<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><font size="+1"><font face="Lucida Grande">Good article in the NYT
          on this </font></font><br>
    </p>
    <pre wrap=""><a class="moz-txt-link-freetext" href="https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it">https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it</a>.

</pre>
    Stephanie Perrin<br>
    <br>
    <div class="moz-cite-prefix">On 2017-05-13 08:22, Niel Harper wrote:<br>
    </div>
    <blockquote
cite="mid:CAOKYo7F_VK_D0UWUaPtge1y=WuF1mrWKPjMA=wteow-czUgNFA@mail.gmail.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <div dir="ltr">
        <div class="gmail_default">
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Hello Wisdom,</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">I want to play the devil's advocate here for a minute.</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Ransomware has been a major problem since the mid-2000s. There was an over 150% increase in new ransomware variants in the first half of 2016 alone. Moreover, cybercriminals are now operating Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less tech-savvy perpetrators to distribute ransomware. News reports would seem to suggest that yesterday's attack was outside the norm, when it really wasn't.</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">While providing information on this particular attack is all well and good, shouldn't we be talking about why governments should not be building up their cyber attack capabilities, and why things like stockpiling zero day vulnerabilities is a really bad idea and compromises the security of the Internet (also eroding online trust)?</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Additionally, shouldn't the discourse include guidelines about protecting individuals and organizations from malware attack (again not criticizing the efficacy and importance of incident response)? </span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div></div>
          <div class="gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Sadly enough, hospitals are usually low hanging fruit for ransomware attacks. Their data sets are critical to patient care and management, and they usually don’t have the IT resources to support critical process areas like vulnerability management, patch management, business continuity management, etc. They also generally don’t have robust backup solutions and/or real-time replication to disaster recovery sites which increases the overall availability of mission critical data for recovery. And from a risk management perspective, they don’t possess the depth of human resources to employ a ‘three lines of defense’ approach to managing organizational risk. 

A robust data backup and recovery solution usually goes a long way in protect oneself from ransomware attacks. My preferred approach for organizations is usually a disk-to-disk-to-tape backup solution combined with offsite replication if possible. The backup tapes are encrypted and stored off site. For individuals, backing up critical data is also very important. But end users need to also regularly update their endpoint security, be wary of phishing and other suspicious emails, and also be mindful the rootkits can be downloaded from legitimate websites that have been compromised.</span></div><div class="gmail-_1mf gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">
</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Regards,</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">
</span></div><div class="gmail-_1mf gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Niel</span></div></div>
        </div>
      </div>
      <div class="gmail_extra"><br>
        <div class="gmail_quote">On Sat, May 13, 2017 at 6:10 AM, Wisdom
          Donkor <span dir="ltr"><<a moz-do-not-send="true"
              href="mailto:wisdom.dk@gmail.com" target="_blank">wisdom.dk@gmail.com</a>></span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">Dear
            Colleagues,<br
              style="font-family:sans-serif;font-size:medium">
            <br>
            Thought of sharing this information.
            <div><span style="font-size:15px"><br>
              </span><span
                style="font-family:sans-serif;font-size:medium">Yesterday,
                May 12, at about 5:00 pm GMT, a massive ransomware hit </span><br
                style="font-family:sans-serif;font-size:medium">
              <span style="font-family:sans-serif;font-size:medium">computer
                systems of hundreds of private companies and public </span><span
                style="font-family:sans-serif;font-size:medium">organizations
                across the world which is believed to have the highest </span><span
                style="font-family:sans-serif;font-size:medium">infection
                rate of all time.</span><br
                style="font-family:sans-serif;font-size:medium">
              <span style="font-family:sans-serif;font-size:medium">The
                Ransomware in question has been identified as a variant
                of </span><br
                style="font-family:sans-serif;font-size:medium">
              <span style="font-family:sans-serif;font-size:medium">ransomware
                known as WannaCry (also known as 'Wana Decrypt0r,' </span><span
                style="font-family:sans-serif;font-size:medium">'WannaCryptor'
                or 'WCRY').</span>
              <div><br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">Like
                  other dangerous ransomware variants, WannaCry also
                  blocks access to </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">a
                  computer or its files and demands money to unlock it.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">Once
                  infected with the WannaCry ransomware, victims are
                  asked to pay up </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">to
                  $300 in order to remove the infection from their PCs;
                  otherwise, </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">their
                  PCs render unusable, and their files remain locked.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">WannaCry
                  attackers use a Windows exploit detected and tested by
                  the NSA </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">called
                  EternalBlue, which was stolen and released by the
                  Shadow Brokers </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">hacking
                  group over a month ago.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">Microsoft
                  released a patch for the vulnerability in March
                  (MS17-010), </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">but
                  many users and organizations who did not patch their
                  systems are </span><span
                  style="font-family:sans-serif;font-size:medium">open
                  to attacks.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">The
                  exploit has the capability to penetrate into machines
                  running </span><span
                  style="font-family:sans-serif;font-size:medium">unpatched
                  version of Windows by exploiting flaws in Microsoft
                  Windows </span><span
                  style="font-family:sans-serif;font-size:medium">SMB
                  Server. This is why the WannaCry ransomware is
                  spreading at an </span><span
                  style="font-family:sans-serif;font-size:medium">astonishing
                  pace.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">Once
                  a single computer in your organization is hit by the
                  WannaCry </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">ransomware,
                  the worm looks for other vulnerable computers and
                  infects </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">them
                  as well.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">In
                  just a few hours, the ransomware targeted over 45,000
                  computers in 74 </span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">countries,
                  including United States, Russia, Germany, Turkey,
                  Italy, </span><span
                  style="font-family:sans-serif;font-size:medium">Philippines
                  and Vietnam, and that the number was still growing.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">A
                  screenshot of detailing nations attacked are attached
                  in this email.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">The
                  ransomeware's actual mode by which it initiates and
                  spreads itself </span><span
                  style="font-family:sans-serif;font-size:medium">on
                  networks has not been discovered but like other
                  ransomware variant, </span><span
                  style="font-family:sans-serif;font-size:medium">malicious
                  links and emails are most likely the culprit.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">CERT-GH
                  recommends users and system admins:</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">1.
                  Take all windows OS systems off the internet and off
                  the network.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">2.
                  Create a backup of all files needed.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">3.
                  Store backup in an airgapped location.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">4.
                  Download windows update(KB4019472) in a sandbox
                  environment.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">5.
                  Install the update without connecting to a
                  network/internet.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">6.
                  After the update, the system can be connected to the
                  internet.</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">Kind
                  Regards</span><br
                  style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <br style="font-family:sans-serif;font-size:medium">
                <span style="font-family:sans-serif;font-size:medium">CERT-GHANA</span></div>
            </div>
            <span class="HOEnZb"><font color="#888888"><br>
                <br>
                -- <br>
                <div dir="ltr">
                  <div>
                    <div dir="ltr">
                      <div dir="ltr">
                        <div dir="ltr">
                          <div dir="ltr">
                            <div dir="ltr">
                              <div dir="ltr">
                                <div>
                                  <div style="font-size:small"><b>WISDOM
                                      DONKOR (S/N Eng.)</b><br>
                                  </div>
                                  <div style="font-size:small">E-government
                                    and Open Government Data Platforms
                                    Specialist<b><br>
                                    </b></div>
                                  <div style="font-size:small">ICANN
                                    Fellow / Member, UN IGF MAG Member,
                                    ISOC Member,<br>
                                  </div>
                                  <div style="font-size:small">Freedom
                                    Online Coalition (FOC) Member, Diplo
                                    Foundation Member,</div>
                                  <div style="font-size:small">OGP Open
                                    Data WG Member, GODAN Memember, ITAG
                                    Member<br>
                                  </div>
                                </div>
                                <div>
                                  <div style="font-size:small">
                                    <div>Email: <a
                                        moz-do-not-send="true"
                                        href="mailto:wisdom.dk@gmail.com"
                                        style="color:rgb(17,85,204)"
                                        target="_blank">wisdom.dk@gmail.com</a></div>
                                    <div>Skype: wisdom_dk</div>
                                    <div>facebook: facebook@wisdom_dk<br>
                                    </div>
                                    <div>Website: <a
                                        moz-do-not-send="true"
                                        href="http://www.data.gov.gh/"
                                        style="color:rgb(17,85,204)"
                                        target="_blank">www.data.gov.gh</a><br>
                                    </div>
                                    <div><a moz-do-not-send="true"
                                        href="http://www.isoc.gh/"
                                        style="color:rgb(17,85,204)"
                                        target="_blank">www.isoc.gh</a> / <a
                                        moz-do-not-send="true"
                                        href="http://www.itag.org.gh/"
                                        style="color:rgb(17,85,204)"
                                        target="_blank">www.itag.org.gh</a></div>
                                  </div>
                                </div>
                              </div>
                            </div>
                          </div>
                        </div>
                      </div>
                    </div>
                  </div>
                </div>
                <br>
              </font></span></blockquote>
        </div>
        <br>
        <br clear="all">
        <div><br>
        </div>
        -- <br>
        <div class="gmail_signature" data-smartmail="gmail_signature">
          <div dir="ltr"><b>Niel Harper</b><br>
            <div>Barbados: +(246) 424 3809<br>
            </div>
            <div>London: +44 207 193 9826<br>
            </div>
            <div>Mobile: +(246) 243 3818<br>
              Email: <a moz-do-not-send="true"
                href="mailto:niel.harper@ieee.org"
                style="color:rgb(17,85,204)" target="_blank">niel.harper@ieee.org</a></div>
            <div>Website: <a moz-do-not-send="true"
                href="http://nielharper.com/" target="_blank">http://nielharper.com</a></div>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>