Live data from Hacker News

Microsoft will make the most from WannaCry

ft.com

71–74 of 74 posts

Re: Microsoft will make the most from WannaCry

#71
post #27

Despite their posturing, how can we trust Microsoft (and other companies like it) ? Windows is a black box. How do we know that there are no backdoors/spying routines to please some governments ? How can we trust that it behaves ethically with all the data it collects ? We only have their word for it.

Well, you often have no other choice. You can go out of your way and install an open source OS, but then there might still be a backdoor in your hardware. Ultimatively, this can not be solved technically, but socially. In a country with a strong rule of law and democracy, you should be able to trust that the state builds no backdoors into your devices when they say they don't. And you should be able to trust the manu…

> there might still be a backdoor in your hardware

But, at least, not in the software. That's a large part of the attack surface that just isn't there.

Re: Microsoft will make the most from WannaCry

#72
post #70
post #67

Earlier quoted context omitted.

> Even without the zero-day it would have spread to whatever NAS was used and eventually encrypt and possibly spread - though just not as quickly. That kind would have been orders of magnitude slower though and again dependant on social engineering: The worm would have needed someone do download the executable from the NAS and run it - in the face of usual security practices and anti-virus software looking for exactl…

> The worm would have needed someone do download the executable from the NAS and run it... Well, by that time the NAS is lost so it is already game over anyway. Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup (which again, probably is the very same NAS)). It is an inconvenience, sure, but comparatively a minor detail.

> Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup [...])

That's a very broad assertion. Maybe that's true in a setup where everyone uses thin clients, but in the usual case, there is still enough friction on Windows to using network shares that many people will have local copies of the files they work with. Also, a NAT is probably the fist thing you'd hook up to a backup - if you're not using a cloud service anyway.

Finally, the workstation itself is absolutely important. If only the NAS were affected you could at least keep working with what's left. Some machines are also specialized, e.g. info screens, ATMs, PoS terminals, hospital equipment...

Re: Microsoft will make the most from WannaCry

#73
post #72
post #70

Earlier quoted context omitted.

> The worm would have needed someone do download the executable from the NAS and run it... Well, by that time the NAS is lost so it is already game over anyway. Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup (which again, probably is the very same NAS)). It is an inconvenience, sure, but comparatively a minor detail.

> Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup [...]) That's a very broad assertion. Maybe that's true in a setup where everyone uses thin clients, but in the usual case, there is still enough friction on Windows to using network shares that many people will have local copies of the files they work with. Also, a NAT is probably the fist thing you'd hook…

Info screens, ATMs etc. are easily reimaged though - no data loss.

Anyway: http://baesystemsai.blogspot.se/2017/05/wanacrypt0r-ransomwo...

The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff.

There is also a working theory that initial compromise may have come from SMB shares exposed to the public internet. Results from Shodan show over 1.5 million devices with port 445 open – the attacker could have infected those shares directly.

Surprisingly large amount of SMB shares exposed directly to internet, that would of course be a great starting point.

Re: Microsoft will make the most from WannaCry

#74
post #73
post #72

Earlier quoted context omitted.

> Nothing of value is stored on individual workstations (and if they do they ought to have some form of backup [...]) That's a very broad assertion. Maybe that's true in a setup where everyone uses thin clients, but in the usual case, there is still enough friction on Windows to using network shares that many people will have local copies of the files they work with. Also, a NAT is probably the fist thing you'd hook…

Info screens, ATMs etc. are easily reimaged though - no data loss. Anyway: http://baesystemsai.blogspot.se/2017/05/wanacrypt0r-ransomwo... The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff. There is also a working theory that initial compromise may have come from SMB sh…

> Info screens, ATMs etc. are easily reimaged though - no data loss.

Indeed. I figure the damage in that case is more lost time and bad publicity (lots of photos showing the ransom note on public screens)

> The initial infection vector is still unknown [...] SMB shares exposed to the public internet

That's interesting. I wasn't aware of that but I agree, it would explain the quick spreading much better.

Post reply on HN