Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

41–50 of 74 posts

Re: Microsoft will make the most from WannaCry

#41
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

What are you even talking about? Don't you know that they do so much open source these days?

You can contribute to open source and still do bad things: https://theintercept.com/2015/12/28/recently-bought-a-window...

Re: Microsoft will make the most from WannaCry

#42

Earlier quoted context omitted.

What are you even talking about? Don't you know that they do so much open source these days?

You can contribute to open source and still do bad things: https://theintercept.com/2015/12/28/recently-bought-a-window...

I believe it was a sarcasm. Look at the italic part.

Re: Microsoft will make the most from WannaCry

#43
post #35
post #30

Earlier quoted context omitted.

Initially through an attachment and subsequently throughm the LAN via SMB. SMB is(was?) enabled by default in Windows Features.

So, if the attack requires you to double-click on virus.exe the NSA exploits everyone is talking about didn't really matter that much did it? Sure, when hitting a large corporation that would obviously help a lot but home networks (which for some reason have been hit quite hard as well) don't even have that many machines to begin with.

The NSA exploits matter because they would be one of the few orgs to have access to multiple zero days. Imagine wannacry paired with a drive by browser exploit.

Re: Microsoft will make the most from WannaCry

#44

Earlier quoted context omitted.

You can contribute to open source and still do bad things: https://theintercept.com/2015/12/28/recently-bought-a-window...

I believe it was a sarcasm. Look at the italic part.

Yes it was. But I am enjoying it.

No one group has a monopoly on knee-jerk reactions, you see.

Re: Microsoft will make the most from WannaCry

#45

Earlier quoted context omitted.

You can contribute to open source and still do bad things: https://theintercept.com/2015/12/28/recently-bought-a-window...

I believe it was a sarcasm. Look at the italic part.

You are correct. Unfortunately I have seen this sentiment used non-sarcastically. what a time to be alive.

Re: Microsoft will make the most from WannaCry

#46
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

Even if we trust Microsoft we cannot trust the government of the USA.

Re: Microsoft will make the most from WannaCry

#47
post #11
post #9

TLDR: Microsoft is using WannaCry as an opportunity to complain about the NSA and as an opportunity to tell people they need to update their software. I personally think that it's great to get the message across that people need to keep their operating systems up-to-date. I see too many non-technical people thinking in dangerous ways: * "I don't want to update software, because the new software could have bugs which…

> * "I've got anti-virus software installed on my computer and we've got a firewall on our network". Which is in large parts due to irresponsible marketing given to these people by AV companies.

Afaik AV wouldn't even protect against WannaCry until after its signature was already in the wild, when it was too late. But Windows update would've prevented the SMB hole by which it spread in networks.

Re: Microsoft will make the most from WannaCry

#48
post #32

Earlier quoted context omitted.

I could agree with the first sentence; the rest...not. (AFAIK, Win10 was not affected by the SMB vulnerability, no?)

Windows doesn't restart after every update for you? You don't believe Microsoft is engaged in propaganda campaigns, specifically the idea that not updating is being a "bad user"? You don't believe that by using Win10, you aren't legitimizing the "OS as Malware" concept and endangering yourself to a huge remote attack surface?

Can't see the original now, someone flagged it. Even so:

- Yes, there are IIRC updates not requiring restart ("not every" "some exist that do not have the property").

- Not updating your existing system is indeed dangerous. Updating your Windows system...is sometimes even more dangerous: I was on the receiving end of "Where do you want to go today? Never mind, you want to upgrade to WinX; stop whining, we know you want it!" That said, there are far more dangerous MS FUD campaigns, I think.

- The final question is quite different to your original claim, IIRC; but yes, Win10 IMNSHO falls squarely under "malware," and thus I'm not using it. Not even using Windows, FWIW. Even better, the GWX fiasco helped me persuade people to move off Windows altogether.

Re: Microsoft will make the most from WannaCry

#49
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

Well, you often have no other choice. You can go out of your way and install an open source OS, but then there might still be a backdoor in your hardware. Ultimatively, this can not be solved technically, but socially. In a country with a strong rule of law and democracy, you should be able to trust that the state builds no backdoors into your devices when they say they don't. And you should be able to trust the manufacturers that they don't do it by themselves. But unfortunately they have incentives to go both ways (short term profit + appeasing governments on the one hand, vs. gaining consumer trust on the other).

I'll go meta here: How can we trust food companies? They have incentives to decieve us, to adulterate their products, produce as cheaply as possible and sell as expensively as possible. There are magazines, websites, that do nothing but test food. It blows my mind when I think about that. How antagonistic is our society, when the people who make our food are working against us. The solution we developed for that are checks and balances in form of journalism and consumer protection laws. Sometimes it works, sometimes not. Whether its adulterants in food or backdoors in software, it's a similar problem.

Re: Microsoft will make the most from WannaCry

#50
post #35

Earlier quoted context omitted.

So, if the attack requires you to double-click on virus.exe the NSA exploits everyone is talking about didn't really matter that much did it? Sure, when hitting a large corporation that would obviously help a lot but home networks (which for some reason have been hit quite hard as well) don't even have that many machines to begin with.

The NSA exploits matter because they would be one of the few orgs to have access to multiple zero days. Imagine wannacry paired with a drive by browser exploit.

Of course, I meant that it didn't matter much in this particular case.

Every news outlet as well as technical sites seems to agree that it was NSA that enabled this attack, but if it all boils down to users opening email attachments that's something else entirely.

Post reply on HN