Victoria Police cancel hundreds of speeding fines after WannaCry virus attack
theage.com.au
theage.com.au
You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole.
Many setups require certification which is void after modifications which may include system updates so it's not "the easiest thing to do". It needs to go through the certification process again.
Even without certification requirements it may not be as trivial as it looks at first to "just update OS" on every device.
The "easiest thing to do" is for the government to report holes just like everybody else does.
Isn't it kind of strange that the only ones that fail to report security issues are a) criminals and b) government?
This is irrelevant in this case. The infection happened months after the security holes had been made public and patches had been released. The same could have happened if the US government had immediately reported the security holes instead of keeping them secret.
> Many setups require certification which is void after modifications which may include system updates so it's not "the easiest thing to do". It needs to go through the certification process again.
That's seems like an utterly useless certification process then. Any certification worth its salt should refuse to certify a networked Windows computer that doesn't automatically install security updates, since things like this WILL happen.
> The department of justice said Victoria’s infection was not the result of a targeted attack, but was caused by a contractor mistakenly connecting infected hardware to cameras.
Some sources are calling this a USB stick, the Guardian is being a bit more cautious.
Technically this means if someone gets snapped and is desperate enough ( will lose job as a result of losing licence etc ) they can turn back and destroy the evidence.
This revealed that the actual image storage was in a hardened cased buried in the ground some distance from the camera.
I suspect though that these are older installs. And that newer ones, particularly those that issue tickets based on time between two cameras, are networked.
The NSA hoards vulnerabilities for the same reason
the military has guns.
Vulnerabilities are fundamentally unlike guns.Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity.
If wannacry was a gun, it'd be a gun that fired backwards and sideways at the same time as forwards, and you can't stop it firing once it's started, and sometimes it starts firing on its own.
Instead, intelligence agencies irresponsibly hold onto them. And so they get leaked at best, or at worst end up in the wrong hands.
As bug fixes are reverse engineered, in your example, the malware could be created just as it was, and the patches had been out for months and the affected machines had not been patched, so again -- what difference would it have made?
1. Analyze the update, determining what parts of the system it changes
2. Analyze how the system behaved before the update (i.e. find the vulnerability)
3. Find suitable parameters for the vulnerability to reliably work
4. Build a proof of concept exploit
5. Integrate it into your ransomware
Getting a working proof of concept from a leak saves you 4 out of 5 steps. If you are a financially motivated cyber criminal (and if you are distributing ransomware, you are), that can mean the difference between a waste of your time and a juicy return on investment.I'm not arguing against the development on Metasploit though, and neither do I want to make an argument against vulnerability research. Every time Tavis Ormandy takes a shower, an AV vendor runs for cover; and on Christmas each year, Karsten Nohl cancels the vacations for some legacy system developers. That's a good thing, because those guys report their findings. They push vendors to fix the vulnerabilities, and they improve the security of systems we all depend on, every day.
Governments should do the same thing. I am all in favor of investing more in vulnerability research, but we need a process of disclosure. Stockpiling vulnerabilities puts everyone at risk, with little benefits.
Circling back to Metasploit: Yes, it makes work easier for cybercriminals. But even just the knowledge that a vulnerability will be available as a module quickly may be enough to make some vendors think twice about not reacting to a disclosure email, whether it's from Project Zero, independent researchers, or (hopefully more often) government CERTs.
So are you arguing people going to discover these independently anyway, or not? Pick one and stick with it. You can't have it both ways...
Normally full disclosure happens after about 45 days (I'm not an expert, I don't know exactly) but in special cases the time is extended.
This would probably be considered as a special case as Microsoft exceptionally released updates to unsupported, old versions of Windows and the hole itself was critical.
Please note that WannaCry hit in mid May - not that long time ago.
Shadow Brokers Group public disclosure of stolen tools from NSA happened in April.
There would have been even less time if this was indeed a security researcher using a 30-45 day time period.
Personally I think most defences are rubbish, it is MAD, and the financial implications would be dire.
It reminds me of a classic line from Spies Like Us: "A weapon unused is a useless weapon."
#Except against dissidents.
It would be nice to see HN do some A/B testing. Divide viewers randomly into two bins: those who see posts in FIFO, vs those who see posts LIFO; see if there is correlation between which comments are upvoted.
Also, it may be that contentious comments push a thread comment rate up, more partisan opinions cause article upvoting too, collectively pushing the article up in rankings. Less emotive topics/replies let an article slide down into the bitbucket.
Not remotely the same thing. The Army hoards guns in case we enter a war and need them. The NSA hoards vulnerabilities so they can spend more time using them on our allies, fellow citizens, anf our enemies.
The key difference is that we can't make the enemies guns ineffective by accumulating even more guns. The NSA could weaken the enemy's vulnerability stockpile by aggressively chasing and releasing vulnerability information to vendors.
Nope! We know it's more complicated than that. But we think the NSA strikes the wrong balance between offense and defense. If you want to understand where people are coming from a little more you could start with some of Bruce Schneier's articles:
https://www.schneier.com/blog/archives/2016/08/the_nsa_is_ho...
https://www.schneier.com/blog/archives/2017/06/wannacry_and_...
... where, for example, Schneier proposes that NSA should keep vulnerabilities for no more than six months, based on how far ahead of adversaries it doesn't appear to be.
The general point Schneier tends to make is: we are a huge fat defensive target with limited offensive targets. Vulnerabilities hurt you in proportion to how much infrastructure you run; we run a lot. Sitting on a vuln so you can use it a dozen times, while powering your society with billions of machines that have the same vuln, is a bad tradeoff.
Unfortunately, for all 3 letter agencies of the world, the analogy may not be far fetched.
"Army is planning to grant exclusive rights to this potentially groundbreaking medicine–along with as much as $173 million in funding from the Department of Health and Human Services—to the French pharmaceutical corporation Sanofi Pasteur. "
https://www.thenation.com/article/the-government-created-thi...
Do vendors get a kickback from Microsoft to use Windows in systems that don't even have a display?
Otherwise I don't see why they would license Windows instead of using a no-cost BSD or Linux derived OS.
My guess is that maintenance of such systems is just much cheaper. Virtually everyone knows the Windows GUI.
Lots of people only "do Windows" so that's the choice they make for the company.
I presume that essentally it is a photo taking device that superimposes a date/time and detected speed (and maybe also OCR's the license plate).
More or less three or four pieces of data:
1) picture
2) date/time
3) speed
4) (maybe) OCR'ed liense plate number
If any of these items were encrypted it would be evident, and the following step (looking in a database for the ownere of the license plate number) would have returned a null result.
The only way for this to actually work (creating a wrong fine) would be if ONLY the license plate number was encrypted by Wannacry AND the encrypted string matched another existing license plate number.
NIPR - Unclassified DoD internet plus powerful defensive capabilities when traffic goes between the intranet and public internet.
SIPR - Private "internet" for military and defense contractors and such to allow for handling SECRET and below. Dedicated circuits.
JWICS - Like SIPR but for TS and SCI channels.
Then other dedicated networks for international partnerships which run on dedicated circuits and using sats.
o_O