{"id":29699,"date":"2017-05-15T11:38:59","date_gmt":"2017-05-15T11:38:59","guid":{"rendered":"http:\/\/www.biphoo.com\/bipnews\/?p=29699"},"modified":"2017-05-15T11:41:46","modified_gmt":"2017-05-15T11:41:46","slug":"dont-hoard-cyberweapons-microsoft-warns-world-leaders","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/dont-hoard-cyberweapons-microsoft-warns-world-leaders.html","title":{"rendered":"Don&#8217;t hoard cyberweapons, Microsoft warns world leaders"},"content":{"rendered":"<h2 style=\"text-align: justify;\">\n\t<span style=\"font-size:22px;\"><strong><span style=\"color:#000000;\">Don&#39;t hoard cyberweapons, Microsoft warns world leaders<\/span><\/strong><\/span><br \/>\n<\/h2>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Microsoft president Brad Smith used Friday&#39;s global ransomware attack as a chance to call once more for the nations of the world to create and adhere to a set of Geneva Convention-like rules in cyberspace.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">The massive &ldquo;WannaCry&rdquo; malware attack crippled more than 20% of hospitals in the United Kingdom and affected more than 200,000 victims in 150 countries, Rob Wainwright, the head of the European Union&rsquo;s &ldquo;Europol&rdquo; law enforcement agency, said Sunday.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">The software, which spreads among Windows computers, infects and then locks up individual machines, demanding a ransom to be paid in the electronic currency Bitcoin. The attack mostly impacted computers in Europe and Asia and for the most part spared North America. The criminals behind the attack have not yet been identified.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Smith and others have long advocated that the world&rsquo;s governments need to pledge not to engage in cyberattacks that target civilian infrastructure.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">The includes not stockpiling flaws in computer code that can be used to craft digital weapons. Just such a stockpiled flaw was behind the rapaciousness and rapidity with which the WannaCry ransomware spread.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">It&rsquo;s believed a group connected to the National Security Agency, known as The Equation Group, found or purchased previously undiscovered flaws in Microsoft Windows code and used them to create cyber-snooping and infiltration tools.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Those tools were part of a large cache of older NSA data that was stolen sometime over the past few years.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">In August 2016, a group calling itself The Shadow Brokers began posting materials from that stolen cache of programs online.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Multiple leaks were posted, including one on April 14 of this year that contained an exploit (flawed computer code that can be used to craft cyberweapons) called EternalBlue.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">That exploit was in turn one of those used to create the WannaCry ransomware program which can rapidly spread itself from computer network to computer network.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">It&rsquo;s believed a group connected to the National Security Agency, known as The Equation Group, found or purchased previously undiscovered flaws in Microsoft Windows code and used them to create cyber-snooping and infiltration tools.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Those tools were part of a large cache of older NSA data that was stolen sometime over the past few years.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">In August 2016, a group calling itself The Shadow Brokers began posting materials from that stolen cache of programs online.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Multiple leaks were posted, including one on April 14 of this year that contained an exploit (flawed computer code that can be used to craft cyberweapons) called EternalBlue.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">That exploit was in turn one of those used to create the WannaCry ransomware program which can rapidly spread itself from computer network to computer network.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Jonathan Sander, chief technology officer for STEALTHbits Technologies, called WannaCry &ldquo;a Frankenstein&#39;s monster of vulnerabilities with patches and exploits that were stolen from the NSA and published for all to see.&rdquo;<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">The theft and posting of the stolen data gave criminals a huge head start. Instead of having to develop their own arsenals of cyberweapons, they simply had to repurpose work done by the highly skilled cyber experts at the NSA, said Phillip Hallam-Baker, principal scientist at the cybersecurity firm Comodo.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Just as dangerous as lost nuclear weapons<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">The U.S. government clearly had its priorities wrong in not focusing on better protecting these cyberweapons, he said.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">&ldquo;Whether or not you think the U.S. government should be spending a fortune developing such cyberweapons, surely it is obvious that the weapons they develop should be properly secured. If someone had lost a nuclear weapon, heads would have rolled. The CIA and NSA have been breached on a massive scale, and now the effects are being felt,&rdquo; Hallam-Baker said.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Many people in fact believe someone at NSA must have tipped Microsoft that the files had been stolen, which is how it knew it needed to push out that particular patch, said Ryan Kalember of Proofpoint, a Sunnyvale, Calif.-based security firm whose researchers were instrumental in fighting the the WannaCry attack.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">A Microsoft spokesman reached Sunday said the company had no comment.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Smith wrote in a blog post Sunday that the attack is an excellent object lesson in why governments stockpiling such vulnerabilities is such a problem.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">&ldquo;This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage,&rdquo; he said.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">Nations need to see the attack as a wake-up call, said Smith.<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"color:#000000;\"><span style=\"font-size:18px;\">&ldquo;They need to take a different approach and adhere in cyberspace to the same rules applied to weapons in the physical world. We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits.&rdquo;<\/span><\/span>\n<\/p>\n<p style=\"text-align: justify;\">\n\t<span style=\"font-size:8px;\"><span style=\"color:#000000;\">Source:-&nbsp;https:\/\/www.usatoday.com\/story\/tech\/news\/2017\/05\/14\/ransomware-wanna-cry-microsoft-brad-smith-cyber-weapon-geneva-convention-nsa\/101690214\/<\/span><\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/dont-hoard-cyberweapons-microsoft-warns-world-leaders.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Don&#39;t hoard cyberweapons, Microsoft warns world leaders Microsoft president Brad Smith used Friday&#39;s global ransomware attack as a chance to call once more for the nations of the world to create and adhere to a set of Geneva Convention-like rules in cyberspace. The massive &ldquo;WannaCry&rdquo; malware attack crippled more than [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":29700,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[18434,18435,18433,18436,7109],"class_list":["post-29699","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-brad-smith","tag-cyber-weapon","tag-dont-hoard-cyberweapons-microsoft-warns-world-leaders","tag-geneva-convention","tag-microsoft"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/29699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=29699"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/29699\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/29700"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=29699"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=29699"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=29699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}