Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

251–260 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#251

Earlier quoted context omitted.

That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.

"That would never happen" doesn't fly as a security proof.

I will concede that phrasing may be poor, better way to put it is that "forced updates + NSL" would result in detection and a media firestorm, giving absolutely no benefit and obliteration of any trust in Microsoft.

Re: Another Ransomware Outbreak Is Going Global

#252

Earlier quoted context omitted.

That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.

Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.

And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.

Re: Another Ransomware Outbreak Is Going Global

#253

Idea: What if the purpose of these WannaCry style ransomware attacks isn't to get people to pay in Bitcoin, but to drive up the price of Bitcoin?

WannaCry caused the price to drop, rather sharply. If anything, the purpose would be to buy cheap Bitcoins and hope the price later corrects back upwards after the news has blown over. I suspect the price drop is due to some trading algorithms using sentiment analysis. They see all the negative press around these ransomware, see the included word Bitcoin, assume the negative article is about Bitcoin, and automaticall…

I doubt wannacry was the reason for the price drop. Rather extensive media coverage about bitcoin hitting $3k which probably woke up some people who realised that it might be the time to cash in.

Re: Another Ransomware Outbreak Is Going Global

#254

Earlier quoted context omitted.

"That would never happen" doesn't fly as a security proof.

I will concede that phrasing may be poor, better way to put it is that "forced updates + NSL" would result in detection and a media firestorm, giving absolutely no benefit and obliteration of any trust in Microsoft.

It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it.

With that said, you do have individual targets that are suspicious (e.g. https://citizenlab.org/2016/08/million-dollar-dissident-ipho...). There's always risk.

Re: Another Ransomware Outbreak Is Going Global

#255

Earlier quoted context omitted.

(You may or may not be joking; let's assume you're not for this response.) This is a dangerous argument. I'm a free software activist, and I firmly believe that security without free software is a facade, but that doesn't mean that free software is more always more secure; it's an open source argument that's been fairly easily refuted lately with high-profile bugs in software like OpenSSL. It's easier to hide secrets…

So far this year, Windows leads the scorecard regarding mass infections and business downtime due to them. So while indeed, open source is not a guarantee for better security, the results are in its favor. It might also be because it's not such an attractive target to hackers due to its low share in the desktop market. But still there millions of linux servers online 24h/24h and I assume they have a bigger potential…

Windows also leads the score card in installation base, which I think is the real causal relationship. If Linux was installed on 90% of desktops you better well believe there'd be a similar number of exploits for it. Something similar happened to Mac OSX not too long ago, as they grew in popularity more and more exploits were found for the operating system.

Re: Another Ransomware Outbreak Is Going Global

#256
post #253

Earlier quoted context omitted.

WannaCry caused the price to drop, rather sharply. If anything, the purpose would be to buy cheap Bitcoins and hope the price later corrects back upwards after the news has blown over. I suspect the price drop is due to some trading algorithms using sentiment analysis. They see all the negative press around these ransomware, see the included word Bitcoin, assume the negative article is about Bitcoin, and automaticall…

I doubt wannacry was the reason for the price drop. Rather extensive media coverage about bitcoin hitting $3k which probably woke up some people who realised that it might be the time to cash in.

This was long before $3k. The price tanked immediately on May 12th and remained depressed until the 17th which was shortly after the initial outbreak was halted by the domain registration.

Re: Another Ransomware Outbreak Is Going Global

#257

i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…

Bitcoin, if it had arrived about ten years earlier, would have been one way for the people in Venezuela to store some value and it may one day allow people who want to run away from their country to bring more of their wealth with them. However crooks are always going to be among the early adopters, so I my guess i my answer would be that it has limited value, right now.

weird that this gets downvoted, its a good response and i think a worthy point.

Re: Another Ransomware Outbreak Is Going Global

#258

Earlier quoted context omitted.

What change? Are you suggesting that there's a cast iron guaranteed way of saying 'this stuff should be in the OS and nothing else'? If you are suggesting that, are you suggesting the trust root for that particular stack is something other than the vendor? If so who? Take the example of Windows. Let's say they agree to put in a backdoor like DoublePulsar. Microsoft release the official OS and say 'we promise this is…

> so I'm actually quite curious to know how you'd detect a malicious closed source vendor like Microsoft who is working with a TLA to provide backdoor access. "Closed-source" certainly does not mean you cannot see the changes, just that far less people know how to read assembly/machine code to understand what is going on. People frequently reverse engineer patches and updates as addition of features means more vulner…

Thanks.

So to go back to these two points:

> They don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates.

> I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless.

It would seem to me that these things are happening. 0days are being added (often to look like simple bugs) and security companies are detecting them and we're talking about them...eventually. So you're both right, but there's a period of sometimes years following the addition of a backdoor to it being discovered. And the NSA doesn't care too much if it's found as you can be sure it's not the only one as the ShadowBrokers showed.

Take the example in this thread - EternalBlue. That particular flaw was introduced in XP wasn't it? And it survived all this time despite the uncountable security researches pouring over the code for a decade and more. It took a hack to reveal these tools.

Maybe the EternalBlue exploit really did just exploit a bug. Maybe it was a backdoor. It doesn't matter though. If it was a bug, it lay undiscovered for years which means there's plenty of opportunity for an actual backdoor to remain undiscovered too. So we have to deal with the possibility that 'exploitable code' (however it originated) may be around for decades and can be in every system as a result.

Following that logic, a new piece of 'exploitable code' could be added in the next Windows update and it could lay undetected for a decade. It's happened before and we didn't find it until the ShadowBrokers did their work, so it can happen again just as easily.

What about Heartbleed. This was another piece of 'exploitable code' that was around for years undetected. The example of this are no doubt many.

It would seem to me then that there are plenty of cases where a 'backdoor' has been placed and plenty where a genuine mistake was made, but we can't ever really know which is which.

I guess that is the problem for us who talk about it as it encourages taking sides, where the reality is paranoid people are sometimes right in certain cases and cynics who think it's just a bug are right in others.

Re: Another Ransomware Outbreak Is Going Global

#259

Earlier quoted context omitted.

I will concede that phrasing may be poor, better way to put it is that "forced updates + NSL" would result in detection and a media firestorm, giving absolutely no benefit and obliteration of any trust in Microsoft.

It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it. With that said, you do have individual targets that are suspicious (e.g. https://citizenlab.org/2016/08/million-dollar-dissident-ipho... ). There's always risk.

> It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it.

At that point, you'd have to hope the target would not check the hashes of update files. If detected, then there is the same issue: A signed malicious update being detected (and easily verified cryptographically if given to a reporter) would cause a catastrophic media firestorm, eroding trust in the vendor forever.

> With that said, you do have individual targets that are suspicious (e.g. https://citizenlab.org/2016/08/million-dollar-dissident-ipho...). There's always risk.

0-day use against perceived "high value targets" is indeed a possibility and valid concern. No argument at all there.

Re: Another Ransomware Outbreak Is Going Global

#260

Earlier quoted context omitted.

Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.

And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.

> Which means soon it will be mitigated.

It was fixed in a security patch one month before the Shadow Brokers leak. All computers affected by this ransomware outbreak (and WannaCry) were those who decided not to patch.

Post reply on HN