Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

51–60 of 74 posts

Re: Microsoft will make the most from WannaCry

#51
post #31

Earlier quoted context omitted.

Look at the number of exploits Microsoft has patched in the last 2-3 years. Then realize most of them also apply to XP, and haven't been patched for that OS. Exploiting XP users is incredibly easy.

So patches applied to later editions are a guide to what could be broken in XP.

You are not the first person to figure this out.

Re: Microsoft will make the most from WannaCry

#52
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

We already know windows is malware. There is no question: https://web.archive.org/web/20130622044225/http://blogs.comp... more here: https://www.gnu.org/proprietary/malware-microsoft.en.html

Oh come on, this is stretching the accepting definition of malware a mile and then some.

This is FUD plain and simple without facts to back it up.

Microsoft releasing details of vulnerabilities in advance to premier customers is not something new. All software companies have that practice and we have seen it happen with recent OpenSSL vulnerabilities when CloudFlare has been given advance notice.

Re: Microsoft will make the most from WannaCry

#53
post #29

Earlier quoted context omitted.

EternalBlue CVE-2017-0144 was [edit:allocated/reserved instead of "assigned" per tweet] 2016-09-09. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0144 Source: https://twitter.com/_supernothing/status/864021595303456768 > MS has known about this bug since 09/2016 (when CVE was assigned) and patched in 03/2017. 240day

From the source that that tweet gets the "date" from: >Date Entry Created 20160909 >Disclaimer: The entry creation date may reflect when the CVE-ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE. Do you have a better source for the 240day claim?

I included a link to the tweet's source.

AFAIK, this CVE's "Date Entry Created" is an interesting metadata artifact without any additional significance currently (no futher background info publicly available at this time). I don't know if MITRE makes any additional info (such as "who") public, though I'm sure it is stored somewhere.

I haven't had a chance to review the same value for other CVE's to determine how "normal" it is for the create date to be so long before when the CVE goes public, nor how things correlate for the associated Shadow Brokers fixes.

--

https://twitter.com/thegrugq/status/853142591289802752

> There are no acknowledgements for MS17-10 which patched most of the big bugs from the ShadowBrokers drop.

https://www.renditioninfosec.com/2017/05/call-to-microsoft-t...

> Microsoft has not disclosed how it came to know about the vulnerabilities included in the MS17-010 patch. Microsoft also has not disclosed any information about “in the wild” exploitation of these vulnerabilities.

Re: Microsoft will make the most from WannaCry

#54
post #50

Earlier quoted context omitted.

The NSA exploits matter because they would be one of the few orgs to have access to multiple zero days. Imagine wannacry paired with a drive by browser exploit.

Of course, I meant that it didn't matter much in this particular case. Every news outlet as well as technical sites seems to agree that it was NSA that enabled this attack, but if it all boils down to users opening email attachments that's something else entirely.

The email attachment is the matchstick, the NSA has soaked everything in gasoline, so to speak. Thanks to the zero day, you need one person opening the attachment to infect every machine on the LAN.

You're right about the point of home networks though. Some wild guesses:

- Infected machines that are moved between networks - e.g. a laptop that's used in both public and a private networks BYOD-style.

- The worm also didn't use broadcasts to spread but simply tried out all IP addresses in its subnet. So if an ISP isn't properly isolating its customers, the worm might spread from customer to customer behind the ISP's NAT.

- People are actually that stupid and clicked on the attachment a lot.

Re: Microsoft will make the most from WannaCry

#55
post #16
post #10

Earlier quoted context omitted.

I wonder how much of the never-upgrade mentality is down to Microsoft insisting on being backwards compatible back till basically the Jurassic period, and providing support for obsolete software for years and years. Their intention is commendable, but there's something to be said for sometimes breaking things for what is hopefully the greater good. The rust package manager issue that was on HN the other week comes to…

No people fear updates from M$ because M$ has a bad history of bricking devices and pushing hidden privacy-harming updates without consorting their users. Or maybe it's the fact that Windows has to restart after every single software update. Really it's astounding that Microsoft provides this kind of awful updating experience and then inseminates propoganda into people's minds that those who don't auto update their W…

Would you please not break the guidelines by posting uncivilly like this?

https://news.ycombinator.com/newsguidelines.html

Re: Microsoft will make the most from WannaCry

#56

Earlier quoted context omitted.

We already know windows is malware. There is no question: https://web.archive.org/web/20130622044225/http://blogs.comp... more here: https://www.gnu.org/proprietary/malware-microsoft.en.html

Oh come on, this is stretching the accepting definition of malware a mile and then some. This is FUD plain and simple without facts to back it up. Microsoft releasing details of vulnerabilities in advance to premier customers is not something new. All software companies have that practice and we have seen it happen with recent OpenSSL vulnerabilities when CloudFlare has been given advance notice.

There are no word games here. Malware means software designed to function in ways that mistreat or harm the user.

If storing my disk encryption keys on Microsoft servers isn't harmful to my privacy and security, I don't know what is.

https://theintercept.com/2015/12/28/recently-bought-a-window...

Re: Microsoft will make the most from WannaCry

#57
post #9

TLDR: Microsoft is using WannaCry as an opportunity to complain about the NSA and as an opportunity to tell people they need to update their software. I personally think that it's great to get the message across that people need to keep their operating systems up-to-date. I see too many non-technical people thinking in dangerous ways: * "I don't want to update software, because the new software could have bugs which…

> I see too many non-technical people thinking in dangerous ways

Large IT organizations are just as bad. Instead of patching proactively, they prefer to delay patches indefinitely. Reddit /r/sysadmin and other public forums have been a mess of "which KB do I install to block WannaCry?" type questions for the past several days.

Re: Microsoft will make the most from WannaCry

#58
True or false?

Microsoft is a company that actively tries to prevent any comparisons of its products with other products, sometimes through threats of filing legal proceedings.

True or false?

Only government agencies are capabale of discovering flaws in Microsoft Windows.

True or false?

A closed source kernel is more secure than an open source kernel.

(For the avoidance of doubt, here "open source" means open to public inspection free of charges, terms or conditions, such as various UNIX-like kernels. It also means the right to make changes, re-compile and re-distribute without charges.)

True or false?

This determination can be made without comparing the source code for both kernels.

Hypothetical and questions:

Product A has 5000-6000 new vulnerabilities per year, about 15 per day.

Product B has 5-20 new vulnerabilities per year.

Can we explain this difference by focusing on the parties who find the problems that require patching?

Alternatively, should we focus instead on the products?

What if Product A is more complex is than Product B?

Does this make any difference?

What if Product B can perform many of the same functions as Product A, particularly the functions that are most often used to exploit a vulnerability.

For example handling data to be sent or recieved from the an untrustowrthy network such as the internet. In other words, networking with remote computers ("internet") as opposed to only networking with local computers ("IBM-compatible PC LAN").

Unlike BSD UNIX, Windows was originally designed for only local networking, where very little if any security is required.

True or false?

Windows still retains some of this original design and source code.

That is a trick question because the Windows source code is not open source. How would anyone verify what is still in that source code?

Keeping the source code from the eyes of its users does not protect them.

It may be possible to reverse engineer Microsoft products or patches to learn how Windows works.

"Good guys" may do this as well as "bad guys".

A vulnerability could be discovered by someone who is not even old enough to work for a government.

Repeat question:

Should we focus on who finds flaws in Windows or should we focus on the Windows product itself?

Re: Microsoft will make the most from WannaCry

#60
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

"We only have their word for it."

You do? Where? Does this company warranty anything?

What the user needs is not for Microsoft to improve Windows. At 15 new vulnerabilities a day (source: Microsoft) how can anyone argue with a straight-face that this is not a futile exercise?

What the user needs is choice. More choices of computers that do not have Windows pre-installed.

This monopoly is hurting consumers. It relies on a product that is grossly unfit for one specific area of usage: interfacing with an untrusted network, i.e., the internet. And Microsoft today requires a user to connect their Windows computer to the internet (for "updates" and "upgrades") lest the user be blamed for the product's own flaws when used in this way.

Windows should not be connected to the internet, ever. It is for the LAN only.

Post reply on HN