Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

291–300 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#291

Earlier quoted context omitted.

Your strange theory, that the economical damage is unavoidable to improve security will break down hard if those 0days are used by terrorists for the first time.

"Your strange theory, that the economical damage is unavoidable to improve security will break down hard if those 0days are used by terrorists for the first time" It's not a "strange theory", it's the literal reason: NatSec is not a strange theory, it's the stated reason by multiple administrators and officials for why this behavior occurs. Plus, how much economic damage was mitigated by using zerodays against terror…

"What if they used a zero day and prevented a 9/11 size 3000 person, multi-billion-dollar terrorist attack?"

What if terrorists use a zero day to blow up a nuclear plant?

Re: Another Ransomware Outbreak Is Going Global

#292
post #212
post #111

Earlier quoted context omitted.

Bitcoin is a neutral technology, think of it like cash. Buying illegal things is always done with cash but it doesn't mean we should get rid of cash altogether. Regardless even if we came to the collective decision that we wanted to get rid of bitcoin, its not feasible due to its decentralized nature.

> it doesn't mean we should get rid of cash altogether I can't remember the last time I saw physical cash. The only ones I know who are still using cash are drug dealers. Not saying it should be banned but it's almost gone in my country already.

gigging musicians are paid in cash really often

Re: Another Ransomware Outbreak Is Going Global

#293

Earlier quoted context omitted.

It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it. With that said, you do have individual targets that are suspicious (e.g. https://citizenlab.org/2016/08/million-dollar-dissident-ipho... ). There's always risk.

> It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it. At that point, you'd have to hope the target would not check the hashes of update files. If detected, then there is the same issue: A signed malicious update being detected (and easily verified cryptographically if given to…

A signed malicious update would be a Big Deal(tm), but the entity would also be able to survive it by claiming it was negligence. I don't believe negligence has not been significantly penalized in the marketplace, aside from perhaps CAs where damage can be limited (prevent new certs from being seen as valid, plenty of other options for sites). There's no such option available for penalizing Microsoft, and their lock-in is significant enough to limit nuclear options for doing so.

"We've revoked the signing key that was hacked by blah blah we have the utmost regard for security and adhered to best practices" and everyone would probably gloss over it for one instance.

Re: Another Ransomware Outbreak Is Going Global

#297

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

Is it not cryptographically possible to create a transparent provably-operational decryptor on top of something like ethereum?

Re: Another Ransomware Outbreak Is Going Global

#298

Earlier quoted context omitted.

> It's extremely risky to put out a mass update, yes. But if it were a targeted attack against an individual, the risk is greatly reduced, especially if that individual won't think twice about it. At that point, you'd have to hope the target would not check the hashes of update files. If detected, then there is the same issue: A signed malicious update being detected (and easily verified cryptographically if given to…

A signed malicious update would be a Big Deal(tm), but the entity would also be able to survive it by claiming it was negligence. I don't believe negligence has not been significantly penalized in the marketplace, aside from perhaps CAs where damage can be limited (prevent new certs from being seen as valid, plenty of other options for sites). There's no such option available for penalizing Microsoft, and their lock-…

Their update signing is surely performed using an HSM with strict procedures for getting production builds signed, due to the exceptional sensitivity.

I think you might underestimate the gravity of such a thing happening, it would not be glossed over.

Re: Another Ransomware Outbreak Is Going Global

#299
post #94
post #75

Can someone provide a simple (but not overly so) explanation of how the current generation of ransomware operate i.e., A) spread and B) lock up the computer? Does it always require human intervention for A. ? Thank you.

There are indications that this new version uses a number of ways to spread. Where attacker == the ransomware executable: First is the EternalBlue exploit developed by and leaked from the NSA. EternalBlue exploits a flaw in Windows systems on port 445 TCP that can be used to take complete control of an unpatched system. So if an attacker can connect to a vulnerable Windows machine on port 445 tcp they can take contro…

Thank you for your explanation (also, others below as well). If I had more time I would try and learn about each of these security exploits because I find it fascinating.

Re: Another Ransomware Outbreak Is Going Global

#300

Earlier quoted context omitted.

I sent my first packet-of-death to an unprotected Windows machine in 1996, so...

1997 here :-) hat was that XP xploit app from back then... I cant recall what it was called...

Winnuke? That was way before XP, though, I remember it crashed windows 95 and 98 first edition.
Post reply on HN