Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

361–370 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#361

Earlier quoted context omitted.

"Your strange theory, that the economical damage is unavoidable to improve security will break down hard if those 0days are used by terrorists for the first time" It's not a "strange theory", it's the literal reason: NatSec is not a strange theory, it's the stated reason by multiple administrators and officials for why this behavior occurs. Plus, how much economic damage was mitigated by using zerodays against terror…

"What if they used a zero day and prevented a 9/11 size 3000 person, multi-billion-dollar terrorist attack?" What if terrorists use a zero day to blow up a nuclear plant?

I'm talking about hypothetical things in the past, you're making up hypotheticals about the future.

Also, I provided a precise example of intelligence compromising ISIS for intelligence regarding airplane bombs, so my example isn't that outlandish.

Re: Another Ransomware Outbreak Is Going Global

#363

Earlier quoted context omitted.

In Ukraine, banking services nationwide as well as credit card payments on the metro in Kiev, and the airport IT systems, are all down. At what point do we call it massive? When US banks and airports start having trouble?

That's interesting. I've heard a lot about Russia testing out cyberwarfare in Ukraine as a possible proving ground for future targets. Was Ukraine the hardest hit by this latest one? It'd be interesting if this were actually made to take down infrastructure under the guise of ransomware.

Ukraine seems to be explicitly targeted, with the initial distribution happening already for some time but having a trigger to start lateral infection (which would be detectable) only 27th June 10:30 ( https://twitter.com/CyberpoliceUA/status/879825132088426499 ) and the actual ransom attacks only some hours after that; so it was intended to spread locally before attracting global attention.

Re: Another Ransomware Outbreak Is Going Global

#364
post #352

Earlier quoted context omitted.

That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.

> That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. While I don't know of that specific scenario, Stuxnet used a hardware vendor's key to install infected drivers[1]. There was also a Chinese registrar that allowed a customer to man-in-the-middle Google[2]. Depending on how Win…

I am talking specifically about a malicious Microsoft-signed OS update in this context.

I fully agree with you regarding general problems which could occur with PKI.

Re: Another Ransomware Outbreak Is Going Global

#365

Kill switch has been found: https://twitter.com/PTsecurity_UK/status/879779707075665922

Why would a ransomware author include a killswitch in their software?

Even ransomeware authors accidentally infect themselves and lose keys.

Re: Another Ransomware Outbreak Is Going Global

#366

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

Great. Maybe we can finally put a price on lack of security protocol.

The article says the ransomware affects even patched Windows boxes. Perhaps what you mean to say is, "Great. Maybe we can finally put a price on using Windows."

Re: Another Ransomware Outbreak Is Going Global

#367

Earlier quoted context omitted.

I used to agree with the "neutral technology" line of reasoning, however I think my view has changed. Everything has an orientation to it, enabling or strengthening certain dynamics, but not others. These characteristics are not static, as they depend on the broader context, and can change rapidly and unpredictably sometimes -- yet they can be quite important and should be considered. I would argue the concept of "pe…

> Everything has an orientation to it This seems true at face value. Consider the cutting edge technology aka as a knife, with an inherent bias for cutting things. Dinner time. Killing time. ("Food is murder"?) It is the context of utility of technology that is the determining factor. A technology, imo, can be deemed directly culpable of ill effects IFF it permits no other utility context other than that which result…

I don't think that's a particularly useful restriction. I think a restriction that factors in the overall utility vs hard of something.

You can pretty much always find a non harmful use for anything so requiring no non harmful users is effectively useless as a criteria.

Re: Another Ransomware Outbreak Is Going Global

#368

Earlier quoted context omitted.

Great. Maybe we can finally put a price on lack of security protocol.

The article says the ransomware affects even patched Windows boxes. Perhaps what you mean to say is, "Great. Maybe we can finally put a price on using Windows."

Patched machines are affected, but they probably weren't the initial entry point. We still rely too much on having a single line of defense.

Re: Another Ransomware Outbreak Is Going Global

#369

Earlier quoted context omitted.

No, the implication is that Windows prior to that was insecure. That does not mean it's secure afterwards, just that we know it was insecure previously. You are extrapolating without evidence.

I think it's more accurate to say that the comment is explicitly stating that Windows was insecure prior to that date, the implication from which is that it was not as insecure after (else why make the distinction of the date at all).

> the implication from which is that it was not as insecure after

I'm saying there is no specific implication without confirmation from the author as the statement can be taken either way, and any you think you see is more to do with your state of mind than the statement itself. It's a statement about what we know. We know something to be factually true prior to that date. Afterwards is open to debate, and is opinion. Making a statement about that the period we have facts for does not imply anything about the period we do not have facts for.

Re: Another Ransomware Outbreak Is Going Global

#370
Wonder if they manage to disable the UK's Trident Nuclear Submarine this time.

"Windows for Warship" https://en.wikipedia.org/wiki/Submarine_Command_System

"Want to Nuke someone, please send Bitcoin to unlock the systems."

https://www.theregister.co.uk/2017/06/27/hms_queen_elizabeth...

Post reply on HN