Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

271–280 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#271
post #59

Earlier quoted context omitted.

Probably via their smart phones

Is it common to have a list of every employee's mobile phone? I would guess a lot of firms just have informal lists of phone numbers held by managers and colleagues. Plus if there was a list, wouldn't it be on a computer that's currently off?

Most managers would have their reports' mobile numbers. Just start with the C-suite and work down. This is a case of hierarchy actually being an advantage...

Re: Another Ransomware Outbreak Is Going Global

#274

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's not easy (I presume) to create such software. So why do they rely on some random e-mail provider? They could have done it so that computers unlock automatically after the address receives the payment. It's not that hard, the software could use multiple ways to get the private key (DNS, IRC, twitter, DHT) and it would be really hard to shut down.

Re: Another Ransomware Outbreak Is Going Global

#275
post #268

Earlier quoted context omitted.

> The only ones I know who are still using cash are drug dealers I was about to say "that's not true, the pot stores are cash only too", before realizing that from the perspective of the Feds that's the same thing. So I guess my real answer is non-business transactions, like buying things on craigslist, or paying my cat sitter.

> like buying things on craigslist, or paying my cat sitter In my country you send money to other people with an app using their telephone number. It's developed as a joint venture between all banks.

ISTM that's a group that already have more than enough power to screw us over... Has this app been audited?

Re: Another Ransomware Outbreak Is Going Global

#276
post #175

Earlier quoted context omitted.

"0-day" does not mean without human intervention. That just means "previously undisclosed".

I understand that. Which is why I said "usually". Typically when we see news using the term 0-day it's because there was no human element needed in the infection of machines. Thinking back in recent memory (17~ years) I can't remember a time when 0-day was used when it didn't mean autonomous infection. Although. I fully understand that the term means that it's a previously unknown issue. Which is why I chose my words…

It "usually" means "undisclosed". Everything else is entirely circumstantial and coincidental.

The reason human intervention is generally required now is because Windows has been hardened enough that some idiot user has to click a button to bypass the built-in basic protection. There's still a possibility of a "0-day" exploit remote-owning a machine, though these sorts of exploits are a lot harder to craft due to that attack surface being exposed to more security scrutiny.

Re: Another Ransomware Outbreak Is Going Global

#277
post #24
post #19

Earlier quoted context omitted.

This is good for now, but snapshots are like RAID: they are not backups.

They are if you send them offsite. Backups with version history are great if you can swing them.

Startup idea: zfssend.net, a place to send snapshots to As A Service :D

Re: Another Ransomware Outbreak Is Going Global

#278
post #274

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's not easy (I presume) to create such software. So why do they rely on some random e-mail provider? They could have done it so that computers unlock automatically after the address receives the payment. It's not that hard, the software could use multiple ways to get the private key (DNS, IRC, twitter, DHT) and it would be really hard to shut down.

Petya is ransomware-as-a-service, the author gives you the binary payload and unlocking service and it's up to the buyer to distribute / infect people. It often leads to poorly setup things like this where the buyer probably didn't expect their variant to spread so wildly.

Re: Another Ransomware Outbreak Is Going Global

#279
post #268

Earlier quoted context omitted.

> like buying things on craigslist, or paying my cat sitter In my country you send money to other people with an app using their telephone number. It's developed as a joint venture between all banks.

ISTM that's a group that already have more than enough power to screw us over... Has this app been audited?

No idea. The convenience is more important to me personally than the risk of being screwed over but since everyone is using it I presume there are people putting pressure back.

Re: Another Ransomware Outbreak Is Going Global

#280

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

Great. Maybe we can finally put a price on lack of security protocol.

Or on some IT guy being asleep at the wheel...
Post reply on HN