<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><font size="+1"><font face="Lucida Grande">Good article in the NYT
on this </font></font><br>
</p>
<pre wrap=""><a class="moz-txt-link-freetext" href="https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it">https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it</a>.
</pre>
Stephanie Perrin<br>
<br>
<div class="moz-cite-prefix">On 2017-05-13 08:22, Niel Harper wrote:<br>
</div>
<blockquote
cite="mid:CAOKYo7F_VK_D0UWUaPtge1y=WuF1mrWKPjMA=wteow-czUgNFA@mail.gmail.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<div dir="ltr">
<div class="gmail_default">
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Hello Wisdom,</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">I want to play the devil's advocate here for a minute.</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Ransomware has been a major problem since the mid-2000s. There was an over 150% increase in new ransomware variants in the first half of 2016 alone. Moreover, cybercriminals are now operating Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less tech-savvy perpetrators to distribute ransomware. News reports would seem to suggest that yesterday's attack was outside the norm, when it really wasn't.</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">While providing information on this particular attack is all well and good, shouldn't we be talking about why governments should not be building up their cyber attack capabilities, and why things like stockpiling zero day vulnerabilities is a really bad idea and compromises the security of the Internet (also eroding online trust)?</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Additionally, shouldn't the discourse include guidelines about protecting individuals and organizations from malware attack (again not criticizing the efficacy and importance of incident response)? </span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
<div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Sadly enough, hospitals are usually low hanging fruit for ransomware attacks. Their data sets are critical to patient care and management, and they usually don’t have the IT resources to support critical process areas like vulnerability management, patch management, business continuity management, etc. They also generally don’t have robust backup solutions and/or real-time replication to disaster recovery sites which increases the overall availability of mission critical data for recovery. And from a risk management perspective, they don’t possess the depth of human resources to employ a ‘three lines of defense’ approach to managing organizational risk.
A robust data backup and recovery solution usually goes a long way in protect oneself from ransomware attacks. My preferred approach for organizations is usually a disk-to-disk-to-tape backup solution combined with offsite replication if possible. The backup tapes are encrypted and stored off site. For individuals, backing up critical data is also very important. But end users need to also regularly update their endpoint security, be wary of phishing and other suspicious emails, and also be mindful the rootkits can be downloaded from legitimate websites that have been compromised.</span></div><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Regards,</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">
</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Niel</span></div></div>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Sat, May 13, 2017 at 6:10 AM, Wisdom
Donkor <span dir="ltr"><<a moz-do-not-send="true"
href="mailto:wisdom.dk@gmail.com" target="_blank">wisdom.dk@gmail.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">Dear
Colleagues,<br
style="font-family:sans-serif;font-size:medium">
<br>
Thought of sharing this information.
<div><span style="font-size:15px"><br>
</span><span
style="font-family:sans-serif;font-size:medium">Yesterday,
May 12, at about 5:00 pm GMT, a massive ransomware hit </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">computer
systems of hundreds of private companies and public </span><span
style="font-family:sans-serif;font-size:medium">organizations
across the world which is believed to have the highest </span><span
style="font-family:sans-serif;font-size:medium">infection
rate of all time.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">The
Ransomware in question has been identified as a variant
of </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">ransomware
known as WannaCry (also known as 'Wana Decrypt0r,' </span><span
style="font-family:sans-serif;font-size:medium">'WannaCryptor'
or 'WCRY').</span>
<div><br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">Like
other dangerous ransomware variants, WannaCry also
blocks access to </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">a
computer or its files and demands money to unlock it.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">Once
infected with the WannaCry ransomware, victims are
asked to pay up </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">to
$300 in order to remove the infection from their PCs;
otherwise, </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">their
PCs render unusable, and their files remain locked.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">WannaCry
attackers use a Windows exploit detected and tested by
the NSA </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">called
EternalBlue, which was stolen and released by the
Shadow Brokers </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">hacking
group over a month ago.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">Microsoft
released a patch for the vulnerability in March
(MS17-010), </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">but
many users and organizations who did not patch their
systems are </span><span
style="font-family:sans-serif;font-size:medium">open
to attacks.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">The
exploit has the capability to penetrate into machines
running </span><span
style="font-family:sans-serif;font-size:medium">unpatched
version of Windows by exploiting flaws in Microsoft
Windows </span><span
style="font-family:sans-serif;font-size:medium">SMB
Server. This is why the WannaCry ransomware is
spreading at an </span><span
style="font-family:sans-serif;font-size:medium">astonishing
pace.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">Once
a single computer in your organization is hit by the
WannaCry </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">ransomware,
the worm looks for other vulnerable computers and
infects </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">them
as well.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">In
just a few hours, the ransomware targeted over 45,000
computers in 74 </span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">countries,
including United States, Russia, Germany, Turkey,
Italy, </span><span
style="font-family:sans-serif;font-size:medium">Philippines
and Vietnam, and that the number was still growing.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">A
screenshot of detailing nations attacked are attached
in this email.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">The
ransomeware's actual mode by which it initiates and
spreads itself </span><span
style="font-family:sans-serif;font-size:medium">on
networks has not been discovered but like other
ransomware variant, </span><span
style="font-family:sans-serif;font-size:medium">malicious
links and emails are most likely the culprit.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">CERT-GH
recommends users and system admins:</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">1.
Take all windows OS systems off the internet and off
the network.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">2.
Create a backup of all files needed.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">3.
Store backup in an airgapped location.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">4.
Download windows update(KB4019472) in a sandbox
environment.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">5.
Install the update without connecting to a
network/internet.</span><br
style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">6.
After the update, the system can be connected to the
internet.</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">Kind
Regards</span><br
style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<br style="font-family:sans-serif;font-size:medium">
<span style="font-family:sans-serif;font-size:medium">CERT-GHANA</span></div>
</div>
<span class="HOEnZb"><font color="#888888"><br>
<br>
-- <br>
<div dir="ltr">
<div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>
<div style="font-size:small"><b>WISDOM
DONKOR (S/N Eng.)</b><br>
</div>
<div style="font-size:small">E-government
and Open Government Data Platforms
Specialist<b><br>
</b></div>
<div style="font-size:small">ICANN
Fellow / Member, UN IGF MAG Member,
ISOC Member,<br>
</div>
<div style="font-size:small">Freedom
Online Coalition (FOC) Member, Diplo
Foundation Member,</div>
<div style="font-size:small">OGP Open
Data WG Member, GODAN Memember, ITAG
Member<br>
</div>
</div>
<div>
<div style="font-size:small">
<div>Email: <a
moz-do-not-send="true"
href="mailto:wisdom.dk@gmail.com"
style="color:rgb(17,85,204)"
target="_blank">wisdom.dk@gmail.com</a></div>
<div>Skype: wisdom_dk</div>
<div>facebook: facebook@wisdom_dk<br>
</div>
<div>Website: <a
moz-do-not-send="true"
href="http://www.data.gov.gh/"
style="color:rgb(17,85,204)"
target="_blank">www.data.gov.gh</a><br>
</div>
<div><a moz-do-not-send="true"
href="http://www.isoc.gh/"
style="color:rgb(17,85,204)"
target="_blank">www.isoc.gh</a> / <a
moz-do-not-send="true"
href="http://www.itag.org.gh/"
style="color:rgb(17,85,204)"
target="_blank">www.itag.org.gh</a></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</font></span></blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
-- <br>
<div class="gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr"><b>Niel Harper</b><br>
<div>Barbados: +(246) 424 3809<br>
</div>
<div>London: +44 207 193 9826<br>
</div>
<div>Mobile: +(246) 243 3818<br>
Email: <a moz-do-not-send="true"
href="mailto:niel.harper@ieee.org"
style="color:rgb(17,85,204)" target="_blank">niel.harper@ieee.org</a></div>
<div>Website: <a moz-do-not-send="true"
href="http://nielharper.com/" target="_blank">http://nielharper.com</a></div>
</div>
</div>
</div>
</blockquote>
<br>
</body>
</html>