Earlier quoted context omitted.
The killswitch: https://twitter.com/0xAmit/status/879789734469488642
This confirmed to work? Anyone else speak on this? If so props to the guy who discovered this.
Another Ransomware Outbreak Is Going Global
351–360 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#352Earlier quoted context omitted.
Yep, forced updates + NSL = they don't need 0days anymore.
That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.
While I don't know of that specific scenario, Stuxnet used a hardware vendor's key to install infected drivers[1]. There was also a Chinese registrar that allowed a customer to man-in-the-middle Google[2]. Depending on how Windows organizes their driver updates, I could see an adversary doing a man-in-the-middle between Microsoft and their target, and pushing a bad driver update.
1. https://www.welivesecurity.com/2010/07/22/why-steal-digital-... 2. https://www.techdirt.com/articles/20140909/03424628458/china...
Re: Another Ransomware Outbreak Is Going Global
#353Earlier quoted context omitted.
Only because most organizations don't know how to be effective at security. It's not hard. You don't actually have to change much. You just have to schedule regular pentests, ideally every couple weeks. Pentests protect everyone because it's our job to worry about all of the security flaws that you can't possibly be aware of in your normal day-to-day development cycle. There's just too much for any organization to kn…
"It's not hard." No, it is not, you just need skilled people working on it. Oh, those people want money for it ...
And this also collides with the willingness to do anything to save a couple of dollars and once that dictate isn't flowing through every once of the company's blood, who knows what will happen.
Re: Another Ransomware Outbreak Is Going Global
#354Earlier quoted context omitted.
"It's not hard." No, it is not, you just need skilled people working on it. Oh, those people want money for it ...
Exactly. It's not hard, it just costs some money. It's exactly the same as physical security. You build fences and buy locks. You pay people to keep an eye on things. You take insurance to cover the rest of the risk. Nothing hard, no new inventions required. It just takes some attention and cash. It's part of the cost of being in business.
It's not impossible but it requires a somewhat universal attitude change.
Re: Another Ransomware Outbreak Is Going Global
#355FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)
It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.
Re: Another Ransomware Outbreak Is Going Global
#356My friend's work laptop is a victim of this same attack... all the way here in the Philippines. There was a company wide email blast to disconnect all workstations from the internet at once. Fascinating development
Re: Another Ransomware Outbreak Is Going Global
#357Earlier quoted context omitted.
It does not seem like something wrong directly. I also think showing off might be intention.
They should have pre-loaded more onto the wallet to give the impression that most people are paying. Less than £10K USD gives the impression that nobody is paying. It is the same psychology as a product only getting a couple of two star reviews - you don't buy it, you go for the product with hundreds of 4-5 star reviews instead.
Re: Another Ransomware Outbreak Is Going Global
#358Earlier quoted context omitted.
Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.
And so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.
Re: Another Ransomware Outbreak Is Going Global
#359Earlier quoted context omitted.
You're implying that from March 14, 2000, Windows was very secure. I think you're getting this backwards. If you say 2017, you and your children-comments' dates will be covered, because they are before March 14 2017.
No, the implication is that Windows prior to that was insecure. That does not mean it's secure afterwards, just that we know it was insecure previously. You are extrapolating without evidence.
Re: Another Ransomware Outbreak Is Going Global
#360Earlier quoted context omitted.
Exactly. It's not hard, it just costs some money. It's exactly the same as physical security. You build fences and buy locks. You pay people to keep an eye on things. You take insurance to cover the rest of the risk. Nothing hard, no new inventions required. It just takes some attention and cash. It's part of the cost of being in business.
Wait, the hardness of information security comes because it has to be built-in everywhere since everything is connected and so everything is a potential attack surface. It's not impossible but it requires a somewhat universal attitude change.
It's a positive statement though: it is possible to be constantly secure if you just get a pentest every few weeks. Big companies can even afford to make it a requirement of their release cycle.