Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

321–330 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#321

Going through their wallets it looks like they've gotten 32 pay outs, some for more than 300 USD. Are there any addresses that they are using outside of the four listed int he article? It'd be an interesting project to try and track where these funds go and where they came from. https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N... - 11 https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... - 4 htt…

where did you get these addresses from? I only get the 115p address on a retweeted photo from an NHS computer

They were posted in the Kaspersky analysis

https://securelist.com/blog/incidents/78351/wannacry-ransomw...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#322

I am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

From what I've seen, it isn't particularly well written. However, you're probably correct about the encryption being strong.

One of the reasons the infection rates are dropping off is that the malware had some kind of poorly implemented sandbox detection, where it would attempt to resolve a non-existent domain. However, now the domain has actually been registered by a researcher, so now every new infection thinks it's running in a sandbox.

This is the work of someone who doesn't really know what they're doing, and they probably copied a large chunk of the code from somewhere else.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#323

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

Those are not the systems involved in these attacks; the NHS systems compromised were the workstations used by doctors to access patient records and the Samba servers storing those records.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#324

Earlier quoted context omitted.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

He has backups of his data. I personally use linux and my github repo is here[1] where i have a bunch of encryption related projects(zuluCrypt,SiriKali and lxqt_wallet). The last windows computer i used was windows xp. I dont want to move him to linux because i am not always around and he can ask other people for help when he is on windows. [1] https://github.com/mhogomchungu

So reinstall the OS from orbit. It's the only way to be sure.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#327

So If I pay how does the hackers decrypt my HD? Is there a way to sniff the key and pay once - decrypt everywhere?

You send them the code (encrypted key?) from your machine, they send you back the key that works for your machine. If you have multiple computers (as these large organizations do), you need to pay for each one separately; the key for one won't work for the other. Perhaps they offer volume discounts?

Send it how, do they provide an email address and helpfully send it back by return mail? A tor hidden service maybe? I'd have assumed they just take the money without bothering to decrypt anything, but maybe they are looking for repeat customers.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#328

Earlier quoted context omitted.

You send them the code (encrypted key?) from your machine, they send you back the key that works for your machine. If you have multiple computers (as these large organizations do), you need to pay for each one separately; the key for one won't work for the other. Perhaps they offer volume discounts?

Send it how, do they provide an email address and helpfully send it back by return mail? A tor hidden service maybe? I'd have assumed they just take the money without bothering to decrypt anything, but maybe they are looking for repeat customers.

Once it's reported that paying for (your specific one, or even just some) ransomware doesn't give users files back, you loose a lot of money. Ransom only works if it's believable you have something to ransom.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#329
post #310

Earlier quoted context omitted.

To quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by feari…

> Patriotism is both a wonderful and terrible thing I found that hypothesis widely accepted, without so much for it. Patriotism fuses core values like freedom or solidarity with a flag. That's why it is easier to pervert. Patriotism tells people that because there are people born in the same line limits that you, you should be proud of what they do, and you should help them first. Patriotism distorts history. > "Four…

Patriotism was temporarily necessary while we rapidly increased standard of living for ourselves, and didn't have enough resources to do it globally. In the early 21st century it was still a zero sum game on subdecade timescales.

Now we have more than enough resources to provide basics for all 10 billion of us (and decreasing) so patriotism has largely been confined to friendly rivalry around sports and regional cuisine. It was just a matter of mapping out the world's local customs and needs so the resources could be distributed intelligently.

And even at that, only about 4% of GWP goes to basic food, shelter, health, education, and cultural-ecological preservation these days. Entertainment and luxury goods make up the rest. This was unthinkable in the 2020s, but there was a lot of duplication of effort due to the maintenance of corporate moats in the basic sustenance industry at that time.

Sent from my iPhone 16S

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#330

Earlier quoted context omitted.

I definitely agree wrt intentional exploits ("backdoors") to be added. To me this news highlights the need for fundamentally safe software. Just like we might have safety laws in the automotive or airline industry.

If the NHS has been significantly crippled by this, and the NSA is partly at fault, could the NHS successfully sue the NSA in the UK? (edit: my logic and phrasing was really bad)

Now that the U.S. has set an alarming precedent that the Kingdom of Saudi Arabia can be sued in U.S. court over terrorist funding, maybe the U.S. government could be sued.

I don't think they'd win; the ransomware authors and operators are the ones who perpetrated the act. The U.S. government probably wouldn't be found negligent since the software was stolen. NHS carries partial liability since it was negligent with its patching, according to industry-wide IT security standards.

Comparing it to firearms, I can be held partially liable for a wrongful death if I leave my Colt 1911 out on my porch; it's different if a burglar stole my gun safe and committed a crime.

(obligatory disclaimer that I am not a lawyer, I just play one on Hacker News)

Post reply on HN