Live data from Hacker News

WanaCrypt0r Ransomworm

baesystemsai.blogspot.com

51–60 of 71 posts

Re: WanaCrypt0r Ransomworm

#51

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

> 7. Infect a friend. Get a discount on your ransom if you infect a friend and they pay.

This is great lol

Re: WanaCrypt0r Ransomworm

#52

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

"2. Deterministic wallet stores all profit in a simple 12 word seed "password."

You don't want the seed distributed to all victims. There is risk it will be reverse engineered.

There is a way to ge

Re: WanaCrypt0r Ransomworm

#53

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

> 7. Infect a friend. Get a discount on your ransom if you infect a friend and they pay. This is great lol

It exists:

https://www.bleepingcomputer.com/news/security/new-scheme-sp...

Re: WanaCrypt0r Ransomworm

#54
Notable that he calls the "kill-switch" a "mistake". For example, Chrome does the same thing. When it starts it checks for some presumably non-existant domain name.

Re: WanaCrypt0r Ransomworm

#55
Isn't it curious that folks like kim dotcom who do not hold hospitals or anyone to ransom earn global notoriety, are raided by swat teams and face the full force of the law while those that hold hospitals to ransom can operate with impunity with people reduced to tracking their bitcoin earnings on twitter.

Is it the job of NSA and all the global security services with their overarching reach, resources and power to warn, track and disable these activities or is to spy on citizens?

Half or more of these activities are used by agencies to shut down or sabotage unfriendly interests and I suspect that's the only reason these shady figures are allowed to exist, treated with kid gloves, operate with near impunity and rarely see consequences. They serve as 'assets' to provide cover. Without consequences these activities will spiral.

Things like ddos ultimately benefit companies like cloudflare. And the preponderance of these kind of worms force people to move their data to the cloud or give up more control to large companies who promise security. This is a subtle form of extortion. We don't know the extortionists but we do know the beneficiaries.

This slowly but surely disempowers individuals and takes control away and shifts it to large companies.

Holding a hospital ransom whatever its security policies is a serious crime and treating it as just another hack rather than extreme criminality and blaming the victims is an extremely self serving technical perspective.

Re: WanaCrypt0r Ransomworm

#56
post #31

Earlier quoted context omitted.

Why the hell can't I click shit in random emails? It's a friggin email and data transfer for crying out loud. Stop blaming users.

One of the things that I personally think is "data" is "software", and I believe that all data should be something that is able to be transferred via e-mail. A sufficient set of random clicks from an e-mail currently can--and in my world view absolutely should be able to--lead to arbitrary code execution without any form of security vulnerability.

The sets Arbitrary code execution and Security vulnerability have a significant overlap; and much of the decision "do I want the program to do what it's about to do?" is in the eye of the user (e.g. the excellent tools by Nir Sofer could be used for Good or for Evil: "Does the user actually want to list their WiFi network passwords, or is this an evil code the user was tricked into running?" The code has no way of deciding.).

However, I see some hope in https://www.qubes-os.org/ - alas, setting it up is not quite as convenient as "meh, open everything everywhere to everyone."

Re: WanaCrypt0r Ransomworm

#57

Isn't it curious that folks like kim dotcom who do not hold hospitals or anyone to ransom earn global notoriety, are raided by swat teams and face the full force of the law while those that hold hospitals to ransom can operate with impunity with people reduced to tracking their bitcoin earnings on twitter. Is it the job of NSA and all the global security services with their overarching reach, resources and power to w…

> Isn't it curious that folks like kim dotcom who do not hold hospitals or anyone to ransom earn global notoriety, are raided by swat teams and face the full face of the law while those that hold hospitals to ransom can operate with impunity with people reduced to tracking their bitcoin earnings on twitter.

Isn't it curious that people who are known to the authorities are arrested, whereas persons unknown are not? That's your question?

Re: WanaCrypt0r Ransomworm

#58

Isn't it curious that folks like kim dotcom who do not hold hospitals or anyone to ransom earn global notoriety, are raided by swat teams and face the full force of the law while those that hold hospitals to ransom can operate with impunity with people reduced to tracking their bitcoin earnings on twitter. Is it the job of NSA and all the global security services with their overarching reach, resources and power to w…

Isn't it curious that folks like kim dotcom who do not hold hospitals or anyone to ransom earn global notoriety, are raided by swat teams and face the full face of the law while those that hold hospitals to ransom can operate with impunity with people reduced to tracking their bitcoin earnings on twitter.

It's a very classic and widespread law enforcement problem: They catch those who are easiest to catch. There's an anecdote that so beautifully displays this fallacy.

A police officer sees a drunken man intently searching the ground near a lamppost and asks him the goal of his quest. The inebriate replies that he is looking for his car keys, and the officer helps for a few minutes without success then he asks whether the man is certain that he dropped the keys near the lamppost.

“No,” is the reply, “I lost the keys somewhere across the street.” “Why look here?” asks the surprised and irritated officer. “The light is much better here,” the intoxicated man responds with aplomb.

Re: WanaCrypt0r Ransomworm

#59
post #48

Earlier quoted context omitted.

Oh, you can . Just like you can inject any random substance given to you by a stranger. Being aware that both are high risk activities is the point, methinks.

There's absolutely no reason that sending a link to someone should be able to pwn their box. There's no reason to make such fragile email systems.

What if they click the link, run the downloaded invoice.EXE, and enter their password when prompted? At a certain point, the user needs to be educated enough to avoid this.

PDF/Office macros are a whole other topic though.

Re: WanaCrypt0r Ransomworm

#60
post #54

Notable that he calls the "kill-switch" a "mistake". For example, Chrome does the same thing. When it starts it checks for some presumably non-existant domain name.

Yes, but the key difference is that chrome uses a randomly generated domain name, while the ransomware has it hardcoded.
Post reply on HN