Author Topic: It's all in the spin  (Read 1586 times)

Hawkmoon

  • friend
  • Senior Member
  • ***
  • Posts: 27,258
It's all in the spin
« on: May 11, 2019, 12:22:28 PM »
https://baltimore.cbslocal.com/2019/05/10/fbi-investigating-baltimore-city-ransomware-attack/

Synopsis: Three days after a ransomware attack, the City of Baltimore's system is supposedly off-line but it's still being attacked by hackers. That should be impossible. I wonder what Baltimore's understanding of "off-line" is.

More to the point, the mayor says that “No city services have been affected. People were able to get their cars at the towing yard, people come in and pay in cash or money orders or they can mail their payments in. So all the city is functioning. We’re doing it a different way and the citizens of Baltimore are not being affected we just cannot get emails and those kinds of things,” Young said. “We are moving forward and citizens should not notice anything other than they have to come in and do things manually.”

So, let's recap:
  • City employees can't use their computers
  • The city has no e-mail communication
  • People can't make any sort of payments on-line, they have to pay by mail or physically walk in and pay by cash or money order
  • Obviously, any of these manual transactions can't be entered into the appropriate computerized records, so they all have to be logged manually and will have to be entered later, after the system has been cleared and restored

But "No city services have been affected." I think hizzoner the mayor needs to look up the definition of "affected."
- - - - - - - - - - - - -
100% Politically Incorrect by Design

WLJ

  • friends
  • Senior Member
  • ***
  • Posts: 28,246
  • On Patrol In The Epsilon Eridani System
Re: It's all in the spin
« Reply #1 on: May 11, 2019, 12:29:14 PM »
https://baltimore.cbslocal.com/2019/05/10/fbi-investigating-baltimore-city-ransomware-attack/

Synopsis: Three days after a ransomware attack, the City of Baltimore's system is supposedly off-line but it's still being attacked by hackers. That should be impossible. I wonder what Baltimore's understanding of "off-line" is.


My guess is that despite being being "offline" a virus or a similar program(s) left by the hackers is still in the network.
"Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us".
- Calvin and Hobbes

Hawkmoon

  • friend
  • Senior Member
  • ***
  • Posts: 27,258
Re: It's all in the spin
« Reply #2 on: May 11, 2019, 12:56:19 PM »
My guess is that despite being being "offline" a virus or a similar program(s) left by the hackers is still in the network.

I agree, but that begs the question: WTF has the city's IT department been doing for the three days since the attack manifested and they took the system off-line? And, if that's the explanation, then saying that "hackers are still accessing the system" isn't exactly an accurate description.
- - - - - - - - - - - - -
100% Politically Incorrect by Design

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,574
  • tinpot megalomaniac, Paulbot, hardware goon
Re: It's all in the spin
« Reply #3 on: May 11, 2019, 01:07:01 PM »
I agree, but that begs the question: WTF has the city's IT department been doing for the three days since the attack manifested and they took the system off-line? And, if that's the explanation, then saying that "hackers are still accessing the system" isn't exactly an accurate description.

Recovering from backup, securing stuff and probably rebuilding affected end user computers. 

Depends on how many computers got hit, from where, and what they're using for backup.

In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

WLJ

  • friends
  • Senior Member
  • ***
  • Posts: 28,246
  • On Patrol In The Epsilon Eridani System
Re: It's all in the spin
« Reply #4 on: May 11, 2019, 01:09:38 PM »
It can take some time to root out a virus, especially an unfamiliar, possibly custom coded, one even for the best experts on the matter.
Not to mention whatever code they may have inserted.
You can't always trust your backups being free of this stuff either.
"Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us".
- Calvin and Hobbes

Hawkmoon

  • friend
  • Senior Member
  • ***
  • Posts: 27,258
Re: It's all in the spin
« Reply #5 on: May 11, 2019, 08:04:49 PM »
Recovering from backup, securing stuff and probably rebuilding affected end user computers. 


I assumed that's what they were doing. It's what they should be doing. But, IMHO, that just doesn't square with "hackers are still accessing the system." If IT is rebuilding and disinfecting the system, it should be shut off from the external world, should it not? So how can hackers still be accessing the system?
- - - - - - - - - - - - -
100% Politically Incorrect by Design

Fly320s

  • friend
  • Senior Member
  • ***
  • Posts: 14,415
  • Formerly, Arthur, King of the Britons
Re: It's all in the spin
« Reply #6 on: May 11, 2019, 08:18:14 PM »
Baltimore?  Who hacks into Baltimore?  That's like breaking into Kmart.  It is depressing to admit to it.
Islamic sex dolls.  Do they blow themselves up?

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,574
  • tinpot megalomaniac, Paulbot, hardware goon
Re: It's all in the spin
« Reply #7 on: May 11, 2019, 09:22:25 PM »
I assumed that's what they were doing. It's what they should be doing. But, IMHO, that just doesn't square with "hackers are still accessing the system." If IT is rebuilding and disinfecting the system, it should be shut off from the external world, should it not? So how can hackers still be accessing the system?

You asked what they were doing.   What I mentioned could easily take that kind of time to do, depending on their systems, what they have for backup, imaging for user's computers, and how many people they have to work on it.  I've had to do this for a couple customers.  Yes, they're unlikely to have functioning systems until it's done.

The article was pretty vague, and was probably filtered through multiple layers of folks that don't know what they're talking about.

« Last Edit: May 12, 2019, 08:32:22 AM by lee n. field »
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

Ron

  • friends
  • Senior Member
  • ***
  • Posts: 10,881
  • Like a tree planted by the rivers of water
    • What I believe ...
Re: It's all in the spin
« Reply #8 on: May 11, 2019, 11:04:49 PM »
Baltimore?  Who hacks into Baltimore?  That's like breaking into Kmart.  It is depressing to admit to it.

As the kids say, LOL 😝
For the invisible things of him since the creation of the world are clearly seen, being perceived through the things that are made, even his everlasting power and divinity, that they may be without excuse. Because knowing God, they didn’t glorify him as God, and didn’t give thanks, but became vain in their reasoning, and their senseless heart was darkened. Professing themselves to be wise, they became fools.

Jamisjockey

  • Booze-fueled paragon of pointless cruelty and wanton sadism
  • friend
  • Senior Member
  • ***
  • Posts: 26,580
  • Your mom sends me care packages
Re: It's all in the spin
« Reply #9 on: May 12, 2019, 08:10:59 AM »
FYI, that is the acting mayor. The elected mayor of Baltimore is under investigation for fraud and is on a medical leave of absence, hiding during the investigation.
JD

 The price of a lottery ticket seems to be the maximum most folks are willing to risk toward the dream of becoming a one-percenter. “Robert Hollis”

Chester32141

  • friend
  • Senior Member
  • ***
  • Posts: 642
Re: It's all in the spin
« Reply #10 on: May 12, 2019, 09:16:44 AM »
FYI, that is the acting mayor. The elected mayor of Baltimore is under investigation for fraud and is on a medical leave of absence, hiding during the investigation.


She stepped down a couple days ago …  ;)
"The best argument against democracy is a 5 minute conversation with the average voter...... "

Photos
CBs Hawg Sauce


MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,733
Re: It's all in the spin
« Reply #11 on: May 12, 2019, 10:38:43 AM »
Is the ransomware attack easier to pull off?  I was just thinking if you are going to hack something, hack in a fake vendor and start billing the city.  Many of those big cities are so disorganized you could probably get paid for years without anyone noticing. 
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

Perd Hapley

  • Superstar of the Internet
  • friend
  • Senior Member
  • ***
  • Posts: 61,393
  • My prepositions are on/in
Re: It's all in the spin
« Reply #12 on: May 12, 2019, 11:52:32 AM »
It looks like some of you are taking "offline" to mean "not connected to the internet." I think they were saying that it's out of service, which is the older, but still common, meaning of the term.
"Doggies are angel babies!" -- my wife

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,574
  • tinpot megalomaniac, Paulbot, hardware goon
Re: It's all in the spin
« Reply #13 on: May 23, 2019, 08:51:11 AM »
Saw a news item yesterday.   Baltimore is still trying to get back up and running.
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.