Could someone write a whitehat worm or virus to get into all those vulnerable Windows systems and close the door behind them by patching the hole?
Another Ransomware Outbreak Is Going Global
311–320 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#312Earlier quoted context omitted.
They don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates. Also Microsoft began to heavily spy onto Windows users as part of normal operation making it difficult to impossible to fully opt out.
I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.
To make a long story short: From what anyone can tell, there is no way for consumers to obtain a version of windows that has security patches and has the ability to run with sane privacy settings. There is an acceptable version called Windows LTSB, but you have to pirate it.
This has been discussed ad nauseum on HN and elsewhere.
Re: Another Ransomware Outbreak Is Going Global
#313Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…
Great. Maybe we can finally put a price on lack of security protocol.
Re: Another Ransomware Outbreak Is Going Global
#314Earlier quoted context omitted.
Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.
And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.
Re: Another Ransomware Outbreak Is Going Global
#315Earlier quoted context omitted.
That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.
Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.
Says who? We have no idea what they're sitting on, even our guesses come from terrible data.
Re: Another Ransomware Outbreak Is Going Global
#316Could someone write a whitehat worm or virus to get into all those vulnerable Windows systems and close the door behind them by patching the hole?
Software virus vaccines - I like it. Can’t believe I’ve never run across the concept before. Must be a thing, no?
Re: Another Ransomware Outbreak Is Going Global
#317Is anyone aware of an entity that attempts to objectively quantify the economic impact of an event like this (ransoms paid, data lost, labor hours lost, new security costs, etc)?
Re: Another Ransomware Outbreak Is Going Global
#318Earlier quoted context omitted.
It is basically WannaCry without the kill switch. It is using the same exploits (EternalBlue). Not some recent zero-day, but sloppy patching.
Seems like there is a kill switch: https://twitter.com/PTsecurity_UK/status/879779707075665922
Re: Another Ransomware Outbreak Is Going Global
#319Earlier quoted context omitted.
Great. Maybe we can finally put a price on lack of security protocol.
OSHA violation in 2025: operator was not using a deterministic operating system
Re: Another Ransomware Outbreak Is Going Global
#320On a related note, I don't understand the reason behind transactions like this: https://blockchain.info/tx/9778c698f3f2a2c9b9e9f0fdea3c96e8f... Is there something special about using numerous senders like that?