6 ms·
At least three of their Annual Reports indicates they knew of the risk of attack. Has there been any Ransomware Attacks that don't involve Windows machines? "
by rpaddock 3y ago
At least three of their Annual Reports indicates they knew of the risk of attack.
Has there been any Ransomware Attacks that don't involve Windows machines?
"Risks Associated with Cyber Attacks
Even though TSMC has established a comprehensive internet
and computing security network, it cannot guarantee
that the Company’s computing systems which control or
maintain vital corporate functions ,such as its manufacturing
operations and enterprise accounting, would be completely
immune to crippling cyber attacks by any third party to
gain unauthorized access to its internal network systems,
to sabotage its operations and goodwill or otherwise. In
the event of a serious cyber attack, TSMC’s systems may
lose important corporate data and its production lines
may be shutdown indefinitely pending the resolution of
such attack. While TSMC also seeks to annually review and
assess its cybersecurity policies and procedures to ensure
their adequacy and effectiveness, it cannot guarantee that
the Company will not be susceptible to new and emerging
risks and attacks in the evolving landscape of cybersecurity
threats. These cyber attacks may also attempt to steal TSMC’s
trade secrets and other intellectual properties and other
sensitive information, such as proprietary information of the
Company’s customers and other stakeholders and personal
information of the Company’s employees. Malicious hackers
may also try to introduce computer viruses, corrupted software
or ransomware into the Company’s network systems to
disrupt its operations, blackmail it for regaining control of its
computing systems or spy for sensitive information. These
attacks may result in TSMC having to pay damages for its
delayed or disrupted orders or incur significant expenses
in implementing remedial and improvement measures to
enhance the Company’s cybersecurity network, and may also
expose the Company to significant legal liabilities arising from
or related to legal proceedings or regulatory investigations
associated with, among other things, leakage of customer or
third party information which TSMC has an obligation to keep
confidential. During 2017 and as of the date of this Annual
Report, the Company had not been aware of any material
cyber attacks or incidents that had or would expected to have
a material adverse effect on its business and operations, nor
had it been involved in any legal proceedings or regulatory
investigations related thereof.
In addition, the Company employs certain third party service
providers for TSMC and its affiliates worldwide with whom
the Company needs to share highly sensitive and confidential
information to enable them to provide the relevant services.
Despite that TSMC requires the third party service providers
to comply with the confidentiality and/or Internet security
requirements in its service agreements with them, there is no
assurance that each of them will strictly fulfill such obligations,
or at all. The on-site network systems of and the off-site cloud
computing networks such as servers maintained by such
service provider and/or its contractors are also subject to risks
associated with cyber attacks. If TSMC or its service providers
are not able to timely resolve the respective technical difficulties
caused by such cyber attacks, or ensure the integrity and
availability of its data (and data belonging to its customers
and other third parties) or control of its or its service providers’
computing systems, the Company’s commitments to its
customers and other stakeholders may be materially impaired
and its results of operations, financial condition, prospects and
reputation may also be materially and adversely affected as a
result." - https://investor.tsmc.com/static/annualReports/2017/english/pdf/e_11.pdf https://investor.tsmc.com/static/annualReports/2017/english/...
- indymike 3y agoFrom experience (was lead dev at company where sales let a bitlocker in and IT had mis-configured backup... which is normal for backup in most companies): It's all about what the infected machines can access. When my employer got hit, the problem was that there were many shared drives that the infected machines could access, and these were bitlockered. People would run programs off a shared drive, and get infected from that... then everything that machine had access to would get bitlockered. Backup was implemented where clients would push files to an open share and the share was backed up. The backups were bitlockered as a result. The shared drives were on a mix of linux and windows servers, and mac users that had shared folders the sales team could access had that data bitlockered. So, Windows was involved - it's how the bitlocker got in, but honestly, it was an emailed binary the salesperson ran that started the fun. Incidentally, the dev team (mix of Windows, Linux, Mac) was completely unaffected because we did not have any open shares, remote access was done with SSH. We used a backup system that ran as a pull, where the machine being backed up could not directly access the backup store, so safe. So yeah, Windows involved, but the damage was more about what infected machine had write access to on the network.
- api 3y agoThere have been ransomware attacks against vulnerable NAS devices, but yes it's mostly Windows. The biggest reason it's mostly Windows is not just worse security posture due to complexity but also that Windows is so popular in business, causing it to be the most aggressively attacked platform.
- wepple 3y agoI expect that to change over time. I personally expect man-in-the-browser attacks to start targeting SaaS application data. I suspect a secondary reason is that the way windows credentials and file shares are set up, you can really build one-size-fits-all malware that goes after creds and hashes in a fairly generic way.
- Grimburger 3y agoThere's a great Linux hardening guide that really made me question the common refrain about linux being more secure. Out of the box on many distros it's not particularly that safe, it's widespread usage in servers rather than desktops means it's more the sensible firewalling and lack of user installed apps that's giving it the appearance of security. Edit: the guide, first link is their rationale - https://madaidans-insecurities.github.io/guides/linux-hardening.html https://madaidans-insecurities.github.io/guides/linux-harden...