Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.security > #1323 > unrolled thread
| Started by | c186282 <c186282@nnada.net> |
|---|---|
| First post | 2025-10-16 03:39 -0400 |
| Last post | 2025-10-26 07:27 -0400 |
| Articles | 13 — 7 participants |
Back to article view | Back to alt.security
Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda c186282 <c186282@nnada.net> - 2025-10-16 03:39 -0400
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Tom Mix <tommix@dev.null> - 2025-10-17 13:32 +0000
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda c186282 <c186282@nnada.net> - 2025-10-17 21:47 -0400
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> - 2025-10-20 21:20 +0200
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Niocláisín Cóilín de Ghlostéir <Spamassassin@irrt.De> - 2025-10-20 21:33 +0200
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Tom Mix <tommix@dev.null> - 2025-10-20 19:52 +0000
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-10-20 20:47 +0000
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> - 2025-10-20 22:50 +0200
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-10-20 23:06 +0000
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda c186282 <c186282@nnada.net> - 2025-10-20 22:49 -0400
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda c186282 <c186282@nnada.net> - 2025-10-20 22:48 -0400
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Tristan Wibberley <tristan.wibberley+netnews2@alumni.manchester.ac.uk> - 2025-10-26 11:05 +0000
Re: Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda Chris Ahlstrom <OFeem1987@teleworm.us> - 2025-10-26 07:27 -0400
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-16 03:39 -0400 |
| Subject | Harrisburg PA - Airport PA System Hacked - Rude Anti-Semite Propaganda |
| Message-ID | <sE2dnTjUGeCFPG31nZ2dnZfqnPoAAAAA@giganews.com> |
https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html international airport's PA system is HACKED and plays anti-Israel message to travelers . . . Just to note, basically EVERY system of ANY kind can be hacked now. That includes all the infrastructure stuff, banking, govt, everything. Vlad and Xi are BUSY BEAVERS. Doing online, well, pretty much ANYTHING ? They CAN, soon WILL, get at it. I kind of envision Vlad and Xi as having a big shiny red button on their desks marked "Destroy West".
[toc] | [next] | [standalone]
| From | Tom Mix <tommix@dev.null> |
|---|---|
| Date | 2025-10-17 13:32 +0000 |
| Message-ID | <slrn10f4hbf.7947.tommix@devnull.org> |
| In reply to | #1323 |
On 2025-10-16, c186282 <c186282@nnada.net> wrote: > https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html > > international airport's PA system is HACKED and plays > anti-Israel message to travelers > > . . . > > Just to note, basically EVERY system of ANY > kind can be hacked now. That includes all > the infrastructure stuff, banking, govt, > everything. Vlad and Xi are BUSY BEAVERS. > > Doing online, well, pretty much ANYTHING ? > They CAN, soon WILL, get at it. > > I kind of envision Vlad and Xi as having > a big shiny red button on their desks > marked "Destroy West". > Good point — scary reminder that attackers can hit critical systems. Not everything is equally vulnerable: many airports and utilities have air-gapped or segmented controls, but legacy gear, third-party vendors, and poor configs open doors. Patching, network segmentation, monitoring, backups, and regular incident-response drills make a huge difference. Also: attribution is tricky — not every hack is a nation-state, though the risk from sophisticated actors is real. For ordinary folks, the best short-term advice is to verify info from official channels, expect delays, and keep your personal accounts and devices patched and on a VPN when using public Wi-Fi. Totally agree — this is a wake-up call, and cyber hygiene plus investment in infrastructure security are the only sane answers. -- Tom Mix
[toc] | [prev] | [next] | [standalone]
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-17 21:47 -0400 |
| Message-ID | <2smdnYcrA9AubG_1nZ2dnZfqnPqdnZ2d@giganews.com> |
| In reply to | #1324 |
On 10/17/25 09:32, Tom Mix wrote: > On 2025-10-16, c186282 <c186282@nnada.net> wrote: >> https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html >> >> international airport's PA system is HACKED and plays >> anti-Israel message to travelers >> >> . . . >> >> Just to note, basically EVERY system of ANY >> kind can be hacked now. That includes all >> the infrastructure stuff, banking, govt, >> everything. Vlad and Xi are BUSY BEAVERS. >> >> Doing online, well, pretty much ANYTHING ? >> They CAN, soon WILL, get at it. >> >> I kind of envision Vlad and Xi as having >> a big shiny red button on their desks >> marked "Destroy West". >> > > Good point — scary reminder that attackers can hit critical systems. > Not everything is equally vulnerable: many airports and utilities have air-gapped > or segmented controls, but legacy gear, third-party vendors, and poor configs > open doors. Patching, network segmentation, monitoring, backups, and regular > incident-response drills make a huge difference. > > Also: attribution is tricky — not every hack is a nation-state, though the risk > from sophisticated actors is real. For ordinary folks, the best short-term > advice is to verify info from official channels, expect delays, and keep your > personal accounts and devices patched and on a VPN when using public Wi-Fi. > > Totally agree — this is a wake-up call, and cyber hygiene plus investment in > infrastructure security are the only sane answers. But it seems nobody DOES it until there's a huge disaster. Human nature perhaps, but that won't keep Vlad's boyz from creating a fault in the cooling pumps at your local nuke plant. Such things might be able to pass as a locally generated 'accident', obscuring the attack. Banking is now especially exposed. Options are outright mass theft or sowing anarchy by blocking the systems or even mixing-up records. I have two main banks I use. One I employ online services, the other I'm still sticking to paper transactions.
[toc] | [prev] | [next] | [standalone]
| From | Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> |
|---|---|
| Date | 2025-10-20 21:20 +0200 |
| Message-ID | <cf7dcbe3-2e29-09b6-0981-3f106db59d44@insomnia247.nl> |
| In reply to | #1324 |
On Fri, 17 Oct 2025, Tom Mix wrote: "[. . .] [. . .] [. . .] For ordinary folks, the best short-term advice is to [. . .] keep your personal accounts and devices patched [. . .] [. . .] [. . .]" Patches are not always improvements. Cf. news:v7fokv$3ehcr$1@dont-email.me (Subject: Re: Canal+ crash) by Dmitry A. Kazakov in news:comp.lang.ada about a software update by CrowdStrike on 19th July 2024.
[toc] | [prev] | [next] | [standalone]
| From | Niocláisín Cóilín de Ghlostéir <Spamassassin@irrt.De> |
|---|---|
| Date | 2025-10-20 21:33 +0200 |
| Message-ID | <6dfb412f-c117-a11f-1dc9-ebf0f5b8bd57@irrt.De> |
| In reply to | #1326 |
Also cf. news:105o7kg$gi0$5@gallifrey.nk.ca (Subject: Re: Is Rocksolid Light really compromised and insecure?) in news:news.admin.peering and news:comp.security.misc and news:news.software.nntp by The Doctor.
[toc] | [prev] | [next] | [standalone]
| From | Tom Mix <tommix@dev.null> |
|---|---|
| Date | 2025-10-20 19:52 +0000 |
| Message-ID | <slrn10fd4om.2t1c8.tommix@devnull.org> |
| In reply to | #1326 |
On 2025-10-20, Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> wrote: > On Fri, 17 Oct 2025, Tom Mix wrote: > "[. . .] > > [. . .] > [. . .] For ordinary folks, the best short-term > advice is to [. . .] keep your > personal accounts and devices patched [. . .] > [. . .] > > [. . .]" > > > Patches are not always improvements. Cf. > news:v7fokv$3ehcr$1@dont-email.me Not patching because it might cause issues is like skipping deodorant because once it made your armpit itch. -- Tom Mix
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-10-20 20:47 +0000 |
| Message-ID | <10d674k$3fqu7$1@dont-email.me> |
| In reply to | #1328 |
On Mon, 20 Oct 2025 19:52:54 GMT, Tom Mix wrote: > Not patching because it might cause issues is like skipping deodorant because > once it made your armpit itch. Think of Microsoft Windows as a full-body attack of hives, then ...
[toc] | [prev] | [next] | [standalone]
| From | Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> |
|---|---|
| Date | 2025-10-20 22:50 +0200 |
| Message-ID | <151db5fd-4b6b-0864-4819-ef7fabe55ee1@irrt.De> |
| In reply to | #1328 |
Patches can ge good. Patches can be bad. A good thing is less likely to need patches.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-10-20 23:06 +0000 |
| Message-ID | <10d6f9q$3huoh$1@dont-email.me> |
| In reply to | #1330 |
On Mon, 20 Oct 2025 22:50:33 +0200, Nioclás Pól Caileán de Ghloucester
wrote:
> Patches can ge good. Patches can be bad. A good thing is less likely
> to need patches.
Greg Kroah-Hartman on the Linux kernel
<https://www.zdnet.com/article/the-linux-security-team-issues-60-cves-a-week-but-dont-stress-do-this-instead/>:
Greg Kroah-Hartman, maintainer of the Linux stable kernel, wants
you to know that on an average week, the Linux security team
issues sixty -- 60 -- Common Vulnerabilities and Exposures (CVE)
security bulletins. Don't stress. That's just life in Linux.
...
Wait. Isn't 60 CVEs a week about problems that can stop your
computer dead in its tracks something to worry about? Well, yes.
Then, again, no.
You see, Kroah-Hartman explained, today, the Linux kernel has "38
million lines of code. You only use a little bit of this. My
laptop uses about one and a half million lines of code. .... Your
phone, the most complex beast out there, uses about 4 million
lines of code. So, out of everything, you're really using a small
portion, but everybody uses a different portion, and that's an
important thing to remember."
...
What you can do to keep your system safe -- whether it's a car or
10,000 servers in a data center -- is simple. Kroah-Hartman's rule
is "If you're not using the latest stable/long-term kernel system,
your system is insecure."
By that, he means update your kernel almost every week. Now, most
of you will find that notion as scary as dealing with 60 CVEs a
week.
The thing is, Kroah-Hartman said, "We have proof this can be done.
Debian runs over 80% of the world's servers and they're using
stable kernel updates. Android, billions of devices out there,
takes every stable kernel update on a couple months lag, but
they're doing it and keeping their devices secure. There's nothing
more complex than embedded into the system, and there's nothing
more common and easy to use than a Debian server.
[toc] | [prev] | [next] | [standalone]
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-20 22:49 -0400 |
| Message-ID | <Bm-dnVkUmLlfaWv1nZ2dnZfqn_ednZ2d@giganews.com> |
| In reply to | #1330 |
On 10/20/25 16:50, Nioclás Pól Caileán de Ghloucester wrote: > Patches can ge good. Patches can be bad. A good thing is less likely to > need patches. But how to be sure 'good' is actually 'good' ? It's a problem. 'AI' won't fix this either.
[toc] | [prev] | [next] | [standalone]
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-20 22:48 -0400 |
| Message-ID | <Bm-dnV4UmLnnaWv1nZ2dnZfqn_ednZ2d@giganews.com> |
| In reply to | #1328 |
On 10/20/25 15:52, Tom Mix wrote: > On 2025-10-20, Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> wrote: >> On Fri, 17 Oct 2025, Tom Mix wrote: >> "[. . .] >> >> [. . .] >> [. . .] For ordinary folks, the best short-term >> advice is to [. . .] keep your >> personal accounts and devices patched [. . .] >> [. . .] >> >> [. . .]" >> >> >> Patches are not always improvements. Cf. >> news:v7fokv$3ehcr$1@dont-email.me > > Not patching because it might cause issues is like skipping deodorant because > once it made your armpit itch. Software/driver "patches" are a mixed bag - and twice so if they're done in an emergency hurry. Ideally you improve the entire base OS, but that scale of upgrade goes very slow. In any case, EVERYTHING now needs to be re-done with hostile actors as the main focus. Russia, China, NK, to a point even India and some of eastern Europe ... they're out to GET us. We aren't using CP/M anymore, today's systems are just ULTRA complex, not to mention all the 'convenience' stuff. A zillion points of attack. Vlad's boyz have nothing better to do than find and exploit ALL of them. Oh, checked, you CAN buy a few Z80+CP/M kit boards still :-) As for 'Ada' ... tried it, wrote some shorties in it (relatively complex linked lists of linked lists and such) ... NO NO NO !!! It's the anal- retentive dream. Surprised mass quantities of programmers didn't jump off the roof (did they?). Perfect for "government" projects of course, takes a month to do what 'C'/other programmers could do in an afternoon ... But the vulnerabilities were only just so much in the hand-writ code. The compiler, the libs, the underlying OS, the hardware, they all had points of attack as well. Ada, at best, kind of reduced ONE of those attack points a little. A tunnel-vision 'fix'.
[toc] | [prev] | [next] | [standalone]
| From | Tristan Wibberley <tristan.wibberley+netnews2@alumni.manchester.ac.uk> |
|---|---|
| Date | 2025-10-26 11:05 +0000 |
| Message-ID | <10dkv9h$3utp5$1@dont-email.me> |
| In reply to | #1328 |
followups reduced On 20/10/2025 20:52, Tom Mix wrote: > Not patching because it might cause issues is like skipping deodorant because > once it made your armpit itch. Issues are a DoS. News about security risks can be a DDoS whenever a security update introduces issues. For security, security updates must introduce no issues; they must be orthogonal to the functionality (both advertised and conventionally assumed). -- Tristan Wibberley The message body is Copyright (C) 2025 Tristan Wibberley except citations and quotations noted. All Rights Reserved except that you may, of course, cite it academically giving credit to me, distribute it verbatim as part of a usenet system or its archives, and use it to promote my greatness and general superiority without misrepresentation of my opinions other than my opinion of my greatness and general superiority which you _may_ misrepresent. You definitely MAY NOT train any production AI system with it but you may train experimental AI that will only be used for evaluation of the AI methods it implements.
[toc] | [prev] | [next] | [standalone]
| From | Chris Ahlstrom <OFeem1987@teleworm.us> |
|---|---|
| Date | 2025-10-26 07:27 -0400 |
| Message-ID | <10dl0jg$3v8ln$2@dont-email.me> |
| In reply to | #1339 |
Tristan Wibberley wrote this post while blinking in Morse code: > <snip> > > -- > Tristan Wibberley > > The message body is Copyright (C) 2025 Tristan Wibberley except > citations and quotations noted. All Rights Reserved except that you may, > of course, cite it academically giving credit to me, distribute it > verbatim as part of a usenet system or its archives, and use it to > promote my greatness and general superiority without misrepresentation > of my opinions other than my opinion of my greatness and general > superiority which you _may_ misrepresent. You definitely MAY NOT train > any production AI system with it but you may train experimental AI that > will only be used for evaluation of the AI methods it implements. :-D -- Don't change the reason, just change the excuses! -- Joe Cointment
[toc] | [prev] | [standalone]
Back to top | Article view | alt.security
csiph-web