• Harrisburg PA - Airport PA System Hacked - Rude Anti-SemitePropaganda

    From c186282@c186282@nnada.net to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security on Thursday, October 16, 2025 03:39:03
    From Newsgroup: alt.security

    https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html

    international airport's PA system is HACKED and plays
    anti-Israel message to travelers

    . . .

    Just to note, basically EVERY system of ANY
    kind can be hacked now. That includes all
    the infrastructure stuff, banking, govt,
    everything. Vlad and Xi are BUSY BEAVERS.

    Doing online, well, pretty much ANYTHING ?
    They CAN, soon WILL, get at it.

    I kind of envision Vlad and Xi as having
    a big shiny red button on their desks
    marked "Destroy West".

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Tom Mix@tommix@dev.null to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security on Friday, October 17, 2025 13:32:31
    From Newsgroup: alt.security

    On 2025-10-16, c186282 <c186282@nnada.net> wrote:
    https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html

    international airport's PA system is HACKED and plays
    anti-Israel message to travelers

    . . .

    Just to note, basically EVERY system of ANY
    kind can be hacked now. That includes all
    the infrastructure stuff, banking, govt,
    everything. Vlad and Xi are BUSY BEAVERS.

    Doing online, well, pretty much ANYTHING ?
    They CAN, soon WILL, get at it.

    I kind of envision Vlad and Xi as having
    a big shiny red button on their desks
    marked "Destroy West".


    Good point — scary reminder that attackers can hit critical systems.
    Not everything is equally vulnerable: many airports and utilities have air-gapped
    or segmented controls, but legacy gear, third-party vendors, and poor configs open doors. Patching, network segmentation, monitoring, backups, and regular incident-response drills make a huge difference.

    Also: attribution is tricky — not every hack is a nation-state, though the risk
    from sophisticated actors is real. For ordinary folks, the best short-term advice is to verify info from official channels, expect delays, and keep your personal accounts and devices patched and on a VPN when using public Wi-Fi.

    Totally agree — this is a wake-up call, and cyber hygiene plus investment in infrastructure security are the only sane answers.
    --
    Tom Mix
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From c186282@c186282@nnada.net to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security on Friday, October 17, 2025 21:47:30
    From Newsgroup: alt.security

    On 10/17/25 09:32, Tom Mix wrote:
    On 2025-10-16, c186282 <c186282@nnada.net> wrote:
    https://www.dailymail.co.uk/news/article-15196513/harrisburg-international-airport-pa-hackers-anti-israel.html

    international airport's PA system is HACKED and plays
    anti-Israel message to travelers

    . . .

    Just to note, basically EVERY system of ANY
    kind can be hacked now. That includes all
    the infrastructure stuff, banking, govt,
    everything. Vlad and Xi are BUSY BEAVERS.

    Doing online, well, pretty much ANYTHING ?
    They CAN, soon WILL, get at it.

    I kind of envision Vlad and Xi as having
    a big shiny red button on their desks
    marked "Destroy West".


    Good point — scary reminder that attackers can hit critical systems.
    Not everything is equally vulnerable: many airports and utilities have air-gapped
    or segmented controls, but legacy gear, third-party vendors, and poor configs open doors. Patching, network segmentation, monitoring, backups, and regular incident-response drills make a huge difference.

    Also: attribution is tricky — not every hack is a nation-state, though the risk
    from sophisticated actors is real. For ordinary folks, the best short-term advice is to verify info from official channels, expect delays, and keep your personal accounts and devices patched and on a VPN when using public Wi-Fi.

    Totally agree — this is a wake-up call, and cyber hygiene plus investment in
    infrastructure security are the only sane answers.


    But it seems nobody DOES it until there's a huge disaster.
    Human nature perhaps, but that won't keep Vlad's boyz from
    creating a fault in the cooling pumps at your local nuke plant.
    Such things might be able to pass as a locally generated
    'accident', obscuring the attack.

    Banking is now especially exposed. Options are outright
    mass theft or sowing anarchy by blocking the systems or
    even mixing-up records.

    I have two main banks I use. One I employ online services,
    the other I'm still sticking to paper transactions.

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Tom Mix@tommix@dev.null to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Monday, October 20, 2025 19:52:54
    From Newsgroup: alt.security

    On 2025-10-20, Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> wrote:
    On Fri, 17 Oct 2025, Tom Mix wrote:
    "[. . .]

    [. . .]
    [. . .] For ordinary folks, the best short-term
    advice is to [. . .] keep your
    personal accounts and devices patched [. . .]
    [. . .]

    [. . .]"


    Patches are not always improvements. Cf.
    news:v7fokv$3ehcr$1@dont-email.me

    Not patching because it might cause issues is like skipping deodorant because once it made your armpit itch.
    --
    Tom Mix
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Lawrence =?iso-8859-13?q?D=FFOliveiro?=@ldo@nz.invalid to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Monday, October 20, 2025 20:47:16
    From Newsgroup: alt.security

    On Mon, 20 Oct 2025 19:52:54 GMT, Tom Mix wrote:

    Not patching because it might cause issues is like skipping deodorant because once it made your armpit itch.

    Think of Microsoft Windows as a full-body attack of hives, then ...
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Lawrence =?iso-8859-13?q?D=FFOliveiro?=@ldo@nz.invalid to talk.politics.misc,alt.politics.usa,alt.security,comp.lang.ada on Monday, October 20, 2025 23:06:34
    From Newsgroup: alt.security

    On Mon, 20 Oct 2025 22:50:33 +0200, Nioclás Pól Caileán de Ghloucester wrote:

    Patches can ge good. Patches can be bad. A good thing is less likely
    to need patches.

    Greg Kroah-Hartman on the Linux kernel <https://www.zdnet.com/article/the-linux-security-team-issues-60-cves-a-week-but-dont-stress-do-this-instead/>:

    Greg Kroah-Hartman, maintainer of the Linux stable kernel, wants
    you to know that on an average week, the Linux security team
    issues sixty -- 60 -- Common Vulnerabilities and Exposures (CVE)
    security bulletins. Don't stress. That's just life in Linux.

    ...

    Wait. Isn't 60 CVEs a week about problems that can stop your
    computer dead in its tracks something to worry about? Well, yes.
    Then, again, no.

    You see, Kroah-Hartman explained, today, the Linux kernel has "38
    million lines of code. You only use a little bit of this. My
    laptop uses about one and a half million lines of code. .... Your
    phone, the most complex beast out there, uses about 4 million
    lines of code. So, out of everything, you're really using a small
    portion, but everybody uses a different portion, and that's an
    important thing to remember."

    ...

    What you can do to keep your system safe -- whether it's a car or
    10,000 servers in a data center -- is simple. Kroah-Hartman's rule
    is "If you're not using the latest stable/long-term kernel system,
    your system is insecure."

    By that, he means update your kernel almost every week. Now, most
    of you will find that notion as scary as dealing with 60 CVEs a
    week.

    The thing is, Kroah-Hartman said, "We have proof this can be done.
    Debian runs over 80% of the world's servers and they're using
    stable kernel updates. Android, billions of devices out there,
    takes every stable kernel update on a couple months lag, but
    they're doing it and keeping their devices secure. There's nothing
    more complex than embedded into the system, and there's nothing
    more common and easy to use than a Debian server.
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From c186282@c186282@nnada.net to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Monday, October 20, 2025 22:48:25
    From Newsgroup: alt.security

    On 10/20/25 15:52, Tom Mix wrote:
    On 2025-10-20, Nioclás Pól Caileán de Ghloucester <Spamassassin@irrt.De> wrote:
    On Fri, 17 Oct 2025, Tom Mix wrote:
    "[. . .]

    [. . .]
    [. . .] For ordinary folks, the best short-term
    advice is to [. . .] keep your
    personal accounts and devices patched [. . .]
    [. . .]

    [. . .]"


    Patches are not always improvements. Cf.
    news:v7fokv$3ehcr$1@dont-email.me

    Not patching because it might cause issues is like skipping deodorant because once it made your armpit itch.

    Software/driver "patches" are a mixed bag - and
    twice so if they're done in an emergency hurry.

    Ideally you improve the entire base OS, but
    that scale of upgrade goes very slow.

    In any case, EVERYTHING now needs to be re-done
    with hostile actors as the main focus. Russia,
    China, NK, to a point even India and some of
    eastern Europe ... they're out to GET us.

    We aren't using CP/M anymore, today's systems
    are just ULTRA complex, not to mention all the
    'convenience' stuff. A zillion points of attack.
    Vlad's boyz have nothing better to do than find
    and exploit ALL of them.

    Oh, checked, you CAN buy a few Z80+CP/M kit
    boards still :-)

    As for 'Ada' ... tried it, wrote some shorties
    in it (relatively complex linked lists of linked
    lists and such) ... NO NO NO !!! It's the anal-
    retentive dream. Surprised mass quantities of
    programmers didn't jump off the roof (did they?).
    Perfect for "government" projects of course, takes
    a month to do what 'C'/other programmers could do
    in an afternoon ...

    But the vulnerabilities were only just so much
    in the hand-writ code. The compiler, the libs,
    the underlying OS, the hardware, they all had
    points of attack as well. Ada, at best, kind
    of reduced ONE of those attack points a little.
    A tunnel-vision 'fix'.

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From c186282@c186282@nnada.net to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Monday, October 20, 2025 22:49:37
    From Newsgroup: alt.security

    On 10/20/25 16:50, Nioclás Pól Caileán de Ghloucester wrote:
    Patches can ge good. Patches can be bad. A good thing is less likely to
    need patches.

    But how to be sure 'good' is actually 'good' ?

    It's a problem.

    'AI' won't fix this either.

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Tristan Wibberley@tristan.wibberley+netnews2@alumni.manchester.ac.uk to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Sunday, October 26, 2025 11:05:21
    From Newsgroup: alt.security

    followups reduced

    On 20/10/2025 20:52, Tom Mix wrote:

    Not patching because it might cause issues is like skipping deodorant because once it made your armpit itch.

    Issues are a DoS. News about security risks can be a DDoS whenever a
    security update introduces issues. For security, security updates must introduce no issues; they must be orthogonal to the functionality (both advertised and conventionally assumed).

    --
    Tristan Wibberley

    The message body is Copyright (C) 2025 Tristan Wibberley except
    citations and quotations noted. All Rights Reserved except that you may,
    of course, cite it academically giving credit to me, distribute it
    verbatim as part of a usenet system or its archives, and use it to
    promote my greatness and general superiority without misrepresentation
    of my opinions other than my opinion of my greatness and general
    superiority which you _may_ misrepresent. You definitely MAY NOT train
    any production AI system with it but you may train experimental AI that
    will only be used for evaluation of the AI methods it implements.

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Chris Ahlstrom@OFeem1987@teleworm.us to talk.politics.misc,alt.politics.usa,alt.fan.rush-limbaugh,alt.security,comp.lang.ada on Sunday, October 26, 2025 07:27:43
    From Newsgroup: alt.security

    Tristan Wibberley wrote this post while blinking in Morse code:

    <snip>

    --
    Tristan Wibberley

    The message body is Copyright (C) 2025 Tristan Wibberley except
    citations and quotations noted. All Rights Reserved except that you may,
    of course, cite it academically giving credit to me, distribute it
    verbatim as part of a usenet system or its archives, and use it to
    promote my greatness and general superiority without misrepresentation
    of my opinions other than my opinion of my greatness and general
    superiority which you _may_ misrepresent. You definitely MAY NOT train
    any production AI system with it but you may train experimental AI that
    will only be used for evaluation of the AI methods it implements.

    :-D
    --
    Don't change the reason, just change the excuses!
    -- Joe Cointment
    --- Synchronet 3.21e-Win32 NewsLink 1.2