Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

351–360 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#351
post #296

Earlier quoted context omitted.

The killswitch: https://twitter.com/0xAmit/status/879789734469488642

This confirmed to work? Anyone else speak on this? If so props to the guy who discovered this.

It is, although it isn't really a 'kill switch' in the sense it can't be deployed universally, but per system it works. This could be considered temporary though, as is turning off your computer if infected and NOT turning it back on. The encryption only takes effect after a restart.

Re: Another Ransomware Outbreak Is Going Global

#352
post #132

Earlier quoted context omitted.

Yep, forced updates + NSL = they don't need 0days anymore.

That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.

> That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news.

While I don't know of that specific scenario, Stuxnet used a hardware vendor's key to install infected drivers[1]. There was also a Chinese registrar that allowed a customer to man-in-the-middle Google[2]. Depending on how Windows organizes their driver updates, I could see an adversary doing a man-in-the-middle between Microsoft and their target, and pushing a bad driver update.

1. https://www.welivesecurity.com/2010/07/22/why-steal-digital-... 2. https://www.techdirt.com/articles/20140909/03424628458/china...

Re: Another Ransomware Outbreak Is Going Global

#353

Earlier quoted context omitted.

Only because most organizations don't know how to be effective at security. It's not hard. You don't actually have to change much. You just have to schedule regular pentests, ideally every couple weeks. Pentests protect everyone because it's our job to worry about all of the security flaws that you can't possibly be aware of in your normal day-to-day development cycle. There's just too much for any organization to kn…

"It's not hard." No, it is not, you just need skilled people working on it. Oh, those people want money for it ...

And people skilled at picking the skilled people and a willingness to actually do what the skilled people say... when those skilled people aren't necessarily the same as the managers shouting managementese...

And this also collides with the willingness to do anything to save a couple of dollars and once that dictate isn't flowing through every once of the company's blood, who knows what will happen.

Re: Another Ransomware Outbreak Is Going Global

#354

Earlier quoted context omitted.

"It's not hard." No, it is not, you just need skilled people working on it. Oh, those people want money for it ...

Exactly. It's not hard, it just costs some money. It's exactly the same as physical security. You build fences and buy locks. You pay people to keep an eye on things. You take insurance to cover the rest of the risk. Nothing hard, no new inventions required. It just takes some attention and cash. It's part of the cost of being in business.

Wait, the hardness of information security comes because it has to be built-in everywhere since everything is connected and so everything is a potential attack surface.

It's not impossible but it requires a somewhat universal attitude change.

Re: Another Ransomware Outbreak Is Going Global

#355

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

It's a lot more likely that the attackers make money via the markets than via a direct ransom.

Re: Another Ransomware Outbreak Is Going Global

#356
post #68

My friend's work laptop is a victim of this same attack... all the way here in the Philippines. There was a company wide email blast to disconnect all workstations from the internet at once. Fascinating development

What company in the PH is this?

Re: Another Ransomware Outbreak Is Going Global

#357

Earlier quoted context omitted.

It does not seem like something wrong directly. I also think showing off might be intention.

They should have pre-loaded more onto the wallet to give the impression that most people are paying. Less than £10K USD gives the impression that nobody is paying. It is the same psychology as a product only getting a couple of two star reviews - you don't buy it, you go for the product with hundreds of 4-5 star reviews instead.

Preloading money leaves a paper trail

Re: Another Ransomware Outbreak Is Going Global

#358

Earlier quoted context omitted.

Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.

And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#359

Earlier quoted context omitted.

You're implying that from March 14, 2000, Windows was very secure. I think you're getting this backwards. If you say 2017, you and your children-comments' dates will be covered, because they are before March 14 2017.

No, the implication is that Windows prior to that was insecure. That does not mean it's secure afterwards, just that we know it was insecure previously. You are extrapolating without evidence.

I think it's more accurate to say that the comment is explicitly stating that Windows was insecure prior to that date, the implication from which is that it was not as insecure after (else why make the distinction of the date at all).

Re: Another Ransomware Outbreak Is Going Global

#360

Earlier quoted context omitted.

Exactly. It's not hard, it just costs some money. It's exactly the same as physical security. You build fences and buy locks. You pay people to keep an eye on things. You take insurance to cover the rest of the risk. Nothing hard, no new inventions required. It just takes some attention and cash. It's part of the cost of being in business.

Wait, the hardness of information security comes because it has to be built-in everywhere since everything is connected and so everything is a potential attack surface. It's not impossible but it requires a somewhat universal attitude change.

I want to agree with you in principle, but in practice it's not possible to be secure with just an attitude change. The attack surfaces have grown too large. Keeping track of all possible vectors is a full-time job in itself. You either need a dedicated security person or regular pentests. And honestly, regular pentests are probably more effective.

It's a positive statement though: it is possible to be constantly secure if you just get a pentest every few weeks. Big companies can even afford to make it a requirement of their release cycle.

Post reply on HN