Biodun Iginla, BBC News

Biodun Iginla, BBC News
Showing posts with label global ransomware. Show all posts
Showing posts with label global ransomware. Show all posts

Monday, May 15, 2017

Global cyber attack: who is to blame?--analysis


by Tamara Kachelmeier and Biodun Iginla, France24 Technology reporters, New York


    NEW YORK - 
    Questions are swirling over who is responsible for the security flaws exploited by hackers in the world's biggest ransomware attack to date, which crippled thousands of businesses and public organizations around the world. Here are some answers:
    - Who bears the blame? -
    Because hackers exploited a security hole in some Windows versions discovered by the National Security Agency, Microsoft says the intelligence agency bears some responsibility.
    "This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem," Microsoft president and general counsel Brad Smith said in a weekend blog post.
    Steven Weber, faculty director at the Center for Long-Term Cybersecurity at the University of California, said "the fault is pretty distributed -- there are plenty of people to blame."
    Weber said the NSA's primary mission is intelligence: "If I were sitting at the NSA I would push that argument right back to Microsoft," he argued. "They would say, 'It's our job to stockpile those weapons and use them against our adversaries.'"
    Other factors were the large number of old, outdated software programs in use and often ineffective security systems.
    Cornell University computer scientist Stephen Wicker blamed "profound ethical lapses" both on the part of the US government and the computing public.
    The flaws "were known to the NSA and CIA, but were kept secret by those organizations to be exploited for their own data collection purposes," Wicker said.
    But he added that a large number of businesses and other users failed to install a patch issued by Microsoft in March.
    "This 'free-rider' problem -- some manufacturers and users choosing to enjoy the benefits of the internet without taking the time and effort to maintain secure computing systems -- is also unethical, and is a problem that will get much worse as the Internet of Things (IoT) continues to grow," Wicker said.
    - How did hackers get this tool? -
    Microsoft effectively confirmed what many analysts have stated, that the ransomware known as "WannaCry" was designed to exploit NSA software that was leaked earlier this year by a group calling itself Shadow Brokers.
    President Vladimir Putin has said Russia -- which has been accused of cyber meddling in several countries -- had nothing to do with the massive cyberattack, and criticized the US intelligence community for creating the original software.
    But Bruce Schneier, chief technology officer for IBM Resilient Systems, has suggested that a state-sponsored actor, most likely Russia, was probably responsible for the initial hack of the NSA.
    "Whoever got this information years before and is leaking it now has to be capable of hacking the NSA and/or the CIA, and willing to publish it all," Schneier said in a recent blog post.
    "The list of countries who fit both criteria is small: Russia, China, and... and... and I'm out of ideas."
    James Lewis, a cybersecurity specialist with the Center for Strategic and International Studies, said he believes the exposure of the flaw likely "leads back to Moscow" -- but that the hackers who designed the malware are probably not Russian.
    "One of the rules in Russia is that Russian criminals are not allowed to hack Russian targets," Lewis said. "This does not fit the pattern of Russian-sponsored activity."
    "The cybercrime market is really innovative," he added, "and they are quick to take advantage of vulnerabilities."
    - What about computer security at large? -
    The attacks came a day after US President Donald Trump signed an executive order calling for improved cybersecurity in the federal government and better cooperation with the private sector.
    But few see this or any single initiative as a silver bullet.
    Weber said the attacks show the risks of an overreliance on computerized systems that are not fully secure.
    "We have built an increasingly digital society on a very insecure foundation and we are starting to see the consequences of that," he said.
    Weber warned there is no single entity capable of fixing this problem in the near future, since security depends on so many factors.
    "If you want to look for an upside, it would be this would be a wakeup call," to improve computer security, he said.
    At the same time, Weber noted that the attack could prompt more people to shun digital technology and turn back to analog systems that can't be hacked.
    Weber said there are already some signs that the public is losing confidence in the digital world as a result of security problems.
    "For Silicon Valley and technology companies, their future depends on these underlying systems working," he said.


    Saturday, May 13, 2017

    BREAKING: Europol says cyber-attack was unprecedented in scale

    May 13, 2017  19H:42  GMT/UTC/ZULU TIME

    • 2 hours ago
    •  
    • From the sectionEurope
    WannaCryImage copyrightWEBROOT
    Image captionThe ransomware has been identified as WannaCry - here shown in a safe environment on a security researcher's computer
    by Elodie Bagnol, Tamara Kachelmeier, and Biodun Iginla, Technology reporters, BBC News, London
    A cyber-attack that hit organisations worldwide including the UK's National Health Service was "unprecedented", Europe's police agency says.
    Europol also warned a "complex international investigation" was required "to identify the culprits".
    Ransomware encrypted data on at least 75,000 computers in 99 countries on Friday. Payments were demanded for access to be restored.
    European countries, including Russia, were among the worst hit.
    Although the spread of the malware - known as WannaCry and variants of that name - appears to have slowed, the threat is not yet over.
    Europol said its cyber-crime team, EC3, was working closely with affected countries to "mitigate the threat and assist victims".
    Media captionNHS cyber attack: "My heart surgery was cancelled"
    In the UK, a total of 48 National Health trusts were hit by Friday's cyber-attack, of which all but six are now back to normal, according to the Home Secretary Amber Rudd.
    The attack left hospitals and doctors unable to access patient data, and led to the cancellation of operations and medical appointments.
    Map

    Who else has been affected by the attack?

    Some reports say Russia has seen more infections than any other country. Banks, the state-owned railways and a mobile phone network were hit.
    Russia's interior ministry said 1,000 of its computers had been infected but the virus was swiftly dealt with and no sensitive data was compromised.
    In Germany, the federal railway operator said electronic boards had been disrupted; people tweeted photos of a ticket machine.
    France's carmaker Renault was forced to stop production at a number of sites.
    Other targets have included:
    • Large Spanish firms - such as telecoms giant Telefonica, and utilities Iberdrola and Gas Natural
    • Portugal Telecom, a university computer lab in Italy, a local authority in Sweden
    • The US delivery company FedEx
    • Schools in China, and hospitals in Indonesia and South Korea
    Coincidentally, finance ministers from the G7 group of leading industrial countries had been meeting on Friday to discuss the threat of cyber-attacks.
    They pledged to work more closely on spotting vulnerabilities and assessing security measures.

    Read more:

    How did it happen and who is behind it?

    The malware spread quickly on Friday, with medical staff in the UK reportedly seeing computers go down "one by one".
    NHS staff shared screenshots of the WannaCry programme, which demanded a payment of $300 (£230) in virtual currency Bitcoin to unlock the files for each computer.
    The infections seem to be deployed via a worm - a program that spreads by itself between computers.
    Most other malicious programs rely on humans to spread by tricking them into clicking on an attachment harbouring the attack code.
    By contrast, once WannaCry is inside an organisation it will hunt down vulnerable machines and infect them too.
    Media captionThe BBC's Rory Cellan Jones explains how Bitcoin works
    It is not clear who is behind the attack, but the tools used to carry it out are believed to have been developed by the US National Security Agency (NSA) to exploit a weakness found in Microsoft's Windows system.
    This exploit - known as EternalBlue - was stolen by a group of hackers known as The Shadow Brokers, who made it freely available in April, saying it was a "protest" about US President Donald Trump.
    A patch for the vulnerability was released by Microsoft in March, which would have automatically protected those computers with Windows Update enabled.
    Media captionWhat is ransomware?
    Microsoft said on Friday it would roll out the update to users of older operating systems "that no longer receive mainstream support", such Windows XP (which the NHS still largely uses), Windows 8 and Windows Server 2003.
    The number of infections seems to be slowing after a "kill switch" appears to have been accidentally triggered by a UK-based cyber-security researcher tweeting as @MalwareTechBlog.
    But in a BBC interview, he warned that it was only a temporary fix. "It is very important that people patch their systems now because there will be another one coming and it will not be stoppable by us," he said.
    Media captionHow a computer expert managed to slow the spread of WannaCryptor

    'Accidental hero' - by Chris Foxx, technology reporter
    The security researcher known online as MalwareTech was analysing the code behind the malware on Friday night when he made his discovery.
    He first noticed that the malware was trying to contact an unusual web address but this address was not connected to a website, because nobody had registered it.
    So, every time the malware tried to contact the mysterious website, it failed - and then set about doing its damage.
    MalwareTech decided to spend £8.50 ($11) and claim the web address. By owning the web address, he could also access analytical data. But he later realised that registering the web address had also stopped the malware trying to spread itself.
    "It was actually partly accidental," he told us at the BBC.

    Have you or your company been affected by the cyber-attack? Email us at haveyoursay@bbc.co.uk
    You can also contact us in the following ways:
    • Tweet: @BBC_HaveYourSay
    • WhatsApp: +447555 173285
    • Text an SMS or MMS to 61124 (UK) or +44 7624 800 100 (international)
    Or use the form below
    Your contact details
    If you are happy to be contacted by a BBC journalist please leave a telephone number that we can contact you on. In some cases a selection of your comments will be published, displaying your name as you provide it and location, unless you state otherwise. Your contact details will never be published. When sending us pictures, video or eyewitness accounts at no time should you endanger yourself or others, take any unnecessary risks or infringe any laws. Please ensure you have read the terms and conditions.

    More on this story

    Europe