(Source) https://twitter.com/Moohten/status/863126339888480256

 

An article from the Nikkei newspaper titled “Cyberattack That Was Bound to Happen After Warnings Were Ignored”1 came across my feed. It contains the following passage.

Of course, the primary responsibility lies with Microsoft in the United States. This is because it sold the Windows operating system targeted in this attack and has been criticized for security flaws for many years.

No, the primary responsibility lies not with Microsoft, but with the organizations that continued using the software after support ended and those that failed to apply patches even when they were released. This kind of irresponsible shifting of blame is putting the public at risk.

It is long past time to understand that purchasing software does not mean buying and owning it like physical goods; it merely means acquiring the right to use it for a certain period. Software providers, too, might want to consider supplying software in a form that stops working when support ends.

The article above cites the example of the United Kingdom’s NHS (National Health Service) having to suspend operations. Its equipment remained based on XP, for which support had ended long ago, and those systems were infected with WannaCry. With medical equipment, it is understandable that systems might remain on XP because the hardware does not support anything newer. But if it had been understood from the outset that the OS would stop working entirely when support ended, both medical institutions and equipment manufacturers would have responded, and I think they would have budgeted for it from the beginning.

I also think the continued, drawn-out use of unsupported software such as XP in cases like this is based on the myth that a network is safe if it is disconnected from the Internet. Even if people believe they have isolated a network, in most cases it has not remained isolated when viewed over time, so they fail to understand that perimeter security is no longer sufficient. This attack, too, did not arrive by email. The apparent infection route was probably a computer that became infected while connected to the Internet through tethering or a similar method and then spread the malware when connected to the internal LAN. After all, no infections originating from email have been observed.

The minimum security standards that organizations must meet should be properly addressed as a matter of national policy. This is because it has already become a public safety issue. Countries should work together to establish the minimum security standards that must be met, just as they set CO2 emissions standards. Management systems such as ISMS allow organizations to set their own levels, so minimum standards may not be maintained, and they are too burdensome for small and medium-sized enterprises. It could be said that a simple checklist-based approach is needed.

Footnotes

  1. “Cyberattack That Was Bound to Happen After Warnings Were Ignored,” The Nikkei (2017-05-19) <http://www.nikkei.com/article/DGXMZO16510220X10C17A5000000/>

Related posts