlier quoted context omitted.

While patches would have helped in this specific case, that's only because Merck was collateral damage. In a targeted attack, it's likely the foreign agency would be using a 0-day attack. The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on critical data. But those practices are extremely rare in my experience. If I was on unfriendly terms with the US,…

> In a targeted attack, it's likely the foreign agency would be using a 0-day attack. A targeted attack is also expensive and the victim would need to have something worth this kind of money and attention. "Nation state actor" just isn't a reasonable risk assumption for a great many organizations. > The only way to protect against that is by reducing the OS monoculture, offline backups, and using network air gaps on…

Nation-state actors can be deterred by nation states. If Vova believes that CNAing someone in the US will cause the US to bankrupt him and/or the people whose support he requires to stay in power, he'll make damn sure this doesn't happen. As long as the US does not demonstrate this capability and willingness to use it, he'll continue to misbehave.
Post reply on HN