Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

31–40 of 74 posts

Re: Microsoft will make the most from WannaCry

#31
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

Look at the number of exploits Microsoft has patched in the last 2-3 years. Then realize most of them also apply to XP, and haven't been patched for that OS. Exploiting XP users is incredibly easy.

Re: Microsoft will make the most from WannaCry

#32
post #16

Earlier quoted context omitted.

No people fear updates from M$ because M$ has a bad history of bricking devices and pushing hidden privacy-harming updates without consorting their users. Or maybe it's the fact that Windows has to restart after every single software update. Really it's astounding that Microsoft provides this kind of awful updating experience and then inseminates propoganda into people's minds that those who don't auto update their W…

I could agree with the first sentence; the rest...not. (AFAIK, Win10 was not affected by the SMB vulnerability, no?)

Windows doesn't restart after every update for you?

You don't believe Microsoft is engaged in propaganda campaigns, specifically the idea that not updating is being a "bad user"?

You don't believe that by using Win10, you aren't legitimizing the "OS as Malware" concept and endangering yourself to a huge remote attack surface?

Re: Microsoft will make the most from WannaCry

#33
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

User clicks an email attachment and then it spreads internally. Extremely common.

Re: Microsoft will make the most from WannaCry

#34
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

The Pro-MS downvoters are in force this morning. I will take the downs b/c I have not added any substance, but this trend is getting out of hand.

Re: Microsoft will make the most from WannaCry

#35
post #30
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

Initially through an attachment and subsequently throughm the LAN via SMB. SMB is(was?) enabled by default in Windows Features.

So, if the attack requires you to double-click on virus.exe the NSA exploits everyone is talking about didn't really matter that much did it?

Sure, when hitting a large corporation that would obviously help a lot but home networks (which for some reason have been hit quite hard as well) don't even have that many machines to begin with.

Re: Microsoft will make the most from WannaCry

#36
post #29
post #14

Not a big fan of Microsoft in general, and I generally distrust anything it does, but I'm beginning to like this Brad Smith fellow. He's been pushing for quite a few privacy initiatives inside Microsoft, and he's now also taking on NSA and calling for a Digital Geneva Convention. I also think Microsoft "got lucky" this time. Shadow Brokers sit on EternalBlue for at least 6 months. They could've released it before the…

EternalBlue CVE-2017-0144 was [edit:allocated/reserved instead of "assigned" per tweet] 2016-09-09. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0144 Source: https://twitter.com/_supernothing/status/864021595303456768 > MS has known about this bug since 09/2016 (when CVE was assigned) and patched in 03/2017. 240day

From the source that that tweet gets the "date" from:

>Date Entry Created 20160909

>Disclaimer: The entry creation date may reflect when the CVE-ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE.

Do you have a better source for the 240day claim?

Re: Microsoft will make the most from WannaCry

#37
post #31
post #24

How does wannacry spread? From what I find it's primarily via an SMB exploit, but who on earth can possible receive SMB traffic on the internet today? Is it automatically opened via UPNP or something? (seems doubtful)

Look at the number of exploits Microsoft has patched in the last 2-3 years. Then realize most of them also apply to XP, and haven't been patched for that OS. Exploiting XP users is incredibly easy.

So patches applied to later editions are a guide to what could be broken in XP.

Re: Microsoft will make the most from WannaCry

#38
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

What are you even talking about? Don't you know that they do so much open source these days?

Re: Microsoft will make the most from WannaCry

#40
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

We already know windows is malware. There is no question: https://web.archive.org/web/20130622044225/http://blogs.comp...

more here: https://www.gnu.org/proprietary/malware-microsoft.en.html

Post reply on HN