Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

61–70 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#61
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

"Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised."

March 14 of what year ?

I would say 2000 but I am open to discussion ...

Re: Another Ransomware Outbreak Is Going Global

#62
post #28

Earlier quoted context omitted.

What a clickbait headline. A paltry $3k and yet the article calls this a "MASSIVE ransomware outbreak". I would be curious to see what a "minor" outbreak is.

There are reports of hundreds to thousands of machines infected across multiple firms in multiple countries. I'd bet >99% of people are never gonna send the $300 in bitcoin to decrypt their machine, instead they'll just clean and restore as much as they can. The $3k is 11 people desperate to restore all their data now, more may come in the future after people have exhausted other options, but the vast majority will n…

Exactly. This is a huge attack. The amounts paid don't mean a thing.

Re: Another Ransomware Outbreak Is Going Global

#63
post #28
post #20

A friend sent me the bitcoin address, they've already collected 2600$. [EDIT] Now 3230$ Source: https://blockchain.info/address/1Mz7153HMuxXTuR2R1t78mGSdzaA...

What a clickbait headline. A paltry $3k and yet the article calls this a "MASSIVE ransomware outbreak". I would be curious to see what a "minor" outbreak is.

The conversion rate is likely very, very low for these, especially so soon after infection.

Re: Another Ransomware Outbreak Is Going Global

#64
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

Re: Another Ransomware Outbreak Is Going Global

#65
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to security exploits even after they've been disclosed and patched.

Re: Another Ransomware Outbreak Is Going Global

#66

Earlier quoted context omitted.

That's not enough anymore: good ransomware will look for backup systems and wipe those out before proceeding. You need read-only, airgapped backups before you can consider yourself safe.

how can they infect an external drive that backed up the data before the infection?

Only if you connect the external drive again during a silent incubation period.

Re: Another Ransomware Outbreak Is Going Global

#67

Earlier quoted context omitted.

That's not enough anymore: good ransomware will look for backup systems and wipe those out before proceeding. You need read-only, airgapped backups before you can consider yourself safe.

A continuous back-up system should be enough --as long as it doesn't have the smarts to reset the encryption pwd on the backup set.

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#69
post #65
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…

No, it's probably not a 0-day this time. But this exploit used to be a NSA 0-day before it became public. Everything that's happening now is the "lite" version of what the NSA is capable of.

Re: Another Ransomware Outbreak Is Going Global

#70
post #12

The Netherlands and various other countries have created laws where either their version of the NSA and/or police can hoard 0days to be used for hacking. This massive outbreak is so widespread that at this stage it appears that it either was a very recent 0day or something which only recently was fixed by a patch. Instead of having loads of countries hoarding security problems I highly encourage a focus on security i…

It is basically WannaCry without the kill switch. It is using the same exploits (EternalBlue). Not some recent zero-day, but sloppy patching.
Post reply on HN