Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Jaltech backs solar firm Wetility in R500-million capital raise

      18 June 2025

      MTN CEO edges Vodacom rival in pay stakes – but just barely

      18 June 2025

      Stolen phone? Samsung now buys you an hour to lock it down

      18 June 2025

      New MD for Dell South Africa

      18 June 2025

      How a dowdy database maker became an investor darling

      18 June 2025
    • World

      Trump Mobile dials into politics, profit and patriarchy

      17 June 2025

      Samsung plots health data hub to link users and doctors in real time

      17 June 2025

      Beijing’s chip champions blacklisted by Taiwan

      16 June 2025

      China is behind in AI chips – but for how much longer?

      13 June 2025

      Yahoo tries to make its mail service relevant again

      13 June 2025
    • In-depth

      Meta bets $72-billion on AI – and investors love it

      17 June 2025

      MultiChoice may unbundle SuperSport from DStv

      12 June 2025

      Grok promised bias-free chat. Then came the edits

      2 June 2025

      Digital fortress: We go inside JB5, Teraco’s giant new AI-ready data centre

      30 May 2025

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025
    • TCS

      TCS+ | AfriGIS’s Helen Hulett on how tech can help resolve South Africa’s water crisis

      18 June 2025

      TechCentral Nexus S0E2: South Africa’s digital battlefield

      16 June 2025

      TechCentral Nexus S0E1: Starlink, BEE and a new leader at Vodacom

      8 June 2025

      TCS+ | The future of mobile money, with MTN’s Kagiso Mothibi

      6 June 2025

      TCS+ | AI is more than hype: Workday execs unpack real human impact

      4 June 2025
    • Opinion

      South Africa pioneered drone laws a decade ago – now it must catch up

      17 June 2025

      AI and the future of ICT distribution

      16 June 2025

      Singapore soared – why can’t we? Lessons South Africa refuses to learn

      13 June 2025

      Beyond the box: why IT distribution depends on real partnerships

      2 June 2025

      South Africa’s next crisis? Being offline in an AI-driven world

      2 June 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » News » Blame game over ransomware attacks

    Blame game over ransomware attacks

    By Agency Staff16 May 2017
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    There’s a blame game brewing over who’s responsible for the massive cyberattack that infected hundreds of thousands of computers around the world since late last week

    Microsoft is pointing its finger at the US government, while some experts say the software giant is accountable, too.

    The attack started on Friday and has affected computers in more than 150 countries, including severe disruptions at Britain’s National Health Service.

    The hack used a technique purportedly stolen from the US National Security Agency to target Microsoft’s market-leading Windows operating system. It effectively takes the computer hostage and demands a US$300 ransom, to be paid in 72 hours with bitcoin.

    Microsoft president and chief legal officer Brad Smith blamed the NSA’s practice of developing hacking methods to use against the US government’s own enemies. The problem is that once those vulnerabilities become public, they can be used by others.

    In March, thousands of leaked Central Intelligence Agency documents exposed vulnerabilities in smartphones, televisions and software built by Apple, Google and Samsung Electronics.

    The argument that it’s the NSA’s fault has merit, according to Alex Abdo, staff attorney at the Knight First Amendment Institute at Columbia University. Still, he said Microsoft should accept some responsibility.

    “Technology companies owe their customers a reliable process for patching security vulnerabilities,” he said. “When a design flaw is discovered in a car, manufacturers issue a recall. Yet, when a serious vulnerability is discovered in software, many companies respond slowly or say it’s not their problem.”

    Microsoft released a patch for the flaw in March after hackers stole the exploit from the NSA. But some organisations didn’t apply it, and others were running older versions of Windows that Microsoft no longer supports. In what it said was a “highly unusual“ step, Microsoft also agreed to provide the patch for older versions of Windows, including Windows XP and Windows Server 2003.

    In 2014, Microsoft ended support for the highly popular Windows XP, released in 2001 and engineered beginning in the late 1990s, arguing that the software was out of date and wasn’t built with modern security safeguards. The company had already been supporting it longer than it normally would have because so many customers still used it and the effort was proving costly. Security patches would be available for clients with older machines, but only if they paid for custom support agreements.

    But with Microsoft making an exception this time and providing the patch free to XP users, it may come under pressure to do the same next time it issues a critical security update. (These are the most important patches that the company recommends users install immediately.) That could saddle the company with the XP albatross for many years past when it hoped to be free from having to maintain the software. The precedent may impact other software sellers, too.

    “They’re going to end up going above and beyond and some vendors are going to start extending support for out-of-support things that they haven’t done before,” said Greg Young, an analyst at market research firm Gartner. “That’s going to become a more common practice.”

    On Monday, private-sector sleuths found a clue about potentially who’s responsible for the WannaCrypt attack. A researcher from Google posted on Twitter that an early version of WannaCrypt from February shared some of the same programming code as malicious software used by the Lazarus Group, the alleged North Korean government hackers behind the destructive attack on Sony in 2014 and the theft of $81m from a Bangladesh central bank account at the New York Fed last year. Others subsequently confirmed the Google researcher’s work.

    Microsoft’s Brad Smith

    On its own, the shared code is little more than an intriguing lead. Once malicious software is in the wild, it is commonly reused by hacking groups, especially nation states trying to leave the fingerprints of another country. But in this case, according to Kaspersky Lab, the shared code was removed from the versions of WannaCrypt that are currently circulating, which reduces the likelihood of such a “false flag” attempt at misdirection. Some security researchers speculated that if the perpetrators were North Korean, the goal may have been to cause a widespread Internet outage to coincide with this weekend’s latest missile test.

    As for Microsoft, some intelligence agency experts questioned its NSA criticism, saying it’s unreasonable for the company to ask governments to stop using its products as a way to attack and monitor enemies.

    “For Microsoft to say that governments should stop developing exploits to Microsoft products is naive,” said Brian Lord, an MD at PGI Cyber and former deputy director at the Government Communications Headquarters, one of the UK’s intelligence agencies. “To keep the world safe, these things have to be done.”

    He said that intelligence agencies tended to be good and responsible stewards of the hacks and exploits they develop. “Occasionally mistakes happen,” he added.  — (c) 2017 Bloomberg LP

    • Reported with assistance from Gerrit De Vynck and Jeremy Kahn


    Brad Smith GCHQ Microsoft NSA
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleCentral banks face cryptic future
    Next Article Brian Molefe must go, ANC says

    Related Posts

    Major rift opens between Microsoft and OpenAI

    17 June 2025

    The future of database management is hybrid. Are you ready?

    6 June 2025

    How AI is rewriting the rules of software development

    4 June 2025
    Company News

    Disrupt first, ask questions later – the uncomfortable truth about incident response

    18 June 2025

    Sage brings together HR leaders to explore the future of payroll and people management

    18 June 2025

    Altron: a brand journey, a birthday celebration and a bet on Joburg’s future

    17 June 2025
    Opinion

    South Africa pioneered drone laws a decade ago – now it must catch up

    17 June 2025

    AI and the future of ICT distribution

    16 June 2025

    Singapore soared – why can’t we? Lessons South Africa refuses to learn

    13 June 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.