Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

231–240 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#231
post #177

Earlier quoted context omitted.

They don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates. Also Microsoft began to heavily spy onto Windows users as part of normal operation making it difficult to impossible to fully opt out.

I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.

What change?

Are you suggesting that there's a cast iron guaranteed way of saying 'this stuff should be in the OS and nothing else'?

If you are suggesting that, are you suggesting the trust root for that particular stack is something other than the vendor? If so who?

Take the example of Windows. Let's say they agree to put in a backdoor like DoublePulsar. Microsoft release the official OS and say 'we promise this is all good and only stuff that should be in here is in here. Honest.' How do we as third parties detect they've put something in there that shouldn't be?

I see you're CEO of verify.ly and have some background in this, so I'm actually quite curious to know how you'd detect a malicious closed source vendor like Microsoft who is working with a TLA to provide backdoor access.

Re: Another Ransomware Outbreak Is Going Global

#232

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

Maersk Line's login site for customers is down, with a message saying their systems are down.[1] APM Terminals, their business unit which runs ports, has their web site down with a 500 error.[2]

* Los Angeles APM container terminal shut down for today according to press report.[3] No mention of this on APM web site.[4]

* Port Elizabeth (NJ) APM container terminal is down for incoming trucks, according to Port Authority of NY and NJ site.[5] No mention of this on APM web site for the port, so apparently APM web site updates have stopped.

* Mobile (AL) APM container terminal is down.[6]

[1] https://my.maerskline.com/ [2] http://www.apmterminals.com [3] http://www.sgvtribune.com/business/20170627/la-ports-largest... [4] http://www.apmterminals.com/en/operations/north-america/los-... [5] https://www.panynj.gov/port/ [6] http://wkrg.com/2017/06/27/widespread-cyberattack-impacts-co...

Re: Another Ransomware Outbreak Is Going Global

#233

Earlier quoted context omitted.

I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.

Have you installed Windows 10 lately? It's all there in plain English.

I am definitely not a fan of all the default analytics gathered, not cool, but I took "cooperates" to be referencing legitimately malicious software.

Re: Another Ransomware Outbreak Is Going Global

#234

Earlier quoted context omitted.

Great. Maybe we can finally put a price on lack of security protocol.

I dream of seeing a "security first" development process adopted ..

Are you sure about that? You do know most organizations will implement that as a huge amount of bureaucracy for every commit, rather than proper man-hours of security-oriented development.

Re: Another Ransomware Outbreak Is Going Global

#235

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's surprising that the attackers ask victims to send an email. Why not ask victims to publicly post a picture of their screen to social networks with a certain hash tag (and a new account)? That would be less traceable and harder to shut down, I think. Not that I want to give attackers any ideas... :-)

Thanks, we'll give it a go next time.

Re: Another Ransomware Outbreak Is Going Global

#236
post #69

Earlier quoted context omitted.

No, it's probably not a 0-day this time. But this exploit used to be a NSA 0-day before it became public. Everything that's happening now is the "lite" version of what the NSA is capable of.

Yeah, and the Department of Defense is capable of nuking major cities. And it's about as relevant to this discussion.

Let me know when the DoD routinely has their nukes stolen, possibly without them ever knowing.

Re: Another Ransomware Outbreak Is Going Global

#237

Earlier quoted context omitted.

(You may or may not be joking; let's assume you're not for this response.) This is a dangerous argument. I'm a free software activist, and I firmly believe that security without free software is a facade, but that doesn't mean that free software is more always more secure; it's an open source argument that's been fairly easily refuted lately with high-profile bugs in software like OpenSSL. It's easier to hide secrets…

So far this year, Windows leads the scorecard regarding mass infections and business downtime due to them. So while indeed, open source is not a guarantee for better security, the results are in its favor. It might also be because it's not such an attractive target to hackers due to its low share in the desktop market. But still there millions of linux servers online 24h/24h and I assume they have a bigger potential…

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#238
post #61
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

"Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised." March 14 of what year ? I would say 2000 but I am open to discussion ...

Mono cultures always die out. You have 3 dominant loop based OS'es that run most of the World, do you see a problem yet?

Re: Another Ransomware Outbreak Is Going Global

#240

Earlier quoted context omitted.

I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.

What change? Are you suggesting that there's a cast iron guaranteed way of saying 'this stuff should be in the OS and nothing else'? If you are suggesting that, are you suggesting the trust root for that particular stack is something other than the vendor? If so who? Take the example of Windows. Let's say they agree to put in a backdoor like DoublePulsar. Microsoft release the official OS and say 'we promise this is…

> so I'm actually quite curious to know how you'd detect a malicious closed source vendor like Microsoft who is working with a TLA to provide backdoor access.

"Closed-source" certainly does not mean you cannot see the changes, just that far less people know how to read assembly/machine code to understand what is going on.

People frequently reverse engineer patches and updates as addition of features means more vulnerabilities. Security companies generally get a whole lot of free marketing in the press if they find and disclose major vulnerabilities (along with building detection/prevention into their products, so there is a large incentive there. Of course it requires trusting security companies to not hold back findings like that, a valid concern, but it at least a step up from completely trusting the vendor to deliver non-backdoored updates.

> Are you suggesting that there's a cast iron guaranteed way of saying 'this stuff should be in the OS and nothing else'?

The security researcher mindset would be along the lines of "How does this new added/changed functionality work, and how could it be abused?" (You are correct that there is no guaranteed manner to find this, otherwise all software would be un-hackable which is not the case).

Post reply on HN