Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

1–10 of 304 posts

Re: Lessons from last week’s cyberattack

#2
> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen. And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today – nation-state action and organized criminal action

Did the Microsoft President just confirm that NSA develop the vulnerability which led to the attacks on hospitals this weekend?!

Re: Lessons from last week’s cyberattack

#3

> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused wid…

I thought that the NSA itself informed Microsoft after EnternalBlue was stolen?

Re: Lessons from last week’s cyberattack

#4

> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused wid…

This is public knowledge at this point.

Re: Lessons from last week’s cyberattack

#5

> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused wid…

> An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen

This is a bad analogy. The solution to people stealing your Tomahawks is to guard your goddamn bombs. A better analogy would be the U.S. military seeing Al Qaeda has a bunch of Tomahawks and doing nothing because they might be aimed at ISIS.

Re: Lessons from last week’s cyberattack

#6
post #4

> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused wid…

This is public knowledge at this point.

Citation please?

Re: Lessons from last week’s cyberattack

#7
> We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits.

This whole incident is really raising the profile of the creation of "cyber weapons".

They aren't like physical weapons with physical controls -- they are digital, controls and costs to copy/distribute are more like digital music than anything a Goverment organization is used to.

Re: Lessons from last week’s cyberattack

#8

> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused wid…

"Did the Microsoft President just confirm that NSA develop the vulnerability "

Where did he do that? He said they found it and kept it for themself, but not that they injected it into Windows.

And about the whole thing, I would rephrase it to "many users learned the hard way about why are security-updates important".

But it is nice, that microsoft advocates a " digital genvue convention" even though I doubt anything will really change.

Re: Lessons from last week’s cyberattack

#10
One thing that strikes me with this malware is that it hits pretty much every single country. Don't hackers try to follow the proverbial "don't shit where you eat" proverb? They have nowhere to hide if they are identified now.
Post reply on HN