Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

61–70 of 74 posts

Re: Microsoft will make the most from WannaCry

#61
post #54
post #50

Earlier quoted context omitted.

Of course, I meant that it didn't matter much in this particular case. Every news outlet as well as technical sites seems to agree that it was NSA that enabled this attack, but if it all boils down to users opening email attachments that's something else entirely.

The email attachment is the matchstick, the NSA has soaked everything in gasoline, so to speak. Thanks to the zero day, you need one person opening the attachment to infect every machine on the LAN. You're right about the point of home networks though. Some wild guesses: - Infected machines that are moved between networks - e.g. a laptop that's used in both public and a private networks BYOD-style. - The worm also di…

Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly.

So, it would have been game over anyway. The main advantage of a quick attack is likely that if you opt to pay to decrypt you have more infected computers (and sure, laptops - but these details are not exactly game-changing).

Re: Microsoft will make the most from WannaCry

#62
post #18

Earlier quoted context omitted.

Yep. I no longer visit news sites with paywalls, no matter how easily circumvented.

I hope you also don't complain about lack of quality of free content.

Nope.

The quality of free content is quite good, and general the bias of that content is more apparent.

Re: Microsoft will make the most from WannaCry

#63
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

Well, you often have no other choice. You can go out of your way and install an open source OS, but then there might still be a backdoor in your hardware. Ultimatively, this can not be solved technically, but socially. In a country with a strong rule of law and democracy, you should be able to trust that the state builds no backdoors into your devices when they say they don't. And you should be able to trust the manu…

I agree although recent developments in the western world indicate that we're not going down the road of checks and balances e.g. snooper charter in the UK, secret courts in the US.

Re: Microsoft will make the most from WannaCry

#64

Earlier quoted context omitted.

Oh come on, this is stretching the accepting definition of malware a mile and then some. This is FUD plain and simple without facts to back it up. Microsoft releasing details of vulnerabilities in advance to premier customers is not something new. All software companies have that practice and we have seen it happen with recent OpenSSL vulnerabilities when CloudFlare has been given advance notice.

There are no word games here. Malware means software designed to function in ways that mistreat or harm the user. If storing my disk encryption keys on Microsoft servers isn't harmful to my privacy and security, I don't know what is. https://theintercept.com/2015/12/28/recently-bought-a-window...

Bullshit.

I'm going to address your specific link.

Microsoft has different classes of customers and the functionality that you don't want, many customers request and may even require. You aren't obligated to use their disk encryption or functionality. You can install your own WDE product, but you appear to want the features of a Ferrari for the price of a Ford Focus, which is not reasonable.

Microsoft is not trying to mess with your system via that method. If anything, that is a blanket improvement prior by default there was no encryption. Could the design be made better? Maybe, with any implementation of a security feature there are always trade-offs. Microsoft could force users to store the key locally or print it, but then millions of people would simply turn encryption off or lose their key. This does not grant MS remote access to your system.

There are plenty of things that are wrong with MS, but saying Windows is malware is FUD plain and simple.

Re: Microsoft will make the most from WannaCry

#65
post #55
post #16

Earlier quoted context omitted.

No people fear updates from M$ because M$ has a bad history of bricking devices and pushing hidden privacy-harming updates without consorting their users. Or maybe it's the fact that Windows has to restart after every single software update. Really it's astounding that Microsoft provides this kind of awful updating experience and then inseminates propoganda into people's minds that those who don't auto update their W…

Would you please not break the guidelines by posting uncivilly like this? https://news.ycombinator.com/newsguidelines.html

I'm familiar with the guidelines.

Please explain to me what about this was uncivil so that I may do better in the future.

Was it my choice in adjectives? Is "stupid" not an appropriate word on HN? Is it because I had a spelling error? Is it because I displayed a strong negative opinion of something?

Re: Microsoft will make the most from WannaCry

#66

Earlier quoted context omitted.

There are no word games here. Malware means software designed to function in ways that mistreat or harm the user. If storing my disk encryption keys on Microsoft servers isn't harmful to my privacy and security, I don't know what is. https://theintercept.com/2015/12/28/recently-bought-a-window...

Bullshit. I'm going to address your specific link. Microsoft has different classes of customers and the functionality that you don't want, many customers request and may even require. You aren't obligated to use their disk encryption or functionality. You can install your own WDE product, but you appear to want the features of a Ferrari for the price of a Ford Focus, which is not reasonable. Microsoft is not trying t…

Transmitting encryption keys is not a feature any sane person would want. It is convenient. But the fact that it does this in the background is ridiculous.

And your cost comparison is equally absurd. It costs more money to store and manage our keys than it would to just leave them alone.

> Microsoft is not trying to mess with your system via that method

They use other methods to interact with your pc without your permission

1. http://www.informationweek.com/microsoft-updates-windows-wit...

2. http://slated.org/windows_by_stealth_the_updates_you_dont_wa...

Your core dumps are being captured. And then sent to a third party: https://betanews.com/2016/11/24/microsoft-shares-windows-10-...

Default settings let Microsoft capture everything you type and your browsing history: https://web.archive.org/web/20151001035410/https://jonathan....

And don't forget about the NSA key buried in windows: http://www.marketoracle.co.uk/Article40836.html

I am a windows user. I'm just not sure how anyone could claim that an OS that updates without your permission, sends and stores your encryption keys, captures browser history and all keystrokes, etc is not considered malware.

Re: Microsoft will make the most from WannaCry

#67
post #61
post #54

Earlier quoted context omitted.

The email attachment is the matchstick, the NSA has soaked everything in gasoline, so to speak. Thanks to the zero day, you need one person opening the attachment to infect every machine on the LAN. You're right about the point of home networks though. Some wild guesses: - Infected machines that are moved between networks - e.g. a laptop that's used in both public and a private networks BYOD-style. - The worm also di…

Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. So, it would have been game over anyway. The main advantage of a quick attack is likely that if you opt to pay to decrypt you have more infected computers (and sure, laptops - but these details are not exactly game-changing).

> Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly.

That kind would have been orders of magnitude slower though and again dependant on social engineering: The worm would have needed someone do download the executable from the NAS and run it - in the face of usual security practices and anti-virus software looking for exactly that kind of thing - for every single machine. Even then the executable would only have admin privileges at best and probably not even that.

Compare that to the exploit which allowed the worm to execute code on every windows machine in the LAN, with system privileges and without any user interaction needed.

I think the exploit increased both the speed and the likelihood of successful infection by an order that is game-changing: Even if an infection was spotted, by the time countermeasures could have been deployed, the damage had already been done. Because no social engineering was required, even machines with restricted user input or no input at all were at risk (e.g. information screens or specialized hospital equipment).

Re: Microsoft will make the most from WannaCry

#68

Earlier quoted context omitted.

Bullshit. I'm going to address your specific link. Microsoft has different classes of customers and the functionality that you don't want, many customers request and may even require. You aren't obligated to use their disk encryption or functionality. You can install your own WDE product, but you appear to want the features of a Ferrari for the price of a Ford Focus, which is not reasonable. Microsoft is not trying t…

Transmitting encryption keys is not a feature any sane person would want. It is convenient. But the fact that it does this in the background is ridiculous. And your cost comparison is equally absurd. It costs more money to store and manage our keys than it would to just leave them alone. > Microsoft is not trying to mess with your system via that method They use other methods to interact with your pc without your per…

Quoting you, "I'm just not sure how anyone could claim that an OS that updates without your permission, sends and stores your encryption keys, captures browser history and all keystrokes, etc is not considered malware."

I'm making that claim and I don't think you have a clue on how security works.

1. Transmitting encryption keys is something many people want as it removes the overhead of them having to manage them on their own. Businesses use this too (via the cloud) in many cases. As for doing it in the background - how else should it do it? Have a big flashy screen that will confuse the average user? This feature allows Microsoft to gradually raise the bar on its OS security and prevent data recovery from physically stolen devices; while still allowing the user to recover their data if they lock themselves out.

2. The cost comparison is valid. Disk is cheap, and key management should be (this I don't know) automated. Microsoft stores tons of data already (all major software vendors do).

3. Windows Updates should trend towards automation frankly for the consumer versions of the product. Those versions don't have sufficient security features to not get updated.

4. No PII is sent with the core dumps; it's debugging information and helps make the product more secure - that's kind of something you want right?

5. The NSA key is a known falsehood. I'm not even going to bother to address it.

I'm honestly not sure if you're a troll or a rabid conspiracy theorist at this point.

Re: Microsoft will make the most from WannaCry

#69

Earlier quoted context omitted.

Transmitting encryption keys is not a feature any sane person would want. It is convenient. But the fact that it does this in the background is ridiculous. And your cost comparison is equally absurd. It costs more money to store and manage our keys than it would to just leave them alone. > Microsoft is not trying to mess with your system via that method They use other methods to interact with your pc without your per…

Quoting you, "I'm just not sure how anyone could claim that an OS that updates without your permission, sends and stores your encryption keys, captures browser history and all keystrokes, etc is not considered malware." I'm making that claim and I don't think you have a clue on how security works. 1. Transmitting encryption keys is something many people want as it removes the overhead of them having to manage them on…

> Transmitting encryption keys is something many people want

This proves you know absolutely nothing about security. lol. The reason they call them "private" is because you are supposed to keep it a secret. Key management services exist to promote ease of use. And those often include extra layers of protection (eg hsm)

> I'm honestly not sure if you're a troll or a rabid conspiracy theorist

Your logical fallicay is "ad hominem". How is this helping your argument?

I use windows. If I was rabid i'd be on SElinux all day. I'm just not ignorant to volumes of data our computers are leaking.

Re: Microsoft will make the most from WannaCry

#70
post #67
post #61

Earlier quoted context omitted.

Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. So, it would have been game over anyway. The main advantage of a quick attack is likely that if you opt to pay to decrypt you have more infected computers (and sure, laptops - but these details are not exactly game-changing).

> Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. That kind would have been orders of magnitude slower though and again dependant on social engineering: The worm would have needed someone do download the executable from the NAS and run it - in the face of usual security practices and anti-virus software looking for exactl…

> The worm would have needed someone do download the executable from the NAS and run it...

Well, by that time the NAS is lost so it is already game over anyway. Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup (which again, probably is the very same NAS)). It is an inconvenience, sure, but comparatively a minor detail.

Post reply on HN