Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

21–30 of 74 posts

Re: Microsoft will make the most from WannaCry

#21
post #9

TLDR: Microsoft is using WannaCry as an opportunity to complain about the NSA and as an opportunity to tell people they need to update their software. I personally think that it's great to get the message across that people need to keep their operating systems up-to-date. I see too many non-technical people thinking in dangerous ways: * "I don't want to update software, because the new software could have bugs which…

>as an opportunity to tell people they need to update their software.

How are defining update? I don't think anyone has issues with security updates but being force-fed a new version of Windows10 every 6 months is questionable especially when its a true re-imaging of the PC and a migration of apps and data, often screwing up in some way mostly with putting in older or buggy drivers that the end user has replaced with newer ones on the previous version. Every update has broke my trackpad on my laptop and badly hurt my gaming performance on my desktop until I could find the proper nvidia drivers. On top of having to deal with all the UI changes and other changes, none of which seem documented in a easy end-user digestible way. Also some of which have to be discovered by sysadmins like Win10 Pro now ignoring GPOs to block the store, for example.

I think MS is going to use anything to justify an evergreen Windows 10. I'm not sure that's a good thing. I'm not more secure with the current version with this issue patched compared to the previous version with this issue patched. Its the same level of security. I dislike it when companies disingenuously conflate feature updates with security updates. These are two entirely different things.

I think is Win10 moved at a much slower pace for feature upgrades, say every 12-18 months, people wouldn't be so wary of it. Instead, MS is forcing things down the throats of customers that are not desired or asked for. Worse, it validates a "ship and fix later" approach that will always lead to poor quality software.

Lastly, MS is just being downright dishonest. Most of the infected weren't Win10 or 8/7 users too lazy to update, but old copies of XP still in use. Those XP users have auto-update running, but MS has chosen EOL it. Fine, but don't browbeat Win10 users sick of endless and buggy feature updates because of it. The two have nothing in common.

Re: Microsoft will make the most from WannaCry

#22
post #16
post #10

Earlier quoted context omitted.

I wonder how much of the never-upgrade mentality is down to Microsoft insisting on being backwards compatible back till basically the Jurassic period, and providing support for obsolete software for years and years. Their intention is commendable, but there's something to be said for sometimes breaking things for what is hopefully the greater good. The rust package manager issue that was on HN the other week comes to…

No people fear updates from M$ because M$ has a bad history of bricking devices and pushing hidden privacy-harming updates without consorting their users. Or maybe it's the fact that Windows has to restart after every single software update. Really it's astounding that Microsoft provides this kind of awful updating experience and then inseminates propoganda into people's minds that those who don't auto update their W…

I could agree with the first sentence; the rest...not. (AFAIK, Win10 was not affected by the SMB vulnerability, no?)

Re: Microsoft will make the most from WannaCry

#23
post #14

Not a big fan of Microsoft in general, and I generally distrust anything it does, but I'm beginning to like this Brad Smith fellow. He's been pushing for quite a few privacy initiatives inside Microsoft, and he's now also taking on NSA and calling for a Digital Geneva Convention. I also think Microsoft "got lucky" this time. Shadow Brokers sit on EternalBlue for at least 6 months. They could've released it before the…

>They could've released it before the NSA

They were looking for buyers this whole time. Perhaps you are unaware but there's an entire cottage industry of selling and buying of vulnerabilities out there. There are many zero days being sat on. No one is getting 'lucky.' They will be sold and used as needed by whatever group.

There seems to be this narrative developing about how this exploit is some rare thing. There are hundreds of serious exploits discovered in Windows a year and those are the ones we know about. There was no nation state involved with conficker, slammer, codered, heartbleed, etc. So its silly to focus solely on the NSA here. Exploits will be found, forever. We don't have the ability to make defect-free software.

Re: Microsoft will make the most from WannaCry

#27
Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

Re: Microsoft will make the most from WannaCry

#28
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

I thought it was infected email attachments, like most ransomware? Once inside the network it could spread all over rather easily.

Re: Microsoft will make the most from WannaCry

#29
post #14

Not a big fan of Microsoft in general, and I generally distrust anything it does, but I'm beginning to like this Brad Smith fellow. He's been pushing for quite a few privacy initiatives inside Microsoft, and he's now also taking on NSA and calling for a Digital Geneva Convention. I also think Microsoft "got lucky" this time. Shadow Brokers sit on EternalBlue for at least 6 months. They could've released it before the…

EternalBlue CVE-2017-0144 was [edit:allocated/reserved instead of "assigned" per tweet] 2016-09-09. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0144

Source: https://twitter.com/_supernothing/status/864021595303456768

> MS has known about this bug since 09/2016 (when CVE was assigned) and patched in 03/2017. 240day

Re: Microsoft will make the most from WannaCry

#30
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

Initially through an attachment and subsequently throughm the LAN via SMB. SMB is(was?) enabled by default in Windows Features.
Post reply on HN