Armed Polite Society

Main Forums => Politics => Topic started by: Hawkmoon on May 11, 2019, 12:22:28 PM

Title: It's all in the spin
Post by: Hawkmoon on May 11, 2019, 12:22:28 PM
https://baltimore.cbslocal.com/2019/05/10/fbi-investigating-baltimore-city-ransomware-attack/

Synopsis: Three days after a ransomware attack, the City of Baltimore's system is supposedly off-line but it's still being attacked by hackers. That should be impossible. I wonder what Baltimore's understanding of "off-line" is.

More to the point, the mayor says that “No city services have been affected. People were able to get their cars at the towing yard, people come in and pay in cash or money orders or they can mail their payments in. So all the city is functioning. We’re doing it a different way and the citizens of Baltimore are not being affected we just cannot get emails and those kinds of things,” Young said. “We are moving forward and citizens should not notice anything other than they have to come in and do things manually.”

So, let's recap:

But "No city services have been affected." I think hizzoner the mayor needs to look up the definition of "affected."
Title: Re: It's all in the spin
Post by: WLJ on May 11, 2019, 12:29:14 PM
https://baltimore.cbslocal.com/2019/05/10/fbi-investigating-baltimore-city-ransomware-attack/

Synopsis: Three days after a ransomware attack, the City of Baltimore's system is supposedly off-line but it's still being attacked by hackers. That should be impossible. I wonder what Baltimore's understanding of "off-line" is.


My guess is that despite being being "offline" a virus or a similar program(s) left by the hackers is still in the network.
Title: Re: It's all in the spin
Post by: Hawkmoon on May 11, 2019, 12:56:19 PM
My guess is that despite being being "offline" a virus or a similar program(s) left by the hackers is still in the network.

I agree, but that begs the question: WTF has the city's IT department been doing for the three days since the attack manifested and they took the system off-line? And, if that's the explanation, then saying that "hackers are still accessing the system" isn't exactly an accurate description.
Title: Re: It's all in the spin
Post by: lee n. field on May 11, 2019, 01:07:01 PM
I agree, but that begs the question: WTF has the city's IT department been doing for the three days since the attack manifested and they took the system off-line? And, if that's the explanation, then saying that "hackers are still accessing the system" isn't exactly an accurate description.

Recovering from backup, securing stuff and probably rebuilding affected end user computers. 

Depends on how many computers got hit, from where, and what they're using for backup.

Title: Re: It's all in the spin
Post by: WLJ on May 11, 2019, 01:09:38 PM
It can take some time to root out a virus, especially an unfamiliar, possibly custom coded, one even for the best experts on the matter.
Not to mention whatever code they may have inserted.
You can't always trust your backups being free of this stuff either.
Title: Re: It's all in the spin
Post by: Hawkmoon on May 11, 2019, 08:04:49 PM
Recovering from backup, securing stuff and probably rebuilding affected end user computers. 


I assumed that's what they were doing. It's what they should be doing. But, IMHO, that just doesn't square with "hackers are still accessing the system." If IT is rebuilding and disinfecting the system, it should be shut off from the external world, should it not? So how can hackers still be accessing the system?
Title: Re: It's all in the spin
Post by: Fly320s on May 11, 2019, 08:18:14 PM
Baltimore?  Who hacks into Baltimore?  That's like breaking into Kmart.  It is depressing to admit to it.
Title: Re: It's all in the spin
Post by: lee n. field on May 11, 2019, 09:22:25 PM
I assumed that's what they were doing. It's what they should be doing. But, IMHO, that just doesn't square with "hackers are still accessing the system." If IT is rebuilding and disinfecting the system, it should be shut off from the external world, should it not? So how can hackers still be accessing the system?

You asked what they were doing.   What I mentioned could easily take that kind of time to do, depending on their systems, what they have for backup, imaging for user's computers, and how many people they have to work on it.  I've had to do this for a couple customers.  Yes, they're unlikely to have functioning systems until it's done.

The article was pretty vague, and was probably filtered through multiple layers of folks that don't know what they're talking about.

Title: Re: It's all in the spin
Post by: Ron on May 11, 2019, 11:04:49 PM
Baltimore?  Who hacks into Baltimore?  That's like breaking into Kmart.  It is depressing to admit to it.

As the kids say, LOL 😝
Title: Re: It's all in the spin
Post by: Jamisjockey on May 12, 2019, 08:10:59 AM
FYI, that is the acting mayor. The elected mayor of Baltimore is under investigation for fraud and is on a medical leave of absence, hiding during the investigation.
Title: Re: It's all in the spin
Post by: Chester32141 on May 12, 2019, 09:16:44 AM
FYI, that is the acting mayor. The elected mayor of Baltimore is under investigation for fraud and is on a medical leave of absence, hiding during the investigation.


She stepped down a couple days ago …  ;)
Title: Re: It's all in the spin
Post by: MechAg94 on May 12, 2019, 10:38:43 AM
Is the ransomware attack easier to pull off?  I was just thinking if you are going to hack something, hack in a fake vendor and start billing the city.  Many of those big cities are so disorganized you could probably get paid for years without anyone noticing. 
Title: Re: It's all in the spin
Post by: Perd Hapley on May 12, 2019, 11:52:32 AM
It looks like some of you are taking "offline" to mean "not connected to the internet." I think they were saying that it's out of service, which is the older, but still common, meaning of the term.
Title: Re: It's all in the spin
Post by: lee n. field on May 23, 2019, 08:51:11 AM
Saw a news item yesterday.   Baltimore is still trying to get back up and running.