International Monetary Fund Hit By Cyber Attack
DotNM writes "CityNews and other media outlets are reporting that the International Monetary Fund has been hit by a 'cyber attack.' They are withholding most of the details; however, it is known that the World Bank has shut down a 'link' between them and the IMF." Adds reader Hugh Pickens, "A cyber security expert told Reuters the infiltration had been a targeted attack, which installed software designed to give a nation state a 'digital insider presence' at the IMF. 'The code was developed and released for this purpose,' said Tom Kellerman, who has worked for the Fund. Bloomberg quoted an unnamed security expert as saying the hackers were connected to a foreign government — however, such attacks are very difficult to trace."
Not much info is given, but it looks like someone got an email, they clicked it and then got infected.
So the hack was really just an employee doing something.
IOW, the Chinese did it, and everyone is too fucking scared to point the finger.
Jesus was all right but his disciples were thick and ordinary. -John Lennon
> Bloomberg quoted an unnamed security expert as saying the hackers were connected to a foreign government
So this "unnamed security expert" sees the IMF as a (world?) government or as part of some (the american?) government.
Or what does the word "foreign" mean here?
How can the hackers be foreign if we're the *international* monetary fund?
You already lost the game, when you accepted belief instead of facts.
I, as a social engineer, would thrive on you, if I weren't on your side here.
Basically, you already did my job. All I would have to do, is feed you "news" about whatever reality I want you to believe in. Causing you to act, based upon that "reality". Resulting in whatever I want you to do. You'd even defend me against others, because your beliefs would be me.
Yes, "evil" just doesn't describe it anymore. And yes, that's why it's only acceptable for me, to do something good with it. (Like educate people about it.)
If you want to know what to think, look at this: Pierce’s cycle of scientific knowledge development.
Notice how it says "observation". Personal observation. And even that can deceive you. (Hence there are optical illusions and "magicans".)
But it's the best you've got. And rational thinking (logic is good, but they can't free you from emotions) does the rest.
Everything else, news, friends, books, me... are just external sources, and hence inherently can't give you any guarantees. You can choose to trust them. But then you also trust their agenda. As all they say, is for the purpose of that agenda. (That's not evil. It's just natural. Their agenda can also be something good to you.)
So make wise choices, and when in doubt, never ever "believe". :)
I actually laughed out.
The most secure computer is one that is not on the internet or networked to other computers. I am surprised BSG preaches that to the mainstream. Or that never sleep with robots.
A BSG ship must be one that must be managed by a team of sysadmins. If you can't network you must have one physical computer per subsystem.
sudo /etc/init.d/hyperdrive restart /etc/hyperdrive.conf
Password:
Core dump: Failed to restart, not aligned
Hint: Is antimatter callibrator powered and within frequency range?
vim
Slashdot needs Geekcode | Can anyone recommend any good SCIFI? My tastes: Foundation, Startide Rising, CITY, Ringworld,
Maybe the politicians will have to stop using their (our) national "credit cards" for a while. A few decades would be nice.
Remember Stuxnet? it was deliberately designed to infect machines that were not connected to the internet by jumping aboard USB thumb drives. Just not being connected to the net isn't enough, although it certainly helps isolate you from the vast majority of the attacks an outside force could try. If that machine is in contact with any other machines, in any way, it's possible to be compromised unless even greater security measures are implemented.
So the most secure machine is one that is not networked with any other machines, and is not allowed contact with any other machines, even vicariously through sharing files.
If you build it, nerds will come. Soylentnews.org
Nevermind, it turns out it was just Goldman Sachs trying to colocate their servers with the IMF computers...
And Americans = terrorist supporters.
e.g.
http://www.youtube.com/watch?v=3NUDWQ0U7N8
How many countries has the USA invaded recently? Whether you are better or worse than someone else is irrelevant. This is what you are.
Deleted
One example is that the IMF stopped Malawi from stockpiling grain, and many people died of starvation as a result:
"... when in 2001 the IMF found out the Malawian government had built up large stockpiles of grain in case there was a crop failure, they ordered them to sell it off to private companies at once. They told Malawi to get their priorities straight by using the proceeds to pay off a loan from a large bank the IMF had told them to take out in the first place, at a 56 per cent annual rate of interest. The Malawian president protested and said this was dangerous. But he had little choice. The grain was sold. The banks were paid.
The next year, the crops failed. The Malawian government had almost nothing to hand out. The starving population was reduced to eating the bark off the trees, and any rats they could capture. The BBC described it as Malawiâ(TM)s âoeworst ever famine.â There had been a much worse crop failure in 1991-2, but there was no famine because then the government had grain stocks to distribute. So at least a thousand innocent people starved to death.
Extracted from http://www.independent.co.uk/opinion/commentators/johann-hari/johann-hari-its-not-just-dominique-strausskahn-the-imf-itself-should-be-on-trial-2292270.html
Other examples: http://en.wikipedia.org/wiki/International_Monetary_Fund#Impact_on_access_to_food
This is the IMF. What's a foreign government, in that context...Martians?
For your security, this post has been encrypted with ROT-13, twice.
Why would a large organization always mean a country? Why not a large bank that wants to know in advance how much risk is really involved in lending money to Greece? Goldman-Sachs has been rumbeling in that area more than enough already.
Actually Stuxnet has been analyzed pretty well and would have attacked Windows XP, Windows Vista, and Windows 7 - no autoplay required. Remember the purpose of placing a USB key in one of these machines is to copy data from / to it because the machines aren't networked and the data has to be analyzed. In this case, a couple of zero day vulnerabilities were utilized that caused Windows to get infected by just opening the folder. Mark Russinovich did a nice, digestible 3 part write up on it that starts here: http://blogs.technet.com/b/markrussinovich/archive/2011/03/30/3416253.aspx.
I believe it was called "international jewry".
Seven puppies were harmed during the making of this post.
Which indicates that the systems were running Windows XP which is the only OS out there with the autorun "feature". If you're using a Windows OS to run critical industrial facilities then you really deserve to be hacked and have your facility shut down. This system was never intended to do that.
If you want a secure setup use a decent Unix variant to run your servers; you can even have them accessible from the outside if you know what you're doing.
That is false, I'm afraid.
A guy at IBM did an online presentation about that. Ubuntu, by default, comes with thumbnail generation activated by default when you insert a USB drive (no autorun, though). After that, he took advantage of a few shortcomings of PDF and video which, combined with this default conf, escalated his privileges all the way to root. Lost the video link, maybe other /.ers may help.
Conclusion: the choice of OS is not, by itself, a security measure. Servers running Windows can be secure, as you said, if you know what you're doing. I agree with you on that: don't put amateurs to manage your servers, be them Unix-like or Windows.
I rarely respond to comments. Also, don't ask for clarifications: a brain and Google are faster, believe me!