7 ms·
I remember a fed speaker in the 90s at Alexis hotel Defcon trying to rationalize their weirdly over-aggressive approach to enforcement by mentioning how hackers
by kyledrake 2y ago
I remember a fed speaker in the 90s at Alexis hotel Defcon trying to rationalize their weirdly over-aggressive approach to enforcement by mentioning how hackers would potentially kill people in hospitals, fast forward to today and it's literally the "security" software vendor that's causing it.
- emodendroket 2y agoNot like hackers haven’t done the same.
- Quarrelsome 2y agonothing like this scale. These machines are full blue screen and completely inoperable.
- toomuchtodo 2y agoThe problem is concentration risk and incentives. Everyone is incentivized to follow the herd and buy Crowdstrike for EDR because of sentiment and network effects. You have to check the box, you have to be able to say you're defending against this risk (Evolve Bank had no EDR, for example), and you have to be able to defend your choice. You've now concentrated operational risk in one vendor, versus multiple competing vendors and products minimizing blast radius. No one ever got fired for buying Crowdstrike previously, and you will have an uphill climb internally attempting to argue that your org shouldn't pick what the bubble considers the best control. With that said, Microsoft could've done this with Defender just as easily, so be mindful of system diversity in your business continuity and disaster recovery plans and enterprise architecture. Heterogeneous systems can have inherent benefits.
- mango7283 2y agoIf you have a networked hybrid heterogeneous system though now you have weakest link issue, since lateral movement can now happen after your weaker perimeter tool is breached
- toomuchtodo 2y agoA threat actor able to evade EDR and moving laterally or pivoting through your env should be an assumption you’ve planned for (we do). Defense in depth, layered controls. Systems, network, identity, etc. One control should never be the difference between success and failure. https://apnews.com/article/tech-outage-crowdstrike-microsoft-windows-7294e6c9356050cb095dad3353e9244c https://apnews.com/article/tech-outage-crowdstrike-microsoft... > “This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”
- philipwhiuk 2y agoWannaCry did about the same damage to be honest. To pretty much the same systems. The irony is the NHS likely installed CrowdStrike as a direct reaction to WannaCry.
- smsm42 2y agoThe difference is malware infection is usually random and gradual. CrowdStrike screwup is everything at once with 100% lethality.
- mttpgn 2y agoI want to agree with the point you're making, but WannaCry, to take one example, had an impact at roughly this scale.
- Scoundreller 2y agoI think recovering from this incident will be more straightforward than WannaCry. At large-scale, you don’t solve problems, you only replace them with smaller ones.
- deleted 2y ago[deleted]
- kube-system 2y agoComputers hit by ransomware are also inoperable, and ransomware is wildly prevalent.
- TeMPOraL 2y agoYes, but computers get infected by ransomware randomly; Crowdstrike infected large amount of life-critical systems worldwide over some time, and then struck them all down at the same time.
- kube-system 2y agoI'm not sure I agree, ransomware attacks against organizations are often targeted. They might not all happen on the same day, but it is even worse: an ongoing threat every day.
- TeMPOraL 2y agoIt's why it's not worse - an ongoing threat means only small amount of systems are affected at a time, and there is time to develop countermeasures. An attack on everything all at once is much more damaging, especially when it eliminates fallback options - like the hospital that can't divert their patients because every other hospital in the country is down too, and so is 911.
- p_l 2y agoRansomware that affects only individual computers died not get payouts outside of hitting extremely incompetent orgs. If you want actually good payout, your crypto locker has to either encrypt network filesystems, or infect crucial core systems (domain controllers, database servers, the filers directly, etc). Ransomware getting smarter about sideways movement, and proper data exfiltration etc attacks, are part of what led to proliferation of requirements for EDRs like Crowdstrike, btw
- TeMPOraL 2y ago
- olyjohn 2y agoNot like the security software has ever stopped it.
- p_l 2y agoA lot of security software, ranging from properly using EDRs like Crowdstrike to things like simply setting some rules in Windows File Server Resource Manager fooled many ransomware attacks at the very least
- rdtsc 2y agoAt least hackers let people boot their machines, and some even have an automated way to restore the files after a payment. CS doesn't even do that. Hackers are looking better and more professional if we're going to put them in the same bucket, that is.
- bostik 2y agoThe criminal crews have a reputation to uphold. You don't deliver on payment, the word gets around and soon enough nobody is going to pay them. These security software vendors have found a wonderful tacit moat: they have managed to infect various questionnaire templates by being present in a short list of "pre-vetted and known" choices in a dropdown/radiobutton menu. If you select the sane option ("other"), you get to explain to technically inept bean counters why you did so. Repeat that for every single regulator, client auditing team, insurance company, etc. ... and soon enough someone will decide it's easier and cheaper to pick an option that gets you through the blind-leading-the-blind question karaoke with less headaches. Remember: vast majority of so-called security products are sold to people high up in the management chain, but they are inflicted upon their victims. The incentives are perverse, and the outcomes accordingly predictable.
- MikePlacid 2y ago> If you select the sane option ("other"), you get to explain to technically inept bean counters why you did so. Tell them it’s for preserving diversity in the field.
- bostik 2y agoFunnily enough, a bit of snark can help from time to time. For anyone browsing the thread archive in the future: you can have that quip in your back pocket and use it verbally when having to discuss the bingo sheet results with someone competent. It's a good bit of extra material, but it can not[ß] be your sole reason. The term you do want to remember is "additional benefit". The reasons you actually write down boil down to four things. High-level technical overview of your chosen solution. Threat model. Outcomes. And compensating controls. (As cringy as that sounds.) If you can demonstrate that you UNDERSTAND the underlying problem, and consider each bingo sheet entry an attempt at tackling a symptom, you will be on firmer ground. Focusing on threat model and the desired outcomes helps to answer the question, "what exactly are you trying to protect yourself from, and why?" ß: I face off with auditors and non-technical security people all the time. I used to face off with regulators in the past. In my experience, both groups respond to outcome-based risk modeling. But you have to be deeply technical to be able to dissect and explain their own questions back to them in terms that map to reality and the underlying technical details.
- BuckRogers 2y agoI can't imagine why any critical system is connected to the internet at all. It never made sense to me. Wifi should not be present on any critical system board and ethernet plugged in only when needed for maintenance. This should be the standard for any life sustaining or surgical systems, and any critical weapons systems.
- vitaflo 2y agoI work for a large medical device company and my team works on securing medical devices. At least at my company as a general rule, the more expensive the equipment (and thus the more critical the equipment, think surgical robots) the less likely it will ever be connected to a network, and that is exactly because of what you said, you remove so many security issues when you keep devices in a disconnected state. Most of what I do is creating the tools to let the field reps go into hospitals and update capital equipment in a disconnected state (IE, the reps must be physically tethered to the device to interact with it). The fact that any critical equipment would get an auto-update, especially mid-surgery is incredibly bad practice.
- nothercastle 2y agoAll this stuff could easily be airgapped or revert to USB stick fail safe.
- mandevil 2y agoHave you ever tried to airgap a gigantic wifi network across several buildings? Has to be wifi because the carts the nurses use roll around. Has to be networked so you can have EMR's that keep track of what your patients have gotten and the Pharmacists, doctors, and nurses can interface with the Pyxis machines correctly. The nurse scans a patients barcode at the Pyxis, the drawer opens to give them the drugs, and then they go into the patient's room and scan the drug barcode and the patients barcode before administering the drug. This system is to prevent the wrong drug from being administered, and has dramatically dropped the rates of mis-administering drugs. The network has to be everywhere on campus (often times across many buildings). Then the doctor needs to see the results of the tests and imaging- who is running around delivering all of these scans to the right doctors? You don't know what you are talking about if you think this is easy.
- zitterbewegung 2y agoWell cryptolockers have actually compromised various hospitals and I remember the first one was in the United Kingdom .
- londons_explore 2y agoDon't forget that nearly all crypto lockers are run by North Korea or other state espionage groups pretending to be North Korea. If we adjusted our foreign policy slightly, I think we would dissuade that whole class of attacker.
- kspacewalk2 2y agoIt's not like hackers haven't killed people in hospitals with e.g. ransomware. Our local dinky hospital system was hit by ransomware twice, which at the very least delayed some important surgeries.