6 ms·
Cite one virus thay crashed the supposed 10 or 100 million machines in 70 minutes. Just one.
by proveitbh 2y ago
Cite one virus thay crashed the supposed 10 or 100 million machines in 70 minutes.
Just one.
- orf 2y agoMicrosoft puts the count at 8.5 million computers. So, percentage wise, the MyDoom virus in 2004 infected a far greater % of computers in a month: which in the context of internet penetration, availability and speeds (40kb/s average, 450kb/s fastest) in 2004 was about as fast as it could have. So it might as well have been 70 minutes, given downloading a 50mb file on dial up would take way longer than 70 mins. To the smart people below: It’s clear to everyone that 70 minutes is not 1 month. The point is that it’s not a fair comparison: it would simply not have been possible to infect that many computers in 70 minutes: the internet infrastructure just wasn’t there. It’s like saying “the Spanish flu didn’t do that much damage because there where less people on the planet” - it’s a meaningless absolute comparison, whereas the relative comparison is what matters.
- lolilokol 2y ago[flagged]
- klijibbn 2y ago[flagged]
- smartpeoplebelw 2y agoThere's also orders of magnitudes more machines today than 20 years ago -- so it should be easier to infect more machines now than before, and yet no one can sight a virus that was as quickly moving and damaging as what crowdstrike did through gross negligence. Be better.
- orf 2y agoThis entire thread is stupid. Computer security as a whole has improved, whilst the complexity of interconnected systems has exponentially increased. This has made the barrier to entry for malware higher, and so means we no longer have the same historic examples of large scale worms targeting consumer machines that we used to. At the same time the financial rewards for finding and exploiting a vulnerability within an organisations complex stack have greatly increased. The rewards are coupled to the time it takes to execute on the vulnerability. This leads to what we have today: localised, and often specialised attacks against valuable targets that are executed as fast as possible in order to minimise the chance a target has to respond or the vulnerability they are exploiting to be burned. Of course the “smart people belw” must know this, so it’s unclear why they are pretending to be dumb.
- canureadno 2y ago[flagged]
- orf 2y agoYou’re not displaying a pattern of healthy behavior by creating numerous new accounts to try and provoke an argument on such a stupid point, without contributing anything of substance to the discussion.
- TeMPOraL 2y ago> This leads to what we have today: localised, and often specialised attacks against valuable targets that are executed as fast as possible in order to minimise the chance a target has to respond or the vulnerability they are exploiting to be burned. Yup, exactly that. So what I'm saying it, it's beyond idiotic to combat this with a kernel-level backdoor managed by one entity and deployed across half the Internet. If anyone manages to breach that, they have a way to make their attack much simpler and much less localized (though they're unlikely to be prepared to capitalize on that). A fuckup on the defense side, on the other hand, can kill everything everywhere all at once. Which is what just happened. It's a "cure" for disease that happens to both boost the potency of the disease, and, once in blue moon, randomly kills the patient for no reason.
- orf 2y agoBut now you run into the tragedy of the commons. The fact is that this does help organisations. Definitely not all of the orgs that buy Crowdstrike, but rapid defence against evolving threats is a valuable thing for companies. So, individually it’s good for a company. But as a whole, and as currently implemented, it’s not good for everyone. However that doesn’t matter. Because individually it’s a benefit.
- TeMPOraL 2y agoThat's right. Which is why I'm hoping that this incident will make both security professionals and regulators reconsider the idea of endpoint security as it's currently done, and that there will be some cultural and regulatory pushback. Maybe this will incentivize people to come up with other ideas on how to secure systems and companies, that don't look like a police state on steroids.
- 8organicbits 2y agoILOVEYOU is a pretty decent contender, although the Internet was smaller back then and it didn't "crash" computers, it did different damage. Computer viruses and worms can spread extremely quickly. > infected millions of Windows computers worldwide within a few hours of its release See: https://en.wikipedia.org/wiki/Timeline_of_computer_viruses_and_worms#2000s https://en.wikipedia.org/wiki/Timeline_of_computer_viruses_a...
- lolilokol 2y ago[flagged]
- smartpeoplebelw 2y ago[flagged]
- orf 2y agoIt’s quite unclear about what your point/agenda is here. Are you truly this unfamiliar with the topic? If so, why comment, and if not, then why comment? It takes about 1 search and 2 clicks to find an article posted less than 24 hours after the initial infection, quoting 2.5 million infected machines. https://www.theregister.com/2000/05/05/love_bug_mutates_faster_than/ https://www.theregister.com/2000/05/05/love_bug_mutates_fast... Try using Google next time instead of giving up at the first dead link you find :)
- echoangle 2y agoCan you explain why you find this idea of fast moving viruses so improbable? Just from the way the internet works, I wouldn’t be surprised if every reachable host could be infected in a few hours if the virus can infect a machine in a short time (a few seconds) and would then begin infecting other machines. Why is that so hard to imagine?
- SoftTalker 2y agoProper firewalling for one. "Every reachable host" should be a fairly small set, ideally an empty set, when you're on the outside looking in. And operating systems aren't that bad anymore. You don't have services out of the box opening ports on all the interfaces, no firewalls, accepting connections from everywhere, and using well-known default (or no) credentials. Even stuff like the recent OpenSSH bug that is remotely exploitable and grants root access wasn't anything close to this kind of disaster because (a) most computers are not running SSH servers on the public internet (b) the exploit is rather difficult to actually execute. Eventually it might not be, but that gives people a bit of breathing space to react. Most cyberattacks use old, unpatched vulnerabilites against unprotected systems combined with social engineering to get the payload past the network boundary. If you are within a pretty broad window of "up to date" on your OS and antivirus updates, you are pretty safe.
- echoangle 2y agoThe focus seems to have been the time limit though. All the reasons you mention are just that there aren’t even that many targets.
- deleted 2y ago[deleted]
- hello_moto 2y agoThe malware doesn't need to infect 100 million machines. It just needs to infect 200k devices to get to the pot: hundred million dollars of ransomware.
- TeMPOraL 2y agoIt's a trivial cost to pay if the alternative is CrowdStrike inflicting billions of dollars of damage and loss of life across several countries. (I expect this to tally up to double-digit billions and thousands of lives lost directly to the outages when the dust settles.)
- hello_moto 2y agoTrivial cost to pay from which side? The organization like MGM and London Drugs?
- nullindividual 2y agohttps://www.caida.org/catalog/papers/2003_sapphire/ https://www.caida.org/catalog/papers/2003_sapphire/ [SQL] Slammer spread incredibly quickly, even though the vulnerability was patched in the prior year. > As it began spreading throughout the Internet, it doubled in size every 8.5 seconds. It infected more than 90 percent of vulnerable hosts within 10 minutes. Worms are not technically viruses, but they can have similar impacts/perform similar tasks on an infected host.
- smartpeoplebelw 2y agoYou are off by several orders of magnitude Also keep in mind 8.5 million is likely the count of machines fully impacted and are not counting the machines impacted but were able to be automatically recovered.
- nullindividual 2y ago> You are off by several orders of magnitude Can you cite something? This is HN, not reddit. > Also keep in mind 8.5 million is likely the count of machines fully impacted and are not counting the machines impacted but were able to be automatically recovered. Do you have evidence of this? Please bring sources with you.
- canureadno 2y ago[flagged]