4 ms·
The NSA exploits matter because they would be one of the few orgs to have access to multiple zero days. Imagine wannacry paired with a drive by browser exploit.
by devopsproject 9y ago
The NSA exploits matter because they would be one of the few orgs to have access to multiple zero days. Imagine wannacry paired with a drive by browser exploit.
- tjoff 9y agoOf course, I meant that it didn't matter much in this particular case. Every news outlet as well as technical sites seems to agree that it was NSA that enabled this attack, but if it all boils down to users opening email attachments that's something else entirely.
- xg15 9y agoThe email attachment is the matchstick, the NSA has soaked everything in gasoline, so to speak. Thanks to the zero day, you need one person opening the attachment to infect every machine on the LAN. You're right about the point of home networks though. Some wild guesses: - Infected machines that are moved between networks - e.g. a laptop that's used in both public and a private networks BYOD-style. - The worm also didn't use broadcasts to spread but simply tried out all IP addresses in its subnet. So if an ISP isn't properly isolating its customers, the worm might spread from customer to customer behind the ISP's NAT. - People are actually that stupid and clicked on the attachment a lot.
- tjoff 9y agoEven without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. So, it would have been game over anyway. The main advantage of a quick attack is likely that if you opt to pay to decrypt you have more infected computers (and sure, laptops - but these details are not exactly game-changing).
- xg15 9y ago> Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. That kind would have been orders of magnitude slower though and again dependant on social engineering: The worm would have needed someone do download the executable from the NAS and run it - in the face of usual security practices and anti-virus software looking for exactly that kind of thing - for every single machine. Even then the executable would only have admin privileges at best and probably not even that. Compare that to the exploit which allowed the worm to execute code on every windows machine in the LAN, with system privileges and without any user interaction needed. I think the exploit increased both the speed and the likelihood of successful infection by an order that is game-changing: Even if an infection was spotted, by the time countermeasures could have been deployed, the damage had already been done. Because no social engineering was required, even machines with restricted user input or no input at all were at risk (e.g. information screens or specialized hospital equipment).
- tjoff 9y ago> The worm would have needed someone do download the executable from the NAS and run it... Well, by that time the NAS is lost so it is already game over anyway. Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup (which again, probably is the very same NAS)). It is an inconvenience, sure, but comparatively a minor detail.
- xg15 9y ago> Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup [...]) That's a very broad assertion. Maybe that's true in a setup where everyone uses thin clients, but in the usual case, there is still enough friction on Windows to using network shares that many people will have local copies of the files they work with. Also, a NAT is probably the fist thing you'd hook up to a backup - if you're not using a cloud service anyway. Finally, the workstation itself is absolutely important. If only the NAS were affected you could at least keep working with what's left. Some machines are also specialized, e.g. info screens, ATMs, PoS terminals, hospital equipment...