Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

331–340 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#331

Earlier quoted context omitted.

You send them the code (encrypted key?) from your machine, they send you back the key that works for your machine. If you have multiple computers (as these large organizations do), you need to pay for each one separately; the key for one won't work for the other. Perhaps they offer volume discounts?

Send it how, do they provide an email address and helpfully send it back by return mail? A tor hidden service maybe? I'd have assumed they just take the money without bothering to decrypt anything, but maybe they are looking for repeat customers.

Depends on the particular malware, but generally it will direct you to a (tor) website explaining the details, often with newbie-friendly guides on how to set up the accounts needed to buy and transfer bitcoin.

They generally do offer a way to decrypt, it's a long term business for them, not a one-time prank; and the results matter - first, the "audience" who are willing and able to pay generally have multiple devices, and they won't pay for the dozen other devices if the first "trial" device isn't successfully decrypted, and second, the infection spreads over victim's contacts - so your buddy who also got the malware managed to decrypt, you're more likely to pay, and if your buddy paid and failed to decrypt, the crooks won't get a dime from you.

There are all kinds of options. For example, one piece of malware offered to decrypt two files of your choosing for free when you contacted them, just to show that they can do so, as a 'teaser' before paying the full amount.

Besides, why wouldn't they decrypt? It's not like it costs them anything or takes much effort; if they have the ability but wouldn't send the keys, then that's just hurting their business "PR/advertising" for no reason whatsoever.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#332
post #78
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

Many years ago, early days of War on Terror, there were 'cyberstorm' exercises by the TLAs of the U.S. military allegedly on some mythical networks that were not 'the internet'.

In 2006 this involved a nice virus that sent all your photos and emails off to people they were not intended to go to, there was a psychological aspect to what was going on with this payload plus a full spectrum dominance aspect - the media were briefed with the cover story but I don't think any journalists deliberately infected a machine to see for themselves.

At the same time that this was going on there were some computer virus problems in U.K. hospitals, those same Windows XP machines they have today. The Russian stock market was taken down around this time too.

Suspiciously I tried to put two and two together on this, but with 'fog of war' you can't prove that the correlation = causation. The timing was uncanny though, a 'cyberstorm' exercise going on at the same time that the BBC News on TV was showing NHS machines taken out by virus.

https://www.dhs.gov/cyber-storm-i

http://www.telegraph.co.uk/news/uknews/1510781/Computer-bug-...

So that was in 2006. A decade ago. If you found a hole in a hospital roof a decade ago they would have had ample opportunity to fix it. They had a good warning a decade ago, things could have changed but nothing did.

I had the pleasure of a backroom tour of a police station one night, don't ask why, luckily I was a 'compliant' person, no trouble at all, allowed to go home with no charges or anything at all. An almost pleasant experience of wrongful arrest, but still with the fingerprints taken - I think it is their guest book.

Every PC I saw was prehistoric. The PC for taking mugshots was early 1990's, running Windows 95 or 98. I had it explained to my why things were so decrepit.

Imagine if during the London riots of 2011 if the PCs PC network had been taken down with all of that police bureaucracy becoming unworkable?!? I believe that the police computers are effectively in the same position as the NHS, with PCs dedicated to one task, e.g. mugshots, and that a take down of this infrastructure would just ruin everything for the police. I think that targeting the UK police and getting their computers compromised (with mugshots, fingerprints, whatever) and then asking the police to pay $$$ in bitcoin before they were locked out for good next week, that would have made me chuckle with schadenfreude.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#333
post #34

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

The computer systems affected by the NHS ransomware incident weren't medical devices; they were patient records servers and emergency receptionist workstations. No excuse for failure to patch.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#334
post #280

Earlier quoted context omitted.

Good time to remind folks that gmail, facebook, whatsapp, amazon etc aren't going to be able to protect their data forever at the levels they currently are capable off. A couple of bad business decisions and they are where yahoo is today. So be smart about how you use these services and educate the non-technical folks around you.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

Just make sure whatever email provider you use offers IMAP and use a client like Thunderbird to keep a local copy in sync. Back that up somewhere safe and you're fine. If you need good, fast search, use something like X1.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#335

Earlier quoted context omitted.

I would say that it's probably smart to occasionally purge all your content from online services and keep your data in cold storage you physically control.

There is quite a large cost to that, though. Being able to search through old emails is a lifesaver. I can't count how many times I have searched through email to find some account info I set up years ago, or to get date information about when something happened. Just today, I searched my email for my old FastTrak account info, and found it on an email from 5 years ago. Deleting all my email would be a big cost to pa…

You can download/store your email to a medium that you control, like a portable hard drive. Storing email online invites theft and can provide hackers with personal information that can be mined for personal info.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#336

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In the article, it mentioned that patient records servers and patient inprocessing workstations were affected. No mention was made about medical devices.

Workstations absolutely should be patched with security updates. Running an intranet-wide update server is non-trivial, but is well within the reach of a competent sysadmin. And failing to do it is negligent.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#337
post #310

Earlier quoted context omitted.

To quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by feari…

> Patriotism is both a wonderful and terrible thing I found that hypothesis widely accepted, without so much for it. Patriotism fuses core values like freedom or solidarity with a flag. That's why it is easier to pervert. Patriotism tells people that because there are people born in the same line limits that you, you should be proud of what they do, and you should help them first. Patriotism distorts history. > "Four…

It's even stronger than that; it's tribal. It affects political affiliations as well; once you've identified yourself as part of a group, you're more inclined to take on group's opinions, and you start to feel knee-jerk disgust at the rationales of the opposing side.

Keep the temperature up, and it eventually leads to civil war, just like amped up patriotism / nationalism leads to wars between states.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#338

Earlier quoted context omitted.

I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?

You don't have to worry about tumbling anymore. You can use XMR.to, Shapeshift.io, or Changelly.com over TOR to move funds directly into another another blockchain currency. So have fun following things around Bitcoin blockchain like some high tech sleuth, but thats a wild goose chase. I buy all my cryptocurrencies through those kind of services nowadays, because there's no risk or temptation to keep coins on custodi…

> I'm actually surprised that the ransomware isn't taking Monero directly yet as some exchanges have direct Monero/USD markets already.

Buying Bitcoin is much easier

Post reply on HN