How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)
Microsoft will make the most from WannaCry
31–40 of 74 posts
Re: Microsoft will make the most from WannaCry
#32Earlier quoted context omitted.
No people fear updates from M$ because M$ has a bad history of bricking devices and pushing hidden privacy-harming updates without consorting their users. Or maybe it's the fact that Windows has to restart after every single software update. Really it's astounding that Microsoft provides this kind of awful updating experience and then inseminates propoganda into people's minds that those who don't auto update their W…
I could agree with the first sentence; the rest...not. (AFAIK, Win10 was not affected by the SMB vulnerability, no?)
You don't believe Microsoft is engaged in propaganda campaigns, specifically the idea that not updating is being a "bad user"?
You don't believe that by using Win10, you aren't legitimizing the "OS as Malware" concept and endangering yourself to a huge remote attack surface?
Re: Microsoft will make the most from WannaCry
#33How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)
Re: Microsoft will make the most from WannaCry
#34Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.
Re: Microsoft will make the most from WannaCry
#35How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)
Initially through an attachment and subsequently throughm the LAN via SMB. SMB is(was?) enabled by default in Windows Features.
Sure, when hitting a large corporation that would obviously help a lot but home networks (which for some reason have been hit quite hard as well) don't even have that many machines to begin with.
Re: Microsoft will make the most from WannaCry
#36Not a big fan of Microsoft in general, and I generally distrust anything it does, but I'm beginning to like this Brad Smith fellow. He's been pushing for quite a few privacy initiatives inside Microsoft, and he's now also taking on NSA and calling for a Digital Geneva Convention. I also think Microsoft "got lucky" this time. Shadow Brokers sit on EternalBlue for at least 6 months. They could've released it before the…
EternalBlue CVE-2017-0144 was [edit:allocated/reserved instead of "assigned" per tweet] 2016-09-09. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0144 Source: https://twitter.com/_supernothing/status/864021595303456768 > MS has known about this bug since 09/2016 (when CVE was assigned) and patched in 03/2017. 240day
>Date Entry Created 20160909
>Disclaimer: The entry creation date may reflect when the CVE-ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE.
Do you have a better source for the 240day claim?
Re: Microsoft will make the most from WannaCry
#37How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)
Look at the number of exploits Microsoft has patched in the last 2-3 years. Then realize most of them also apply to XP, and haven't been patched for that OS. Exploiting XP users is incredibly easy.
Re: Microsoft will make the most from WannaCry
#38Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.
Re: Microsoft will make the most from WannaCry
#39Re: Microsoft will make the most from WannaCry
#40Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.
more here: https://www.gnu.org/proprietary/malware-microsoft.en.html