Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

261–270 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#261
post #111

i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…

Bitcoin is a neutral technology, think of it like cash. Buying illegal things is always done with cash but it doesn't mean we should get rid of cash altogether. Regardless even if we came to the collective decision that we wanted to get rid of bitcoin, its not feasible due to its decentralized nature.

I used to agree with the "neutral technology" line of reasoning, however I think my view has changed. Everything has an orientation to it, enabling or strengthening certain dynamics, but not others. These characteristics are not static, as they depend on the broader context, and can change rapidly and unpredictably sometimes -- yet they can be quite important and should be considered.

I would argue the concept of "perfect neutrality" is a non-sequitur. When someone says something is very neutral, it seems to me they are actually noticing that something either has near universal acceptance in the current mind-share or is simply non-consequential such that no one really cares one way or another.

It reminds me "inherent value" (the general philosophical concept, not the financial term with very specific meaning), which a lot of thinkers find to be a misguided concept.

That's not to say we should ban bitcoin. And even if we wanted to, as you said, attempting to do so would be a rather absurd endeavor.

Re: Another Ransomware Outbreak Is Going Global

#262

Earlier quoted context omitted.

And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.

> Which means soon it will be mitigated. It was fixed in a security patch one month before the Shadow Brokers leak. All computers affected by this ransomware outbreak (and WannaCry) were those who decided not to patch.

I suppose with the word "mitigation" kind of already having a connotation in the security community, I probably shouldn't have used it without making clear that I wanted the term to include its more banal implications such as "install the patch" and/or "get your systems off that old-ass OS!"

Re: Another Ransomware Outbreak Is Going Global

#263
post #212
post #111

Earlier quoted context omitted.

Bitcoin is a neutral technology, think of it like cash. Buying illegal things is always done with cash but it doesn't mean we should get rid of cash altogether. Regardless even if we came to the collective decision that we wanted to get rid of bitcoin, its not feasible due to its decentralized nature.

> it doesn't mean we should get rid of cash altogether I can't remember the last time I saw physical cash. The only ones I know who are still using cash are drug dealers. Not saying it should be banned but it's almost gone in my country already.

Wow, out of interest, where do you live? Cash is still going strong in Western Europe.

Re: Another Ransomware Outbreak Is Going Global

#264

Earlier quoted context omitted.

Depends on where you live. I doubt you'd have faced any repercussions for buying that VPN subscription with your credit card, but the governments of other countries might not be so understanding. Bitcoin should exist for the same reasons Tor exists. Just because Tor is used by child predators and of little practical use to the average Western citizen doesn't negate its positive value.

"Just because Tor is used by child predators and of little practical use to the average Western citizen doesn't negate its positive value." you cant just say that and expect me to decide its worth it on balance, you need to make a case for it. maybe this isnt the place, but its a funny thing to just kind of assert. arguing that things should exist because there are potential upsides is missing the point, which is tha…

> its particularly bold to make that claim about tor- there must be a hell of an upside to justify the child predators

Even if Tor didn't exist, there would be child pornography. Would there more, less, or just as much of it? That's difficult to say. It's also difficult to say how much easier it makes the lives of those fighting for freedom of speech. Thus, saying whether Tor is, overall, a "good" or "bad" technology would involve comparing two unknown quantities.

Re: Another Ransomware Outbreak Is Going Global

#265
post #212
post #111

Earlier quoted context omitted.

Bitcoin is a neutral technology, think of it like cash. Buying illegal things is always done with cash but it doesn't mean we should get rid of cash altogether. Regardless even if we came to the collective decision that we wanted to get rid of bitcoin, its not feasible due to its decentralized nature.

> it doesn't mean we should get rid of cash altogether I can't remember the last time I saw physical cash. The only ones I know who are still using cash are drug dealers. Not saying it should be banned but it's almost gone in my country already.

> The only ones I know who are still using cash are drug dealers

I was about to say "that's not true, the pot stores are cash only too", before realizing that from the perspective of the Feds that's the same thing.

So I guess my real answer is non-business transactions, like buying things on craigslist, or paying my cat sitter.

Re: Another Ransomware Outbreak Is Going Global

#266

Earlier quoted context omitted.

It's surprising that the attackers ask victims to send an email. Why not ask victims to publicly post a picture of their screen to social networks with a certain hash tag (and a new account)? That would be less traceable and harder to shut down, I think. Not that I want to give attackers any ideas... :-)

There's so many creative things you can do when you imagine yourself as one of these attackers. - Make a big target amount of money that any large company can pay, eg $10M, and tell people you'll release everyone's key if the amount is raised. - Use an online board like this one to control the state of your network. - Embarrass individual firms by posting pics of their offices from their own webcams. Etc, etc. I reck…

> Make a big target amount of money that any large company can pay, eg $10M

That sounds like a good way to get state level actors on your case.

Re: Another Ransomware Outbreak Is Going Global

#267

Earlier quoted context omitted.

> so I'm actually quite curious to know how you'd detect a malicious closed source vendor like Microsoft who is working with a TLA to provide backdoor access. "Closed-source" certainly does not mean you cannot see the changes, just that far less people know how to read assembly/machine code to understand what is going on. People frequently reverse engineer patches and updates as addition of features means more vulner…

Thanks. So to go back to these two points: > They don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates. > I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. It would seem to me that these things are happening. 0days are being added (often to look like simple bugs) and security companies are detecting them and we…

> So you're both right, but there's a period of sometimes years following the addition of a backdoor to it being discovered. And the NSA doesn't care too much if it's found as you can be sure it's not the only one as the ShadowBrokers showed.

EternalBlue was a vulnerability, not a backdoor, as a backdoor would imply it was intentionally inserted. Again, any proof of malicious code being intentionally inserted would be huge news and would permanently kill trust in the vendor.

> Following that logic, a new piece of 'exploitable code' could be added in the next Windows update and it could lay undetected for a decade. It's happened before and we didn't find it until the ShadowBrokers did their work, so it can happen again just as easily.

This would be huge news. A negative cannot be proven, but it would not really serve much benefit to theorize about intentional backdoor insertion without proof. Anger at something like that is best saved for a provable case (Think of it this way: To a non-tech person, it would be great for them to be able to express outrage/call their reps/etc when there is definitive proof of this, versus saying "oh I heard this was already happening so whatever").

> I guess that is the problem for us who talk about it as it encourages taking sides, where the reality is paranoid people are sometimes right in certain cases and cynics who think it's just a bug are right in others.

There is nothing wrong with being overcautious. Problems arise when worrisome conclusions are reached, causing some (for example) to be unsure about the safety of automatic updates. The effect of this would be users avoiding a perceived risk of a malicious update, yet allowing them to be more exposed to real known vulnerabilities by not installing important security patches.

Re: Another Ransomware Outbreak Is Going Global

#268
post #212

Earlier quoted context omitted.

> it doesn't mean we should get rid of cash altogether I can't remember the last time I saw physical cash. The only ones I know who are still using cash are drug dealers. Not saying it should be banned but it's almost gone in my country already.

> The only ones I know who are still using cash are drug dealers I was about to say "that's not true, the pot stores are cash only too", before realizing that from the perspective of the Feds that's the same thing. So I guess my real answer is non-business transactions, like buying things on craigslist, or paying my cat sitter.

> like buying things on craigslist, or paying my cat sitter

In my country you send money to other people with an app using their telephone number. It's developed as a joint venture between all banks.

Re: Another Ransomware Outbreak Is Going Global

#269

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

The web sites that are supposed to give APM port status are frozen. It appears that many (all?) APM terminals worldwide are not accepting incoming trucks. Unclear whether ships are being unloaded.

There's surprisingly little info about this from the actual ports. Even Twitter output has become so PR-controlled that nobody involved is getting important information out. APM, Maersk, and the Port of Los Angeles all have Twitter feeds, and none of them have any useful info about this. Even the Port of Los Angeles Police have nothing.

The Port Authority of New York and New Jersey has a clue. Their alerts feed has useful info.[1]

    6/27/2017 4:30:08 PM

     APM closed 6/28 & plan to open 6/29 6:00 am, 
     gate hours to 7:00 pm (cut off) 6/29 thru 7/7. 
     Free-time will be extended 2 days due to service impact.
     (The free time extension means customers have two extra days to 
     bring back their empties before being charged.)

    6/27/2017 1:14:23 PM

     Due to extent of system impact, APM Terminals will not be opening 
     for the remainder of the day. Updates on tomorrow's status to follow.

    6/27/2017 9:12:22 AM

     APM is still experiencing system issues. Please delay arrivals.

    6/27/2017 8:58:03 AM

     APM Terminals is still experiencing system issues. Please
     delay arrival until further notice. Updates will follow.

    6/27/2017 7:53:09 AM

     APM Terminals is experiencing system issues and working to 
     restore. Please delay arrival.
Whoever is posting those seems to be the one person on the planet sending out useful info about this. The biggest container terminal on the East Coast is closed today and tomorrow.

[1] http://btt.paalerts.com/recentmessages.aspx

Post reply on HN