Ransomware – NO ONE WINS

Ransomware – NO ONE WINS

Last week's Ransomware attack is just a reminder on how fragile our computer systems are how depended and vulnerable we all are because of that.

It only took 24-48 hours to spread this Ransomware to 100,000 machines in 150 countries before it was stopped a by a kill switch hard coded into the software.

The kill switch was found by a young security researcher who works for Kryptos Logic and thanks to him we all are not spending hours and hours fixing the broken machines or restoring data from backups.

Like many others I am taking few lessons from this.

No 1 - Organizations/Governments with their own agendas

Now, this really pisses me off. The "bug" or vulnerability that was exploited by hackers has been used for NSA for years to spy or remote control computers around the world based on Windows Operating System (which is majority of the PCs). If NSA really needs to spy on machines, why don't they get the USA government to force Microsoft in installing a remote control software that is safe and would not be exploited by hackers?

Once everyone knew about this "bug", Microsoft released a patch in March which was supposed to fix this issue (Microsoft even went out of their way to release patches for unsupported Windows XP and 2003 operating systems). However patches are not always updates straight away, and for large organizations it takes a while before they are tested and deployed to production machines.

When would USA government (who controls NSA and other security agencies) realize that there needs to be a transparency and transfer of information to the manufacturer before the public knows so that an update is released and everything is secured even before criminals in eastern Europe/Russia come up with a Ransomware based on that exploit?  

What pisses me even more is that , this is not the first or the last case of these kind of attacks based on information or exploits discovered by large budget organizations, like NSA. Basically NSA is doing all the work in discovering these bugs and hackers use that to create these Ransomware to make money.

Looks like I am not alone in blaming NSA for breaking MS code, Microsoft's president Brad Smith is pissed off at NSA as well.  

No 2 - Refusal of Governments to track these theives and hackers

I refuse to believe that Governments cannot track where the money is going if they want to. How is it possible that real money transferred to these accounts cannot be traced and tracked to the hackers?

Banks need to start playing ball and these so called “super powers” need to grow some balls. Governments really need to put some priority in dealing with these criminal organizations before it is too late and they become as dangerous as North Korea or ISIS. There needs to a be a justice league of some kind that has powers anywhere in the world to go after these criminals. Yes, I know it is not going to happen because some of these shady organizations are state funded and used for hacking or finding "Bugs/Volunerabilites" but there is no harm in suggesting.

No 3 - How connected we all are

Its amazing how little time it takes for these Ransomwares to spread around the world. We are all now lot more connected then ever. With its advantages it poses a threat of spreading these kind of attacks.

All the dumb machines of the past now have a requirement to be connected to the Internet for different reasons e.g. remote controlling, getting updates, connecting to other systems. 

So, that was my rant about this particular attack. If I look at the bigger picture and think about the kind of problems we could all have, it makes me very nervous. Imagine the time when we will have driverless cars and IOT devices controlling every aspect of our life from ordering groceries to making sure we are taking our medicine on time etc. That is the time which scares me. Imagine a scenario where you are in your car and suddenly the temperature is set to very high. You cannot open windows or turn the temperature down unless you pay someone certain amount of bit coins. That is just a small example, I am sure you all can think of worse ones. I think it is time we all need to start working together specially the “super powers” of this world and combat this threat before it gets out of hand. Because if we don’t NO ONE WINS.


Muneeb Chand

Learning and Enablement Specialist at Foodstuffs North Island

7 年

Thanks for the insights, Imran Sadiq. Certainly much to consider!

Anastasia Ramsay

Customer Success Lead @ Ideally

7 年

Great post! A very interesting perspective on the scandal!

Priscila Bernardes

CEO at Lancom Technology

7 年

Great take on this Imran Sadiq! Highly recommend the reading to everyone interested in the topic.

要查看或添加评论,请登录

Imran Sadiq的更多文章

  • An honest review of AWS DataSync

    An honest review of AWS DataSync

    To start off with, its a great service if you want to continuously sync or a one time copy of data from one location to…

    1 条评论
  • My Shortlist Of re:Invent 2021 Announcements

    My Shortlist Of re:Invent 2021 Announcements

    AWS is in its third wave of services evaluation. First wave was the base services e.

    4 条评论
  • What does it mean to have a local AWS region

    What does it mean to have a local AWS region

    With the latest announcement from AWS on opening of their new Region in Auckland, I thought I should share some…

    6 条评论
  • Web client for AWS SFTP

    Web client for AWS SFTP

    FTP has been around for a long time and still is a strong contender when it comes to transferring data between ad-hoc…

    2 条评论
  • AWS's static stability and recent outage

    AWS's static stability and recent outage

    On January 22nd 2020 between 4:07 PM and 11:20PM PST, you could not create new resources in a VPC for AWS Sydney…

  • Eventful Days in Seattle

    Eventful Days in Seattle

    Sitting here in Starbucks Reserve (one of the best places to visit if you area coffee lover), I am going over the last…

    5 条评论
  • Getting to know AWS Control Tower

    Getting to know AWS Control Tower

    I first attended training on Landing Zones back in August 2018 when it was introduced to APN partners. My immediate…

    2 条评论
  • Recap from AWS Sydney Summit

    Recap from AWS Sydney Summit

    Since 2018, AWS has stepped up its game when it comes to hosting a tech conference in Southern hemisphere. AWS Sydney…

    7 条评论
  • Lancom Tech Talk: How to deploy S3 Static Websites to Test, UAT, or Production AWS Accounts from CodePipeline

    Lancom Tech Talk: How to deploy S3 Static Websites to Test, UAT, or Production AWS Accounts from CodePipeline

    In this blog post, I will demonstrate how to create a continuous deployment pipeline for Static Website deployment into…

    1 条评论
  • Why I abandoned Facebook...

    Why I abandoned Facebook...

    I abandoned Facebook couple of years back. Well, almost abandoned it.

    9 条评论

社区洞察

其他会员也浏览了