Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

241–250 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#241
post #132

Earlier quoted context omitted.

Yep, forced updates + NSL = they don't need 0days anymore.

That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.

"That would never happen" doesn't fly as a security proof.

Re: Another Ransomware Outbreak Is Going Global

#242
post #234

Earlier quoted context omitted.

I dream of seeing a "security first" development process adopted ..

Are you sure about that? You do know most organizations will implement that as a huge amount of bureaucracy for every commit, rather than proper man-hours of security-oriented development.

Only because most organizations don't know how to be effective at security.

It's not hard. You don't actually have to change much. You just have to schedule regular pentests, ideally every couple weeks.

Pentests protect everyone because it's our job to worry about all of the security flaws that you can't possibly be aware of in your normal day-to-day development cycle. There's just too much for any organization to know about except security companies. This way you can focus on development and we can focus on pointing out how to fix what's broken.

Re: Another Ransomware Outbreak Is Going Global

#243

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's surprising that the attackers ask victims to send an email. Why not ask victims to publicly post a picture of their screen to social networks with a certain hash tag (and a new account)? That would be less traceable and harder to shut down, I think. Not that I want to give attackers any ideas... :-)

I've seen variants that use Bitmessage and other anonymous messengers before.

Re: Another Ransomware Outbreak Is Going Global

#244

Earlier quoted context omitted.

I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.

I honestly cannot tell if this is brilliant sarcasm or if you'be somehow missed all the "very loud discussion" about Windows 10 on HN. :)

If you are referring to the level of analytics gathered, I fully agree! My point is, there would be a similarly loud reaction (at a wider scale) if a backdoor were introduced.

Re: Another Ransomware Outbreak Is Going Global

#245

How can one check quickly if his OS is vulnerable ? I know MS pushed updates, but sometimes updates are stuck, or fail to install or are delayed by the user .. so

Just do a Windows Update -> Update History and see if you have a cumulative update after 5/24.

https://imgoat.com/uploads/2e74f10e03/26813.png

Re: Another Ransomware Outbreak Is Going Global

#246

Earlier quoted context omitted.

It's relevant because it's like the nukes were stolen and that it will continue to happen

I'd argue its relevant because you can't CTRL+C CTRL+V a nuke.

But would you download a car?

Re: Another Ransomware Outbreak Is Going Global

#247

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's surprising that the attackers ask victims to send an email. Why not ask victims to publicly post a picture of their screen to social networks with a certain hash tag (and a new account)? That would be less traceable and harder to shut down, I think. Not that I want to give attackers any ideas... :-)

There's so many creative things you can do when you imagine yourself as one of these attackers.

- Make a big target amount of money that any large company can pay, eg $10M, and tell people you'll release everyone's key if the amount is raised.

- Use an online board like this one to control the state of your network.

- Embarrass individual firms by posting pics of their offices from their own webcams.

Etc, etc. I reckon talking about these sorts of things will help find solutions rather than just inspire the bad guys.

Re: Another Ransomware Outbreak Is Going Global

#248
post #63
post #28

Earlier quoted context omitted.

What a clickbait headline. A paltry $3k and yet the article calls this a "MASSIVE ransomware outbreak". I would be curious to see what a "minor" outbreak is.

The conversion rate is likely very, very low for these, especially so soon after infection.

You are right. I misjudged.

Re: Another Ransomware Outbreak Is Going Global

#249
post #119

i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…

Bitcoin hasn't enabled ransomware. There was ransomware before.

How did that work? Sending money via western union? Wouldn't work in a large scale operation.
Post reply on HN