{"id":2567,"date":"2020-07-28T09:21:58","date_gmt":"2020-07-28T13:21:58","guid":{"rendered":"https:\/\/zzzptm.com\/wordpress\/?p=2567"},"modified":"2020-07-28T09:21:58","modified_gmt":"2020-07-28T13:21:58","slug":"good-morning-america-how-are-you-2","status":"publish","type":"post","link":"https:\/\/zzzptm.com\/wordpress\/?p=2567","title":{"rendered":"Good Morning America How Are You?"},"content":{"rendered":"\n<p>I wrote this back in December 2019. <\/p>\n\n\n\n<p>The city of New Orleans just got attacked and that made me think of the song about a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/train\">train<\/a>&nbsp;by the same name, whose chorus opens with that line&#8230; but this time, the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/question\">question<\/a>&nbsp;lacks the soft charm and slow nostalgia of Steve Goodman&#8217;s folk song. This time, the question is cold, jarring, unnerving. It&#8217;s not the first major US city to be attacked and made to be dark and it won&#8217;t be the last. The cities and other local&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/governments\">governments<\/a>&nbsp;of the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/usa\">USA<\/a>&nbsp;simply aren&#8217;t going to be able to deal with&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/cyberattacks\">cyberattacks<\/a>&nbsp;on their own, so they&#8217;re going to be target-rich environments for state actors and the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/criminals\">criminals<\/a>&nbsp;they hire to detonate hand grenades to cover their tracks&#8230; or just the criminals who blow things up, you never can tell.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,h_503.582,q_auto,w_507\/v1\/post-attachments\/The_City_of_New_Orleans_-_Arlo_Guthrie_vs6f58\" alt=\"\"\/><\/figure>\n\n\n\n<p>We can tell the cities and counties and states of the USA all we want about security and be met with the tired, nodding heads and empty eyes of IT&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/staff\">staff<\/a>&nbsp;that tried to tell the same message to their higher-ups. They know. They&#8217;re not idiots. They&#8217;re just faced with small budgets and political imperatives to get stuff done, no matter what. They know that when their town \/ county \/ state experiences a major&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/breach\">breach<\/a>, it will lead to the first time that entity seriously considered spending time and&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/money\">money<\/a>&nbsp;on security measures. It will lead to the first time IT is allowed to do what it knows needs to be done, even if it&#8217;s done on top of the rubble and ruin of the past.<\/p>\n\n\n\n<p>Do they have a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/perimeter\">perimeter<\/a>&nbsp;firewall? Sure, but there was the time somebody high up got mad about&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/traffic\">traffic<\/a>&nbsp;being blocked, so it&#8217;s set to permit all traffic by default. Do they have a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/datacenter\">datacenter<\/a>&nbsp;firewall? Yes, indeed, right here in this box in the storeroom. It is fresh and ready to go. Do they have&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/antivirus\">antivirus<\/a>&nbsp;running on every PC? Absolutely. Well, we can only tell for sure on PCs that have antivirus running on them&#8230; we don&#8217;t know about the ones that have fallen out of&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/communication\">communication<\/a>&nbsp;with our software maintenance platforms.<\/p>\n\n\n\n<p>Need I continue? Some of you are already at the point where you can bear the horror no more, but I must press on! You must see more, that you know the depths of their helplessness! Do you see the unsecured&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/internet\">Internet<\/a>&nbsp;line in that&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/office\">office<\/a>, terminating on a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/windows\">Windows<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/server-2009\">server<\/a>&nbsp;with&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/rdp\">RDP<\/a>&nbsp;running, no limit on&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/logon\">logon<\/a>&nbsp;attempts? Do you see the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/flat-network\">flat network<\/a>, with&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/telnet\">telnet<\/a>&nbsp;still running on&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/switches\">switches<\/a>&nbsp;and routers? Do you see massive file shares with no permissions set to halt normal&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/users\">users<\/a>&nbsp;from deleting or changing files? Do you see the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/backup\">backup<\/a>&nbsp;server that constantly fails its nightly&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/backups\">backups<\/a>, with the backup&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/operator\">operator<\/a>&nbsp;simply clicking through the errors on his shift because he was told long ago to just ignore them? Do you see the gear that all respond to the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/snmp\">SNMP<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/community\">community<\/a>&nbsp;&#8220;public&#8221;?<\/p>\n\n\n\n<p>And there is more horror in there, I say. I didn&#8217;t even get to the Windows NT 4.0 server that&#8217;s still on the network. Why? Well, the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/payroll\">payroll<\/a>&nbsp;application couldn&#8217;t upgrade to run on Windows 2000, so we keep it going on that server over there&#8230; and there is yet more, deeper and deeper into hell.<\/p>\n\n\n\n<p>Who knows what static routes&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/lurk\">lurk<\/a>&nbsp;deep within the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/network\">network<\/a>, routes that&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/bypass\">bypass<\/a>&nbsp;the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/firewall\">firewall<\/a>&nbsp;entirely for special&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ip-addresses\">IP addresses<\/a>&nbsp;in faraway lands where US lacks extradition rights? And are there programs on unsuspected and unsuspecting&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/systems\">systems<\/a>&nbsp;that are just counting down the days until the dust settles, things revert to normal, and the problems of the past make themselves available for mayhem once again? Clean up all you want, but what do you do if that payroll server on NT 4.0 is infected? The only person who can rebuild that system died 3 years ago. If it&#8217;s&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/infected\">infected<\/a>, maybe we can just put it behind a firewall and only open the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ports\">ports<\/a>&nbsp;needed for Windows and Active Directory. Oh wait, that&#8217;s all of them&#8230;<\/p>\n\n\n\n<p>So what is the solution? Is this where the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/federal-government\">federal government<\/a>&nbsp;steps in and supplements the IT budgets of local&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/government\">government<\/a>&nbsp;entities? Or would that lead only to swollen&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/management\">management<\/a>&nbsp;salaries with pittances spent on actual new technical hires? Is this where the feds create a system of&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/firewalls\">firewalls<\/a>&nbsp;to filter all traffic entering and leaving the nation, such as the Chinese do?<\/p>\n\n\n\n<p>Actually, that might be what we need. It wouldn&#8217;t do anything for completely&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/domestic\">domestic<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/attacks\">attacks<\/a>, but it could do at least something to halt attacks from outside the USA, right?<\/p>\n\n\n\n<p>Except&#8230; how do we know the difference between legitimate traffic from abroad and traffic with&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/malicious\">malicious<\/a>&nbsp;intent?&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/encryption\">Encryption<\/a>&nbsp;doesn&#8217;t allow one to peek into the packets very easily. Banning known bad source&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ip\">IP<\/a>&nbsp;addresses just leads to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/attackers\">attackers<\/a>&nbsp;compromising systems with other IP addresses and then launching attacks from there.<\/p>\n\n\n\n<p>But maybe the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/protection\">protection<\/a>&nbsp;is on the outbound side, with a massive&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/proxy\">proxy<\/a>&nbsp;server cutting&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/communications\">communications<\/a>&nbsp;with&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/scam\">scam<\/a>&nbsp;sites and other evil online in other countries. But for how long would the proxy server be protecting us only from&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/malware\">malware<\/a>&nbsp;and fraud? Wouldn&#8217;t&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/law-enforcement\">law enforcement<\/a>&nbsp;argue that we need to be protected from&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/terrorist\">terrorist<\/a>&nbsp;propaganda? How broad is that classification? Wouldn&#8217;t&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/entertainment\">entertainment<\/a>&nbsp;firms want to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/protect\">protect<\/a>&nbsp;us from&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/download\">download<\/a>&nbsp;sites? Would they also want to &#8220;protect&#8221; us from foreign entertainment outlets that didn&#8217;t allow them to act as middlemen brokers for their content? Would we also be &#8220;protected&#8221; from foreign news sources that didn&#8217;t go along with the administration&#8217;s views?&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/blocking\">Blocking<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/russian\">Russian<\/a>&nbsp;state news propaganda I wouldn&#8217;t mind, but I sure would mind if a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/cbc\">CBC<\/a>&nbsp;or BBC investigative journalism programme that was critical of a US firm or governmental&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/policy\">policy<\/a>&nbsp;was blocked.<\/p>\n\n\n\n<p>I hate to suggest this, as it&#8217;s highly exploitative, but we could allow recent grads to learn IT and then work for pathetic, near-volunteer wages for local government entities in order to pay off their student debts. I hesitate to introduce a scheme to offer pardons for nonviolent offenders that do pro bono IT work, since&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/fraud\">fraud<\/a>&nbsp;and cyberattacks are, themselves, nonviolent crimes&#8230;<\/p>\n\n\n\n<p>The City of New Orleans owns Louis Armstrong&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/international\">International<\/a>&nbsp;Airport. Did this recent&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/attack\">attack<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/penetrate\">penetrate<\/a>&nbsp;into the airport? Or was the firewall that is supposed to sequester it also permitting all traffic because there&#8217;s a full&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/trust\">trust<\/a>&nbsp;between its&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ad\">AD<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/domain\">domain<\/a>&nbsp;and the City&#8217;s? Or for some other reason, I don&#8217;t care. It&#8217;s all a nightmare, and when I wake up, there&#8217;s some shadow moving across my screen, saying, &#8220;g00d m0rn1ng 4m3r1c4, h0w r u?&#8221;<\/p>\n\n\n\n<p>I don&#8217;t know&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/how-to\">how to<\/a>&nbsp;answer that question. I normally don&#8217;t want to curse the darkness without lighting a candle, but I&#8217;m at a loss for answers to all the questions I asked. Cyberattacks can produce near-nuclear results, if done on a sufficient&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/scale\">scale<\/a>&nbsp;and with intent to destroy, not just&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/encrypt\">encrypt<\/a>&nbsp;and demand ransom. Perhaps lasers and hypersonic missiles can defend the USA from sudden attacks launched from bombers, ICBM&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/silos\">silos<\/a>, or&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/nuclear\">nuclear<\/a>&nbsp;submarines. What good are those against cyberattacks that target our highly&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vulnerable\">vulnerable<\/a>&nbsp;small government entities?<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I wrote this back in December 2019. The city of New Orleans just got attacked and that made me think of the song about a&nbsp;train&nbsp;by the same name, whose chorus opens with that line&#8230; but this time, the&nbsp;question&nbsp;lacks the soft charm and slow nostalgia of Steve Goodman&#8217;s folk song. This time, the question is cold, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2567","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2567"}],"version-history":[{"count":1,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2567\/revisions"}],"predecessor-version":[{"id":2568,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2567\/revisions\/2568"}],"wp:attachment":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}