We never took it seriously. WannaCry is the bill.

Er Galvao Abbott
The White Hat ElePHPant
2 min readMay 15, 2017

Update your software.
Backup often.
Use a firewall.
Use an antivirus.
Don’t trust attachments, etc…

For how long the IT industry has been repeating these simple statements? Oh, they are simple and anyone, let alone system administrators would be capable of abiding to them, if only they cared.

It’s easy to point a finger at Microsoft Windows

Windows has always been one juicy target for criticism and easy laughs. What people seem to forget is that although the OS is in fact targeted way more often than anything else, many just-as-juicy cases in the past were about sysadmins not changing default passwords, ignoring cryptography, so on and so forth… And oh, how it goes on and on and on…

It’s easy to point a finger at management

Yes, it is more often than not an industry driven by money-hungry, deadline-oriented ignorant assholes, but we dance along their song, don’t we? We mumble silently at work and stick to our values and rant loudly on blogs and social media. If only we could do the opposite…

What’s not easy to do is to admit to our mistakes… and change the status quo.

I often say mistakes are not the issue. We’re humans, prone to error, sometimes driven for the wrong reasons. The issue is whether you do or don’t learn with them. It’s what you do about it when they happen.

So, you lowered your head and accepted bad management;
So, you were burnt out from an insane work schedule;
So, you said to yourself “what are the odds of anything serious happening?”.

There’s absolutely nothing wrong with that, as long as you learn the stakes you took, accept that mistakes were made and move on to be a better professional (sic) and to make a better industry out of all this.

Cry. Or don’t. Pay. Or don’t. But please, let’s learn and grow.

--

--

Er Galvao Abbott
The White Hat ElePHPant

Brazilian programmer and web app security advisor; Zend Framework Evangelist.