Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

381–390 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#381

Earlier quoted context omitted.

The web sites that are supposed to give APM port status are frozen. It appears that many (all?) APM terminals worldwide are not accepting incoming trucks. Unclear whether ships are being unloaded. There's surprisingly little info about this from the actual ports. Even Twitter output has become so PR-controlled that nobody involved is getting important information out. APM, Maersk, and the Port of Los Angeles all have…

And the next relevant update: 6/27/2017 7:11:15 PM As of 6:30 Tues. 6/27, APM Terminals employees are still without email or office telephone services. No emails or voicemails can be accessed or answered. Please standby for PA Alerts or for critical matters please contact Giovanni Antonuccio (908) 966 - 2779.

That's bad. Maersk hasn't been communicating with the shipping industry. Journal of Commerce says nobody is getting useful info about Maersk's status.[1] Now we have a hint as to why - they can't even communicate internally.

The Maersk site still has nothing but a statement that they are down. Maersk's Twitter feed has nothing useful. No press releases. The only useful comments are coming from non-Maersk port employees.

[1] http://www.joc.com/maritime-news/container-lines/maersk-line... [2] http://labusinessjournal.com/news/2017/jun/27/maersk-halts-o...

Re: Another Ransomware Outbreak Is Going Global

#382
post #368

Earlier quoted context omitted.

The article says the ransomware affects even patched Windows boxes. Perhaps what you mean to say is, "Great. Maybe we can finally put a price on using Windows."

Patched machines are affected, but they probably weren't the initial entry point. We still rely too much on having a single line of defense.

My understanding is that patched computers are only affected via pass-the-hash from an unpatched computer.

Re: Another Ransomware Outbreak Is Going Global

#383

Kill switch has been found: https://twitter.com/PTsecurity_UK/status/879779707075665922

Why would a ransomware author include a killswitch in their software?

It's a means to detect sandboxing, either for testing or to foil analysis attempts by third parties.

Re: Another Ransomware Outbreak Is Going Global

#384
post #263
post #212

Earlier quoted context omitted.

> it doesn't mean we should get rid of cash altogether I can't remember the last time I saw physical cash. The only ones I know who are still using cash are drug dealers. Not saying it should be banned but it's almost gone in my country already.

Wow, out of interest, where do you live? Cash is still going strong in Western Europe.

His description matches Sweden

Re: Another Ransomware Outbreak Is Going Global

#385

Earlier quoted context omitted.

Wait, the hardness of information security comes because it has to be built-in everywhere since everything is connected and so everything is a potential attack surface. It's not impossible but it requires a somewhat universal attitude change.

I want to agree with you in principle, but in practice it's not possible to be secure with just an attitude change. The attack surfaces have grown too large. Keeping track of all possible vectors is a full-time job in itself. You either need a dedicated security person or regular pentests. And honestly, regular pentests are probably more effective. It's a positive statement though: it is possible to be constantly sec…

Attitude change in the sense of not being willing to allow inherently insecure architectures - management always moving the company towards secure-on-principle architectures (not that I'm qualified to say if it's a good example but Google's BeyondCorp is an example of aiming to make everything secure on principle meaning not leaky on principle). That added to any pentesting or other necessary immediate security measures.

The impression I have is that today's event was the result of a lot of companies allowing insecure-on-principle architectures like a zillion apps each with their own update structure (random Ukrainian enterprise app supplier gets penetrated and the whole world goes down). A pentester might never be able to find that vector until that app supplier leaves their door open or someone finds out about them for example.

Re: Another Ransomware Outbreak Is Going Global

#386

i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…

> but, i would personally trade that for not having ransomware attacks.

You can't go back in time and "undo" Bitcoin. If you criminalize Bitcoin, crooks might very well continue to use it, if it's their best option. It won't be as financially liquid, of course, but the crooks will just tweak their prices to account for this. Either a more efficient underground payment system will be used, if Bitcoin were criminalized, or Bitcoin would continue to be used.

The proverbial cat's out the bag: crooks have access to Bitcoin code, too, and can easily replicate a blockchain to create CrookCoin. You can't truly prevent criminals from doing stuff using laws, since we call them criminals in the first place because they seemingly have little reverence for laws.

Re: Another Ransomware Outbreak Is Going Global

#387

Earlier quoted context omitted.

> the implication from which is that it was not as insecure after I'm saying there is no specific implication without confirmation from the author as the statement can be taken either way, and any you think you see is more to do with your state of mind than the statement itself. It's a statement about what we know. We know something to be factually true prior to that date. Afterwards is open to debate, and is opinion…

I feel like you and I are not operating on the same definition of implication. In the above comment when using the word implication my intent was "a conclusion that can be drawn despite not being explicitly stated". To be unambiguous, the explicit statement is that computers prior to a specific date should be considered to be compromised. The conclusion that can be drawn, based on the fact that the writer specified t…

> the above comment when using the word implication my intent was "a conclusion that can be drawn despite not being explicitly stated".

Yes, that is the same definition. But it is an error to draw that conclusion in question because it requires unsupported assumptions. That's why it's not implied in the original statement.

> The conclusion that can be drawn, based on the fact that the writer specified that date, is that later dates did not qualify for the same statement, because the conditions were not sufficient.

No, the later dates did not qualify because the knowledge is insufficient, or if you allow that the knowledge was an implicit part of the statement, it's not longer a binary proposition . If there are two true propositions that must be true for the original statement (we were insecure, and we know we were insecure), there are multiple alternatives. The problem is you are assuming a single one of the possible alternatives is implied, when it's not.

For example, I can say "up to this point in life, I haven't committed a felony." That does not imply I plan to commit a felony by itself. With additional context, it may or may not. I could just as easily follow that statement with "I don't see that changing any time soon" as with "I'm not sure if it's likely I'll still be able to say that next year." That additional context combined with the original statement carries the implication. In this case, people are assuming it's along the lines of one of those followups, when there is really no disambiguating context. Assuming one or the other is a problem of the person interpreting the statement, and in my opinion the root cause of quite a few arguments as a result of misunderstanding, which is why I called it out in the first place.

> That is to say, that they were not insecure enough for the writer to include in his comment.

Or they decided for whatever reasons they did not want to mention it. For example, to simplify the message and call attention to what they thought was of greater importance. Don't assume intent without evidence.

> while computers might be compromised after that date, the writer doesn't believe it's worth advising people to ASSUME they are compromised.

Which is a valid stance to have. I don't believe it's useful for the average person that has stayed patched to assume they are compromised. To assume so would mean never logging into any online account in my case. I believe it's useful to assume you are always under some level of attack, whether active or passive, and take precautions, but to assume you are compromised is quite a bit farther than that.

Re: Another Ransomware Outbreak Is Going Global

#388

Wonder if they manage to disable the UK's Trident Nuclear Submarine this time. "Windows for Warship" https://en.wikipedia.org/wiki/Submarine_Command_System "Want to Nuke someone, please send Bitcoin to unlock the systems." https://www.theregister.co.uk/2017/06/27/hms_queen_elizabeth...

The news here was reporting earlier that the Chernobyl monitoring computers were compromised.

Edit: No link, but it was on ABC (Australia) live news, which is pretty reliable. Here is a less reliable source:

https://www.independent.co.uk/life-style/gadgets-and-tech/ne...

Re: Another Ransomware Outbreak Is Going Global

#389
post #388

Wonder if they manage to disable the UK's Trident Nuclear Submarine this time. "Windows for Warship" https://en.wikipedia.org/wiki/Submarine_Command_System "Want to Nuke someone, please send Bitcoin to unlock the systems." https://www.theregister.co.uk/2017/06/27/hms_queen_elizabeth...

The news here was reporting earlier that the Chernobyl monitoring computers were compromised. Edit: No link, but it was on ABC (Australia) live news, which is pretty reliable. Here is a less reliable source: https://www.independent.co.uk/life-style/gadgets-and-tech/ne...

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#390
post #388

Wonder if they manage to disable the UK's Trident Nuclear Submarine this time. "Windows for Warship" https://en.wikipedia.org/wiki/Submarine_Command_System "Want to Nuke someone, please send Bitcoin to unlock the systems." https://www.theregister.co.uk/2017/06/27/hms_queen_elizabeth...

The news here was reporting earlier that the Chernobyl monitoring computers were compromised. Edit: No link, but it was on ABC (Australia) live news, which is pretty reliable. Here is a less reliable source: https://www.independent.co.uk/life-style/gadgets-and-tech/ne...

Is there a public link for that?
Post reply on HN