From governments to individuals, there’s plenty of finger-pointing going on following the latest global cyberattack.
p
Who’s being targeted for blame? There’s Microsoft, whose ubiquitous Windows operating systems were compromised after attackers exploited a security hole.
p
Then there’s the U.S. government, whose Windows hacking tools were leaked to the internet and got into the hands of cybercriminals.
p
There are the companies, universities, hospitals and other organizations that didn’t install Microsoft’s fixes and take other precautions, such as backing up data.
p
Lastly there are, of course, the attackers, who kidnapped precious data and demanded ransom be paid.
p
You can point a lot of fingers, but I think given that this was not a zero-day vulnerability (for which no patch is available), the people hacked are to blame, said Robert Cattanach, a partner at the international law firm Dorsey Whitney and an expert on cybersecurity and data breaches. Still, the NSA can’t be very proud of this. Microsoft can’t be proud.
p
Here are some of the key players in the attack and what may — or may not — be their fault.
p
subhead
The NSA
/subhead
p
WannaCry, as the ransomware is known, uses a Windows vulnerability originally identified by the NSA, according to security experts. So it makes sense to assign some responsibility to the NSA — the attackers didn’t come up with this security hole on their own, after all.
p
On top of that, critics say, the government didn’t notify companies like Microsoft about the vulnerabilities quickly enough. Brad Smith, Microsoft’s top lawyer, criticized U.S. intelligence agencies for stockpiling software code that can be used by hackers.
p
We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world, wrote Smith in a blog post on Sunday.
p
The ACLU, meanwhile, urged Congress to pass a law requiring the government to…