Live data from Hacker News

WanaCrypt0r Ransomworm

baesystemsai.blogspot.com

31–40 of 71 posts

Re: WanaCrypt0r Ransomworm

#31
post #15

Earlier quoted context omitted.

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users. It's not like 'stop clicking random shit in emails' is bad advice.

Why the hell can't I click shit in random emails? It's a friggin email and data transfer for crying out loud. Stop blaming users.

One of the things that I personally think is "data" is "software", and I believe that all data should be something that is able to be transferred via e-mail. A sufficient set of random clicks from an e-mail currently can--and in my world view absolutely should be able to--lead to arbitrary code execution without any form of security vulnerability.

Re: WanaCrypt0r Ransomworm

#32
post #22

Did these happenings had any effect on windows market share? Hope somebody will blog on that too. I hope many people have understood to not have public windows servers at least. It could most probably affect their business in the long run (Not saying that GNU/Linux is safe. But it is safer ).

[deleted]

Re: WanaCrypt0r Ransomworm

#33
post #23
post #8

I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me. "As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

1998 was still a great year in Windows world. In 1999 the DotNet vision made lot's of things kind of legacy - kind of, because despite all odds Win32 and shell32/Explorer are still thriving where as DotNet Framework is now officially legacy tech. And UWP hasn't caught on, as mobile is dead end for MS and their Store is incredible bad. True Visual Studio was really great. And like many, one had a VS6 and VB6 install s…

> Back in the 1990s MS was a good company.

It really wasn't.

Re: WanaCrypt0r Ransomworm

#35
post #15

Earlier quoted context omitted.

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users. It's not like 'stop clicking random shit in emails' is bad advice.

Why the hell can't I click shit in random emails? It's a friggin email and data transfer for crying out loud. Stop blaming users.

Because when your run content in executables, in the case of Ransomware its usually Word macros or js files, those programs run with your user rights, which have read/write permissions for your files. Now you lose your files and you expect the IT department to fix everything for you, instead of doing what the IT department says or using common sense.

Funny how that works. You want all the power but none of the responsibility. This is like saying "Why can't I drink bleach, stop criticizing me doctors!"

>It's a friggin email and data transfer

and guns are just tubes which throw lead around, but I certainly don't want to be on the receiving end of one. What's your point? Its incredible to me how many people refuse to believe we live in a world of risk when it comes to information technology and its not all fun and games.

Re: WanaCrypt0r Ransomworm

#36
post #22

Did these happenings had any effect on windows market share? Hope somebody will blog on that too. I hope many people have understood to not have public windows servers at least. It could most probably affect their business in the long run (Not saying that GNU/Linux is safe. But it is safer ).

If you think about it, it's actually safer, from a malware perspective, to use Windows Phone instead of Android. And for the same reason.

Re: WanaCrypt0r Ransomworm

#38
post #24

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

I don't know a single person who would pay upwards of $300 to get their files back if they got hit with ransomware. Hell, I've got something like 10 years of personal files on my machine and I wouldn't pay that much for them. I would bet a lot more people would be willing to pay if the fee was more like $50. That takes it out of the category of 'a lot of money for computer files' for a lot of people and puts it in th…

Hmm, I'd certainly consider it, most based on not wanting to deal with the consequences of formatting the machine and starting again (installing programs, set up various setting/configuration options, etc.)

I can't 100% say I would, but maybe.

Re: WanaCrypt0r Ransomworm

#39

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

"Are peoples files really so worthless, or bitcoin really so hard, or people so untrusting of unencrypt." I think that is super small subset. Average people use a ton of cloud software nowadays: google docs, dropbox etc. Let alone use a desktop for anything besides work. The files they super care about (photos) are usually on their device or scattered all over facebook. Work files/computers, well they don't care abou…

I think its funny that your real last name is Ransom. I wonder if someones last name influences what they focus on in life. In my case, I guess not, I've punished my heart with cheeseburgers more than I care to count, hehe. Maybe I've just focused on it the wrong way.

Re: WanaCrypt0r Ransomworm

#40
post #25

I'm surprised by how carefully the worm seems to be coded. They make sure they have an internet connection, they check for disk space in order not to run out while encrypting, they save a backup copy of the "tasksched" executable before replacing it, they shutdown databases (I assume in order to prevent corruption?) etc... I guess they want to make sure the decryption process will work without any issue so that the v…

[deleted]
Post reply on HN