Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Tech Experts Comment on UA, NYSE Computer Problems
Articles

Tech Experts Comment on UA, NYSE Computer Problems

ISBuzz TeamBy ISBuzz TeamJuly 9, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NYSE computer problems
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Reflecting on this morning’s computer problems that grounded flights on United, halted trading on the NYSE, and took The Wall Street Journal website offline for a short period, cybersecurity experts commented :

Jonathan Sander, Strategy & Research Officer at STEALTHbits Technologies (www.stealthbits.com):

“United Airlines and NYSE both made strong statements via Twitter that their outages were not security related. There’s no reason to doubt them. But what does it say that this is the first thing everyone assumes? If you went to a clothing store on Main Street and there was a “we’ll be back” later sign in the window, would you assume a thief had broken in? It’s very clear that the good guys are not winning the PR battle in the digital security world. We all assume the bad guys can take down any sized company at any time.”

Tim Erlin, Director of IT Security and Risk Strategy at Tripwire (www.tripwire.com):

“There is virtually no part of our global economy that isn’t dependent on interconnected technology today, and the level of interdependence continues to increase steadily. That means that any failure, malicious or not, has the potential to create economic repercussions.

There are many layers of technology between the consumer and the services we depend on, from the individual smartphone that you use to access a service, to the vendor who provides the networking equipment used by the telecommunications company to provide connectivity to the company providing the service. The level of complexity can be staggering, and this means an error made by a developer half-way around the world somewhere in the supply chain of a service can impact the operations of major businesses like United.

Collectively our goal should not be to eliminate errors, instead we should focus on providing resiliency in the face of known instability.

From a cybersecurity perspective, the obvious disruptions to service might not be what we need to worry about. Instead,  we should be detecting the nearly invisible infiltration of valuable systems.”

Igor Baikalov, Chief Scientist at Securonix (www.securonix.com):

“If the DHS and FBI are correct in ruling out a cyber attack as a cause of outages at United Airlines, NYSE, and WSJ – all happening this morning in the span of a few hours – and it’s not an aftershock of the recently concluded “Cyber Guard” war games, then our technological foundation is in a really bad shape. It’s our critical infrastructure we’re talking about! To have vital transportation, financial, and media companies, that are heavily dependent on technology, experience disrupting “glitches” in their busiest hours is something that only global war game scenario can envision. It’s just not something that one plans for in real life.

What every enterprise should plan for is business continuity and disaster recovery – remember “A” in CIA (Confidentiality, Integrity and Availability) attributes of Information Security? The problem is that High Availability (minimum downtime) and especially Fault Tolerance (no single point of failure) is very expensive, and for as long as the cost of implementation exceeds the cost of outage, businesses are not going to do it. Something has to be said on the maturity of change management processes too: it’s not the first rodeo for NYSE, and why there were no staged rollout and rollback plans in place is hard to comprehend. Was it really that much cheaper to deploy system-wide changes right before the opening bell, and bring the whole thing down, than to execute a careful deployment overnight, with sufficient time for testing and reversing the changes if needed?

I mean, these are serious companies with smart people doing expensive stuff – it’s not some low-life “Internet of Things” – how could the basic principles of Information Security be so ignored? Perhaps, I stick with the conspiracy theory of nation-state retaliation for the market crash, or alien invasion.”

Pierluigi Stella, Chief Technology Officer of Network Box USA (www.networkboxusa.com):

“These 2 stories (UA and NYSE) do not seem immediately related to hacking as I’d previously thought; although if a hacker wanted to disrupt operations, this would’ve been a good way to do it. The general issue here is, we depend so much on technology that when something malfunctions the effects cascade broadly and affect large numbers of people.

The reports seem to point to a router issue.

A router is a device that operates like an intersection, deciding where traffic goes based on multiple parameters.  If a router’s configuration is incorrect, you get a traffic jam, computers can’t talk to each other, and things stop working.  A website would typically talk to a database server; if the router breaks and the two can’t talk, when you try to check in, the server can’t find your information, and you end up grounded.

Now, in a case like this, I’d assume there are multiple redundancies to avoid interruptions of such critical functions.  Meaning, you don’t install only 1 router at every intersection; you use at least 2, with mirrored configurations, so if one breaks, you can replace it without anyone even noticing.

I’m afraid the only reason why such a disruption might happen (that I can think of) would be human error – someone, somewhere made a mistake and broke the configuration of the router – or so it’d appear. Therefore, the issue isn’t really our dependency on technology, but rather, our dependency on those who maintain and configure said technology.

The internet is so interconnected that a small error in one place can rapidly bring many other things to a screeching halt.

In 2005, someone in the Czech  Republic made a small mistake on a router and took down half the internet for several hours.  Yes, we are _that_ interconnected.  In this morning’s case, the issue affected only United, so it was an internal router; but it still demonstrates the fact that technology needs to be operated with caution, and that, ultimately, the human element is always the weakest link.  No matter how many redundancies you set in place and how much money you invest, if someone makes a mistake in a configuration, you end up with some serious problems.

I don’t know at this point what happened at NYSE, but there too, I’m fairly certain, there are plenty of redundancies so that if a computer breaks, you have at the very least, 2 more doing the same work.  Certain major disruptions don’t happen because a disk broke in an organization of this scale; they happen because someone made a mistake.

So please, let’s not blame technology.  Yes, we do depend on it, but that isn’t going to change.  In fact, it’s only going to be more and more so.  And the more we depend on it, the less these issues happen because technology on its own doesn’t make mistakes and can be set to be redundant (alright, technology sometimes does make mistakes, but they can always be traced back to the human who configured or built them!) to avoid issues when something breaks.

Humans make mistakes ergo it’s the human element which needs to be vetted the most in this dependence of our world upon technology.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}