Wana Decrypt0r (Wanacry Ransomware) - Computerphile

$300 or your files are toast: Dr Pound takes a look at the latest ransomware to be doing the rounds.
How Wana Decrypt0r encrypts files:
• How WanaCrypt Encrypts...
Microsoft Blog: bit.ly/Computerphile-Wana_MS
Professor Ross Anderson's blog: bit.ly/Computerphile-Wana_Ross
MalwareTech's blog: bit.ly/Computerphile-Wana_Mal
End to End Encryption: • End to End Encryption ...
Internet of Things Problems: • Internet of Things Pro...
/ computerphile
/ computer_phile
This video was filmed and edited by Sean Riley.
Computer Science at the University of Nottingham: bit.ly/nottscomputer
Computerphile is a sister project to Brady Haran's Numberphile. More at www.bradyharan.com

Пікірлер: 2 000

  • @bosnianowitzkifan41
    @bosnianowitzkifan415 жыл бұрын

    Officer: How did the hacker escape? Me: I don't know he just ransomware

  • @marcellowheeler88

    @marcellowheeler88

    5 жыл бұрын

    Oh you...!!!

  • @Random-om8rq

    @Random-om8rq

    5 жыл бұрын

    BOI U A GENIUS

  • @jacobr7729

    @jacobr7729

    4 жыл бұрын

    ba dum tsssss

  • @cybroX

    @cybroX

    4 жыл бұрын

    Lol

  • @jean-baptistelasselle4562

    @jean-baptistelasselle4562

    4 жыл бұрын

    excellent one ^^

  • @TheTruthSentMe
    @TheTruthSentMe7 жыл бұрын

    I hope this guy will be in many more videos on this channel. I find the stuff he is talking about so fascinating.

  • @chuckvanderbildt

    @chuckvanderbildt

    7 жыл бұрын

    He gave the most calm, reasoned and sensible explanation of this whole debacle that I have come across so far.

  • @nahsik

    @nahsik

    7 жыл бұрын

    CounterKitty same here. He does a lot of interesting videos on this channel. More of him please.

  • @alehax27

    @alehax27

    7 жыл бұрын

    Agreed. I sat here and listened to the entire 15 min talk

  • @pantherdddjvdgx

    @pantherdddjvdgx

    7 жыл бұрын

    This is a great channel, but I enjoy watching his stuff the most!

  • @___aZa___

    @___aZa___

    7 жыл бұрын

    same

  • @WolfireGaming
    @WolfireGaming7 жыл бұрын

    "All software have bugs" um rude, my Hello World program is perfect and has no bugs, how dare you.

  • @theX24968Z

    @theX24968Z

    7 жыл бұрын

    if it doesn't have any bugs, it doesn't have enough features.

  • @dragonfyzex1546

    @dragonfyzex1546

    7 жыл бұрын

    WolfireGaming HAHAHHAAHAHHA. The bug, it doesn't say hello KZread

  • @oddstr13

    @oddstr13

    7 жыл бұрын

    ``` #!/usr/bin/env python print("Hello, World!") ```

  • @4lligator

    @4lligator

    7 жыл бұрын

    PROGRAM HELLO PRINT *, "HELLO WORLD!" END PROGRAM HELLO

  • @AnirudhGiri

    @AnirudhGiri

    7 жыл бұрын

    +4lligator FORTRAN! Ayy!

  • @SkinnyCow.
    @SkinnyCow.5 жыл бұрын

    Someone hacked the NSA and stole their backdoor exploits. Damn, those dudes must have a seriously large set of balls.

  • @oldandwesternreviews2823

    @oldandwesternreviews2823

    Ай бұрын

    😂😂

  • @untitled8027
    @untitled80277 жыл бұрын

    *aggressively installs updates*

  • @fsmoura

    @fsmoura

    7 жыл бұрын

    LET ME SEE YOUR WAR FACE oДo

  • @jeffirwin7862

    @jeffirwin7862

    7 жыл бұрын

    *installation* *intensifies*

  • @Danscottmusic

    @Danscottmusic

    7 жыл бұрын

    _passive aggressively installs update_

  • @SuperQualifyed

    @SuperQualifyed

    7 жыл бұрын

    Secretly turns back on auto update after 2 years

  • @pm79080

    @pm79080

    7 жыл бұрын

    Stallman Was Right

  • @vortex_7574
    @vortex_75744 жыл бұрын

    So the MalwareTech dude that he was talking about, he found the killswitch and then was hailed a hero. He lived in the UK and went to Las Vegas for a vacation and guess what? The FBI arrested him at the airport. It's because in his younger years when he was learning how to hack, he made a malware which he mistakenly sold to someone. The malware was then incorporated with Kronos which led to sensitive bank information to be leaked. He had trials and he wasn't allowed to leave the U.S. nor, was he allowed to legally work there for 18 months. He finally gave up and accepted his charges. On the day of his sentencing, the Judge let him go as he had done the world a huge favor by finding the killswitch and disabling WanaCry ransomware. A very interesting documentary, indeed! {also, when he was arrested, he was left on bail on a bond of $30k, his story got out in his country and the very second day, the community had paid it off completely!}

  • @nathanash101
    @nathanash1017 жыл бұрын

    "If you're running XP, the first think you should do is turn off your machine because you have no business running XP" lol

  • @dannygjk

    @dannygjk

    6 жыл бұрын

    He doesn't know WTF he is talking about. He is only a spokesperson.

  • @MrVestek

    @MrVestek

    5 жыл бұрын

    Found the Windows XP user.

  • @VishalSharma-gt1hy

    @VishalSharma-gt1hy

    5 жыл бұрын

    XP

  • @iflnr978

    @iflnr978

    4 жыл бұрын

    should? there's lots of things I should and shouldn't do. I love XP inside a container with no online or network access so i can torture it after it's creator screwed with Linux for years. "Linux is a cancer that NEEDS to be eradicated!"

  • @HaloDude557

    @HaloDude557

    4 жыл бұрын

    shody ryon linux is for big brain users only

  • @NevaehBeatez
    @NevaehBeatez7 жыл бұрын

    I think failure to report a vulnerability like this should be a crime, but we all know NSA is outside of the law

  • @clul100
    @clul1007 жыл бұрын

    I believe that is the first time someone argued for the forced updates in Windows 10

  • @rcookie5128

    @rcookie5128

    7 жыл бұрын

    yes, indeed. I still want to decide when or if I want to update my system.. just a few days ago I got this lovely unnecessary "Windows creator" update, which brought me a few new programms I'll never use and in return my desktop icons are slightly offset to the top (its just a handfull of pixels, but I still notice it, its kinda annoying).

  • @dykam

    @dykam

    7 жыл бұрын

    BS, security experts have always been a fan of it. Of course there's stuff attached to it which is less desirable, but the basic premise of forced security updates isn't too controversial.

  • @patryk2535

    @patryk2535

    7 жыл бұрын

    I think the only problem with automatic Windows updates is that they require system restart.

  • @BlueTJLP

    @BlueTJLP

    7 жыл бұрын

    Patryk Pawleta With an SSD, this is done in no time at all.

  • @BlueTJLP

    @BlueTJLP

    7 жыл бұрын

    rainbowevil That's impossible.

  • @georgehornsby2075
    @georgehornsby20757 жыл бұрын

    Paid $300 to get my computer decrypted so I could watch this video

  • @ciaran1344

    @ciaran1344

    7 жыл бұрын

    (It's a joke)

  • @cybercat1531

    @cybercat1531

    7 жыл бұрын

    No. You have not.

  • @georgehornsby2075

    @georgehornsby2075

    7 жыл бұрын

    You got me

  • @BlueTJLP

    @BlueTJLP

    7 жыл бұрын

    Money well spent.

  • @fsmoura

    @fsmoura

    7 жыл бұрын

    _"You got me"_ Yes. You got gotten. Now, please pay $300 to the following bitcoin address in order to proceed.

  • @0ptera
    @0ptera7 жыл бұрын

    The problem with Microsofts update policy is they don't discern between security, driver and feature updates. Security updates should be installed instantly. Driver updates can break whole system. Nvidia.seems very prone to this. Feature Updates are almost guaranteed to introduce new bugs.

  • @sonicscrewdriverdw

    @sonicscrewdriverdw

    7 жыл бұрын

    Kyoko Kobayashi I like how you didn't mention bug fixes at all 😂

  • @0ptera

    @0ptera

    7 жыл бұрын

    @sonicscrewdriverdw While there is a potential 4th category for bug fixes, the non critical like changed currency symbol of Azerbaijan, generally bug fixes can be categorized in the 3 categories I mentioned.

  • @peacem8574

    @peacem8574

    7 жыл бұрын

    Kyoko Kobayashi Microsoft is at least trying. Even XP got security updates and it's normally not supported anymore.

  • @Justin7166

    @Justin7166

    7 жыл бұрын

    Kyoko Kobayashi Yep. Sums up the problems with Windows 10's forced updates.

  • @jonathandpg6115

    @jonathandpg6115

    7 жыл бұрын

    Also it shouldn't auto update when I am using or could be using my computer. That gets annoying quick

  • @qwerty975311
    @qwerty9753115 жыл бұрын

    Dr. Pound is my favorite presenter you feature on this channel. He's very well spoken and clear in his explanations. I also enjoy his drawings that illustrate what he is talking about.

  • @Pepperoni-Tony
    @Pepperoni-Tony7 жыл бұрын

    How is it that my mac takes hours to encrypt my drive/files, but this thing does it in seconds?

  • @kissingfrogs

    @kissingfrogs

    7 жыл бұрын

    Great point. Thats what I have been wondering. And for me some preparation before I could encrypt, then as you say, time is needed to encrypt

  • @DaveH82

    @DaveH82

    7 жыл бұрын

    There are different levels of encryption. It could be doing a simpler one. When you perform a full disk encryption, it's also encrypting the free space for future use.

  • @aNaGrMa

    @aNaGrMa

    7 жыл бұрын

    There is a finite list of extensions (around 50) that crytolockers look for .doc .docx .jpg etc.- the important ones to you, not an operating system - so it won't ever take as long as encrypting a full drive, for the reason Dave H said. The reason for this is the malware is there to make money essentially through blackmail. They wouldn't make any money if it encrypted your windows installation.

  • @threepointonefour607

    @threepointonefour607

    7 жыл бұрын

    I think the mac drive encryption does the whole drive including the operating system. Ransom ware usually doesnt encrypt the OS since they couldn't get your money if it did

  • @jossbird3358

    @jossbird3358

    7 жыл бұрын

    Huh easy just modify extensions of important files to protect against ransom-ware or keep backups

  • @TheSeanUhTron
    @TheSeanUhTron7 жыл бұрын

    *NSA* ~ _We put surveillance above our countries safety._

  • @somethingcool9063

    @somethingcool9063

    7 жыл бұрын

    no not really, they make these ransomewares so that if terrorists find something out like a nuclear weapon they can encript all their files, you don't get that though scince you don't work in the NSA

  • @wilfriedsteinbach8700

    @wilfriedsteinbach8700

    4 жыл бұрын

    @@somethingcool9063 That's not how things work lol...

  • @uuu12343

    @uuu12343

    4 жыл бұрын

    SomethingCool Yeah, because someone with your level of control on English worked for the NSA

  • @Volvoman90

    @Volvoman90

    4 жыл бұрын

    Country's*

  • @abnorcscreenname8489
    @abnorcscreenname84897 жыл бұрын

    Dr. Pound's videos are the highlight of this channel for me. Great work.

  • @derekfoulk4692
    @derekfoulk46927 жыл бұрын

    I love the new content you guys are making, this channel is quickly becoming my favorite! Keep up the good work guys!

  • @ComputingCactus
    @ComputingCactus7 жыл бұрын

    You can thank the NSA for this hack.

  • @AscottSauce

    @AscottSauce

    7 жыл бұрын

    Vercusgames wut

  • @jossbird3358

    @jossbird3358

    7 жыл бұрын

    +Vercusgames lol is this a joke?

  • @markus8282

    @markus8282

    7 жыл бұрын

    Not even enough for heir breakfast.

  • @aidancarlisle6237

    @aidancarlisle6237

    7 жыл бұрын

    Dr Strangelove noooo it got leaked buddy. not sure where you heard that from

  • @heyitsmejm4792

    @heyitsmejm4792

    7 жыл бұрын

    Spy it got leaked?? the video says that exploit has been up since windows xp, why didn't​ the NSA inform Microsoft about the said issue, its because they're taking that exploit as an advantage to hack peoples computer to spy..

  • @MaxMakerChannel
    @MaxMakerChannel7 жыл бұрын

    I expected to find out about the actual virus. He kinda only summed up the news from this weekend. Does this virus actually encrypt your files? How can you get rid of it? (I am not affected)

  • @LakeVermilionDreams

    @LakeVermilionDreams

    7 жыл бұрын

    Max Maker patch your windows machines, if they aren't. If you get ransomware, you either pay up for the files, or wipe your machine and lose the files, or wipe and restore your files from air-gapped backups. Either way, you should wipe the system because it already has been compromised, and there's no real way of knowing whatever else was put in there.

  • 7 жыл бұрын

    Does this virus actually encrypt your files? yes it encrypts all the files it can find How can you get rid of it? as far as I know you can't (people who have payed have not received a decryptor or key)

  • @keithkaranu4258

    @keithkaranu4258

    7 жыл бұрын

    yes it does encrypt your files no you can't remove it or at least not easily

  • @DaffyDaffyDaffy33322

    @DaffyDaffyDaffy33322

    7 жыл бұрын

    Yes, it actually does encrypt your files. You can get rid of it by removing the files it created, and tweaking some stuff in msconfig and task scheduler (I didn't try this, but that's the usual recipe for removing malware). It won't decrypt your files if you remove it, so consider them lost, but the malware is likely easily removable.

  • @michaelpound9891

    @michaelpound9891

    7 жыл бұрын

    I hope to do a video on the actual encryption soon! We didn't want this one to be too long.

  • @N1cX591
    @N1cX5917 жыл бұрын

    This guy is such a great host. Videos about very intriguing topics and explains everything very well

  • @edss
    @edss7 жыл бұрын

    14:24 "we're doing this to fu.... counter terrorism"

  • @thedangerousjitu694

    @thedangerousjitu694

    5 жыл бұрын

    lol

  • @tmcowley

    @tmcowley

    4 жыл бұрын

    to fight you imbecile

  • @huntforerror

    @huntforerror

    4 жыл бұрын

    @@tmcowley Cowley boy

  • @spaceman2142
    @spaceman21427 жыл бұрын

    That 1940's Ford Analogy was beautiful

  • @kevinyou9621

    @kevinyou9621

    5 жыл бұрын

    HEHE

  • @rello6608

    @rello6608

    4 жыл бұрын

    Yes

  • @SproutyPottedPlant
    @SproutyPottedPlant7 жыл бұрын

    it's a vulnerability in SMB1 (Super Mario Brothers)

  • @katrinal353

    @katrinal353

    7 жыл бұрын

    Gah! SMB has always been my weakness!!

  • @oystein18

    @oystein18

    7 жыл бұрын

    Knuckles the Echidna aha, that makes sense, thanks

  • @GoldenGrenadier

    @GoldenGrenadier

    7 жыл бұрын

    Knuckles the Echidna are you going to be in sonic forces?

  • @SproutyPottedPlant

    @SproutyPottedPlant

    7 жыл бұрын

    Ohh I'm hoping Sega make me the main character!

  • @Chaotix_

    @Chaotix_

    7 жыл бұрын

    Sonic Forces & Knuckles

  • @gthakur17
    @gthakur177 жыл бұрын

    Yesterday i was thinking about that ransomware could be a great topic for computerphile and when i woke up today i found this video. I was pleasently surprised.Thanks computerphile

  • @iyaanazeez8989
    @iyaanazeez89893 жыл бұрын

    I have always been fascinated by the engineering that goes into crafting these malwares. Just mind blowing details

  • @David_Last_Name
    @David_Last_Name7 жыл бұрын

    Fortunately for me, my computer already has so many viruses on it theres no room for any more!

  • @antipoti

    @antipoti

    5 жыл бұрын

    I actually laughed, thank you! :D

  • @nilen

    @nilen

    4 жыл бұрын

    antipoti why

  • @R3lay0

    @R3lay0

    4 жыл бұрын

    Worst case it renders all tge other viruses useless by encrypting them

  • @theolodger

    @theolodger

    3 жыл бұрын

    @@R3lay0 why worst.?

  • @FlyBoyMart

    @FlyBoyMart

    3 жыл бұрын

    Like in the simpsons when mr burns goes for a health checkup and has every disease on earth...indestructible

  • @BitcoinMotorist
    @BitcoinMotorist7 жыл бұрын

    If you're smart enough to figure out how to pay the ransom you're probably not running XP

  • @MaxMakerChannel
    @MaxMakerChannel7 жыл бұрын

    Is the encryption key for these viruses always the same? Does the encryption ever get broken?

  • @Keex11

    @Keex11

    7 жыл бұрын

    Max Maker if the programmers have half a brain, they copy/pasted a decent aes implementation. then you won't break the algorithm. But maybe they screwed up key control in some way to open an attack vector.

  • @antalz

    @antalz

    7 жыл бұрын

    They use RSA to encrypt, with a different public key for each victim. There may be errors in key handling, but RSA itself is uncrackable for another decade at least.

  • @RobertPoenaru
    @RobertPoenaru7 жыл бұрын

    I was waiting for your video since Saturday! :)

  • @SamAndrew27
    @SamAndrew275 жыл бұрын

    6:52 As a "lone wolf" SysAdmin, this kept me up at night back in 2017...honestly pretty terrifying, the thought of ransomware worm ripping through the corporate LAN you manage! Luckily I was able to react quickly enough and get everything patched.

  • @burnzy3210
    @burnzy32107 жыл бұрын

    no link to the exe in the video description??? wtf, unsubbed

  • @PaulPaulPaulson

    @PaulPaulPaulson

    7 жыл бұрын

    burnzy3210 You can't unsubscribe until you pay 300$

  • @Peng_Pong

    @Peng_Pong

    7 жыл бұрын

    That moment when the reply gets more likes than the comment itself.

  • @aanayjhawar2359

    @aanayjhawar2359

    7 жыл бұрын

    Spiky. mey 2

  • @crashbandicoot4everr

    @crashbandicoot4everr

    7 жыл бұрын

    I have the exe. WannaLink? :P

  • @Brickkzz

    @Brickkzz

    7 жыл бұрын

    wtf i hate Grumpfh now

  • @PullerzCoD
    @PullerzCoD7 жыл бұрын

    Love the Dr Pound videos, never fails to be interesting!

  • @Soundole
    @Soundole7 жыл бұрын

    I love Dr. Pound's discussions :)

  • @BlueEyesWhiteTeddy
    @BlueEyesWhiteTeddy5 жыл бұрын

    I love the shadow brokers. I think it's far more ethical to tell everyone about the existence of these exploits and the fact that a so called "Security" agency knew about them and kept them a secret arrogantly thinking that nobody would know. Far more than someone who knows about an exploit and doesn't tell anybody so that everybody is vulnerable. What if some third party found the exploit and used it without telling anybody, far more problems could arise as microsoft wouldn't have put out a patch.

  • @cade2770

    @cade2770

    Жыл бұрын

    It's not that simple as you're picking the better of two evils. TSB motive is not truth, it is profit. They sell exploits to script kiddies who use it in trojans, RATs, and ransomware.

  • @TheRealDerohneNick
    @TheRealDerohneNick7 жыл бұрын

    A "Do not try this at home" on Computerphile. That's a first... right?

  • @Zigr-Inc
    @Zigr-Inc5 жыл бұрын

    love it! awesome job with the interview mate :)

  • @davidsweeney111
    @davidsweeney1117 жыл бұрын

    Thanks for getting this one out guys, interesting as ever!

  • @Ryukachoo
    @Ryukachoo7 жыл бұрын

    it's amusing how the NSA is now whining about how microsoft should have put in a legitimate backdoor for them to use so they wouldn't have to stockpile exploits except microsoft has every right to say "you want us to make you a back door so you can get hacked and lose that too?"

  • @Nordryd
    @Nordryd5 жыл бұрын

    I want Dr. Pound to teach me Computer Science. I wish I had him when I was in college

  • @GrumpyFinch
    @GrumpyFinch4 жыл бұрын

    This gent is doing things for me with his intelligence and simple explanations. Aside that - this channel is fantastic. Thank you.

  • @christopherdeleon513
    @christopherdeleon5135 жыл бұрын

    I had to google what a “sandbox” or “virtual machine” was (to examine how code is being executed in a protected environment) so I really don’t know why I watch some of this stuff but holy hell I learn a lot. Thanks!

  • @ruthlessadmin
    @ruthlessadmin7 жыл бұрын

    I've switched all my computers to linux. I finished the last one up just a week before this came out. This sort of thing is one of the main motivating factors. Not that viruses don't exist for the platform, or that hackers wont still hack but at least there isn't any major bureaucracy holding up patches.

  • @tonycolle8699
    @tonycolle86996 жыл бұрын

    It always scares me when someone says, "I'm from the government. I'm here to help. Trust me."

  • @iflnr978

    @iflnr978

    4 жыл бұрын

    me too, cause government takes its orders from industry lobbyists, else why would 4 out of five big corporations pay no corporate income tax? why would a graph of wealth distribution over time show the richest one percent as owning more wealth than the poorest 90 percent. or is it the poorest 99 percent. in other words, when the rich don't pay and are in charge of tax regulation, they take everything, wall street goes crazy and instead of funding main street, stock values are disconnected from the rest of the economy.

  • @11thcucumber23
    @11thcucumber237 жыл бұрын

    Dr Pound it's always a good information and content =D I'm italian and I appreciate it! Thanks Computerphile

  • @VauxhallViva1975
    @VauxhallViva19757 жыл бұрын

    Excellent video. :) Describes the problem calmly, without all the media hype. I will link anyone with questions about it to this video.

  • @Sparrow420
    @Sparrow4203 жыл бұрын

    8:58 "volkswagon emission situation", lol, this is gold.

  • @BlenderDefender

    @BlenderDefender

    3 жыл бұрын

    It is not the first time they say that

  • @zanaris-falador
    @zanaris-falador7 жыл бұрын

    I'm using the Ransomware splash screen as my wallpaper right now.

  • @dragonfyzex1546

    @dragonfyzex1546

    7 жыл бұрын

    Zanaris Falador I wanna do that

  • @cptxander
    @cptxander7 жыл бұрын

    Great video as always guys

  • @bunniz
    @bunniz7 жыл бұрын

    I can't believe I haven't found this channel before. I learnt about all of this type of malware but I never saw one in action.

  • @tymenvanessen3119
    @tymenvanessen31197 жыл бұрын

    could my windows 98 be affected wannaCry? or is it indeed 9,8 times as secure as windows 10 by now?

  • @shomz

    @shomz

    5 жыл бұрын

    Only one way to find out... what's your email address?

  • @valhar2000
    @valhar20007 жыл бұрын

    12:36 Oh yeah! To minimize this problem, I configured our network so that the Win XP machine can see the scanner, but it cannot connect to the Internet at all. Also, we only turn it on when we need to use the scanner.

  • @thillyification
    @thillyification6 жыл бұрын

    I like your analogies very much.

  • @akashkumarharsh9285
    @akashkumarharsh92856 жыл бұрын

    love the way you teach dude

  • @EternalListener
    @EternalListener7 жыл бұрын

    *laughs in linux*

  • @allieisasleep

    @allieisasleep

    7 жыл бұрын

    Hope you like your non existent game support

  • @MRawash

    @MRawash

    7 жыл бұрын

    Axtronima, Hope you like your non existent privacy and security, while I enjoy my 588 games on Steam. :)

  • @MRawash

    @MRawash

    7 жыл бұрын

    Axtronima, viruses could just as easily look like updates for your currently installed programs, so hope you like living in constant fear. :)

  • @MRawash

    @MRawash

    7 жыл бұрын

    Sweyn78, you don't have to pretend, Linux *is* objectively better. Just because security bugs exist doesn't mean they're easy to utilize/exploit, and in the case of MS Windows, some of the security vulnerabilities are even touted as "features" (see Win10's telemetry), so there is no comparison.

  • @MRawash

    @MRawash

    7 жыл бұрын

    Sweyn78, Linux is currently the most popular OS in the world, so I'm not sure how you reached that conclusion. If you're talking about desktop in particular then that's something else, though desktop users benefit from the same security patches that are applied to other forms of Linux, so they are not any less protected. Also, most of Linux's _funding_ comes in the form of man hours contributed by big businesses and organizations that utilize or depend on it (i.e. they'd rather pay their own developers, than donate to unmanaged volunteers), so this is at worst a minor problem for FOSS, and at best, an advantage, because it allows professionals with varying levels of expertise, backgrounds and agendas to contribute to the same projects.

  • @Spiralem
    @Spiralem7 жыл бұрын

    > Yeah, and win 10 is patching non functional drivers over my existing working one ={

  • @theX24968Z

    @theX24968Z

    7 жыл бұрын

    you can turn it off by disabling the windows update service.

  • @Spiralem

    @Spiralem

    7 жыл бұрын

    but is just one rouge update =

  • @Sypaka

    @Sypaka

    5 жыл бұрын

    if you turn off the wuauserv, you get a companion update application, which demands you to update.I went so far as deleting this server, but it became worse. I got that nag screen once per day.

  • @SkinnyCow.

    @SkinnyCow.

    5 жыл бұрын

    and it keylogs every keystroke right back to Microsoft/NSA/CIA/Homeland Security

  • @77garga

    @77garga

    4 жыл бұрын

    @@SkinnyCow. you mean Mossad...

  • @DrachenYT
    @DrachenYT7 жыл бұрын

    I would love for this man to be my professor. So personable and knowledgeable.

  • @primarypenguin
    @primarypenguin7 жыл бұрын

    Dr. Mike Pound is the man! I will always click on a mike pound video.

  • @TeganBurns
    @TeganBurns7 жыл бұрын

    I can't wait for someone to exploit a update server, everyone will be so confused.

  • @grn1

    @grn1

    3 жыл бұрын

    It's been done, possibly even before your comment was made (Piriform was twice a victim of this).

  • @dannygjk

    @dannygjk

    3 жыл бұрын

    @@grn1 yep it's SOP for hackers.

  • @TheSupernatural72

    @TheSupernatural72

    2 жыл бұрын

    exploit "an" update ..you sucker

  • @ihateyoutubehandles
    @ihateyoutubehandles7 жыл бұрын

    Organizations with legacy software and legacy OS dependencies should isolate offline computers from machines that can access the web. That's information security 101.

  • @johnfrancisdoe1563

    @johnfrancisdoe1563

    5 жыл бұрын

    Nicolas W. Wolf Unless that legacy software has an online component. And EternalBlue can attack machines that only talk to the local network in very minimal ways.

  • @DacLMK

    @DacLMK

    2 жыл бұрын

    Stuxnet proved that you can't isolate yourself from malware.

  • @baldeepbirak
    @baldeepbirak6 жыл бұрын

    Great insight into WCry.

  • @gunpointonu
    @gunpointonu7 жыл бұрын

    This guy's really interesting and eloquent would love to see more videos with him in

  • @ATEAMDarkChemical
    @ATEAMDarkChemical7 жыл бұрын

    You CAN turn off the updates for windows 10. Juest not the clasic way. Some service tweaks and registry tweaks can do anything on windows.

  • @Correctrix

    @Correctrix

    7 жыл бұрын

    Yeah, but don't.

  • @hugofontes5708

    @hugofontes5708

    7 жыл бұрын

    updates> windows crashes doesn't update> people crash windows I guess I just need to find fixes faster then

  • @theX24968Z

    @theX24968Z

    7 жыл бұрын

    all you need to do is disable the update service.

  • @TheMrCarnification

    @TheMrCarnification

    7 жыл бұрын

    I'd rather have to remind myself to update it than to have something important to do and little time to do it and be greeted with the message telling me windows is updating upon booting

  • @OptimusPrimeagar

    @OptimusPrimeagar

    7 жыл бұрын

    Easy turn off your wifi saved alot of time for you!

  • @panchociarer
    @panchociarer7 жыл бұрын

    thing is windows updates tend to break things much more frequently than attacks from the vulnerabilities they patch

  • @JonathanAnon
    @JonathanAnon7 жыл бұрын

    You can turn off Windows 10 updates by stopping the service from running, but there is no "user" option to switch it off. Great video guys, well explained.

  • @starlingohara316
    @starlingohara3167 жыл бұрын

    (Cross posted question) Is WannaCry able to infect systems that don’t have the Microsoft vulnerability once it is present on the infected system's network? Or is it confined only to systems that have the vulnerability?

  • @DeviousMalcontent2
    @DeviousMalcontent27 жыл бұрын

    11:37 Jokes on you! I'm running Windows ME...

  • @LLuann
    @LLuann7 жыл бұрын

    *UPDATES SYSTEM AGRESSIVELY*

  • @ProgrammerSheep

    @ProgrammerSheep

    5 жыл бұрын

    *copies comments aggressively*

  • @sarcastamusraconteur6881
    @sarcastamusraconteur68817 жыл бұрын

    i could watch this guy all day.very entertaining bloke...

  • @agix666
    @agix6667 жыл бұрын

    I only watch Computerphile videos when this guy is doing the videos

  • @EagleOfDestiny1
    @EagleOfDestiny13 жыл бұрын

    *trojan virus starts spreading in China* China 3 years later: “oh yeah check this out”

  • @zeroumashi2947
    @zeroumashi29474 жыл бұрын

    "You've got no business running xp" tell that to ATM manufacturers running SP4.

  • @lordmas2099
    @lordmas20997 жыл бұрын

    I could listen to this guy talk all day

  • @joshinthemoment
    @joshinthemoment7 жыл бұрын

    thanks for sharing. very well developed thought and easy to understand explanation.

  • @nicholasgawler-collins5754
    @nicholasgawler-collins57543 жыл бұрын

    I always thought it was called "WanaCry" since it made you wanna cry.

  • @Kitulous

    @Kitulous

    3 жыл бұрын

    @Harmit Romey if only decrypting was not IMPOSSIBLE due to the immense amount of computational work needed to be done. So begone, bot. Stop promoting scams and go find a real job.

  • @ambassadorofpain1
    @ambassadorofpain17 жыл бұрын

    The only interesting thing about this whole situation is the NSA angle. The rest of this is so over-hyped in the media, it's just another day at the office as far as I'm concerned.

  • @apreasher
    @apreasher7 жыл бұрын

    superb explanation!

  • @Jack_McKalling
    @Jack_McKalling7 жыл бұрын

    computerphile, is it possible that a lot of the videos are recorded in mono sound? I cannot hear anything for some reason

  • @DragonNuts
    @DragonNuts7 жыл бұрын

    Dose it actually give your files back if you pay?

  • @Neceros

    @Neceros

    7 жыл бұрын

    Nope. You can't track bitcoins, so they have no clue who's paid them or not. It's just a ploy to grab money.

  • @jimsmind3894

    @jimsmind3894

    7 жыл бұрын

    I'm SpeeDee Unlikely, often the websites they use to provide the unlock code get shut down quickly, and if you do you'll end up on a sucker's list and a obvious target in future.

  • @TechyBen

    @TechyBen

    7 жыл бұрын

    If bitcoins cannot be tracked... how do people pay for services... Duh!

  • @leofisher1280

    @leofisher1280

    7 жыл бұрын

    I'm SpeeDee I would think that it would. viruses need to be reputable

  • @cybercat1531

    @cybercat1531

    7 жыл бұрын

    No, the authors of WannaCryptor don't track payments/are doing it manually. No-one has yet received a working decrypt key for their files.

  • @youngPC
    @youngPC7 жыл бұрын

    Thanks NSA.

  • @Siminfrance
    @Siminfrance7 жыл бұрын

    Very well explained, thanks

  • @XerroMedia
    @XerroMedia7 жыл бұрын

    Question: Can this ransomware (or ransomware in general) encrypt files that are already encrypted? For instance if I have all the files on a secondary hard drive encrypted with a program like Truecrypt would the ransomware still be able to encrypt those files?

  • @nintendoeats
    @nintendoeats7 жыл бұрын

    My girlfriend's dad (not an enthusiast or especially computer savvy) has written down the number of an update which he needs to prevent windows from installing so that he can run Battlefield Vietnam, which he paid for, and a computer that he paid for running an operating system that he paid for. And hence, the case against forced updates.

  • @InsaneGamersOfficial

    @InsaneGamersOfficial

    7 жыл бұрын

    If you never install the updates, you kind of deserve what comes after them. It's harsh but true. Now, why BF: Vietnam doesn't work is because SECDRV.SYS (the copy protection on the game DVD) had many bugs - one of which allowed for a hackers to remotely control your PC, deploy ransomware, etc. There's loads of news articles if you don't believe me. MS and Macrovision, creator of the DRM, worked together to fix these issues around 2009/2010, but older games that were released before it was fixed are out of luck. MS stopped said versions of Secdrv.sys from working on Windows 10. It can easily be fixed by applying "nocd" patches.

  • @nintendoeats

    @nintendoeats

    7 жыл бұрын

    I was actually telling him about nocd cracks last time I was over. If it's a copy protection issue then I will get him set up with one when we go up this weekend, thanks for the tip. However, my point stands that the ability to not install specific updates (and ESPECIALLY feature updates) is relevant to consumers.

  • @KnakuanaRka

    @KnakuanaRka

    2 жыл бұрын

    @@InsaneGamersOfficial You’re totally missing the point; they “got what was coming to them” because they were FORCED to install the updates!

  • @X0bevil
    @X0bevil3 жыл бұрын

    "No one in Nottingham as far as we know has got it" sounds like he's talking about a way too familiar virus

  • @kaca2903
    @kaca29037 жыл бұрын

    I like how descriptive names in programming are.. WannaCry for a ransomware, RockYou, HashCat, patches etc. Pulling paralels between real life things and digital code bits.

  • @aishaibrahim2953
    @aishaibrahim29532 жыл бұрын

    I love the cubes in the background

  • @jeffirwin7862
    @jeffirwin78627 жыл бұрын

    Have you considered changing your name to Dr. Hashtag?

  • @karmaarachnid8345

    @karmaarachnid8345

    7 жыл бұрын

    Dr. Octothorpe would be more dignified... and menacing.

  • @Mynx31
    @Mynx317 жыл бұрын

    National Insecurity Agency

  • @KSh14
    @KSh147 жыл бұрын

    I'm sorry if this is a silly question. But, how exactly are Linux machines protected from this? Linux uses samba to share files too right?

  • @MASAbirokou
    @MASAbirokou3 жыл бұрын

    thank you for translating 😸! so helpful !

  • @Ronenlahat
    @Ronenlahat7 жыл бұрын

    One should be able to turn off annoying UI updates and leave only important security ones

  • @theX24968Z

    @theX24968Z

    7 жыл бұрын

    you can turn it off by disabling the windows update service.

  • @groszak1

    @groszak1

    6 жыл бұрын

    does it keep the important security updates?

  • @mortenmoulder
    @mortenmoulder7 жыл бұрын

    To anyone saying "Why not block the Bitcoin address": There is no one "owning" Bitcoin who can define rules for it. No one can stop what Bitcoin has become nor can they change the Bitcoin protocol. It's simply impossible to do such thing, when everything is run P2P and with no owner. Look at it like torrents. "The owners of torrenting" (inventors) cannot simply say "This torrent cannot be downloaded anymore", because they have no authority.

  • @ishashka

    @ishashka

    5 жыл бұрын

    The power of convention

  • @karialatalo2447
    @karialatalo24477 жыл бұрын

    In addition to what has been said about manually configuring scheduled tasks or group policies to disable Win10 updates, it's also possible to request a special corporate version of it. There's some fringe cases, where the multi-gigabyte updates over the network are not tenable, or when the computer absolutely cannot suffer unforeseen restarts / performance degradations. There was one case with African wild life reservation posts and their satellite data caps..

  • @scottbeard9603
    @scottbeard96037 жыл бұрын

    Dr Pound, you mentioned at the end that people may not update because of the necessity of resets. Is this actually a necessity? It seems to me that more people would update regularly if it didn't affect their usage. If it is a necessity, why? I only ask because I am a Uni student, and I know that if I'm writing an essay a few hours before a deadline (I know I shouldn't, but who doesn't?), then I will not install a patch that requires a restart. I then forget about it until I'm reminded maybe a week later

  • @SamZcko
    @SamZcko4 жыл бұрын

    Hey mike, I know you aren't reading this but thank you so much for being a breath of fresh air when defending Microsoft (the company I do tech support for). We get calls daily from customers who still in 2020 have not upgraded to Windows 10 and blame us for getting a virus on their machine running Windows 7. Thank you Michael Pound!!!

  • @radiandrzgaming8708

    @radiandrzgaming8708

    Жыл бұрын

    With the exception that Windows 10 is the malware.

  • @michaelgoodwin593
    @michaelgoodwin5937 жыл бұрын

    Ad-blocker will keep me safe.

  • @josephf151
    @josephf1517 жыл бұрын

    Here is a thought that I came up with, however I am unsure of how well it could be applied (if it even can be). If you were to take a hard disk that had been encrypted by this program, and referenced a known file on the disc, say the OS or some document that has been shared with someone else, would you be able to then throw a ton of compute power at trying to crack just that one file and thus have a key? (or would you need to crunch the whole disc?) If I am correct, these encrypted files should still be viewable in the file explorer, they just cannot be read, so would I be wrong in assuming that you could locate files based on their size, and then use the encrypted copy and the known good to solve the problem? If you found a key, would it work on other computers? because if so then it would be worth it to throw a super computer on it and thus get a key relatively quickly. Either way, thank you for yet another great video. EDIT: it seems they are using RSA keys? does that mean brute forcing even one file is out of the picture?

  • @byAnArgentinian
    @byAnArgentinian7 жыл бұрын

    Great info. And yes, you can turn off auto updates on W10. Which is good for some scenarios.

  • @ergogray3143
    @ergogray31437 жыл бұрын

    This is why the backdoor should be off limits...unless it's consensual.

  • @palestinevideos2025

    @palestinevideos2025

    4 жыл бұрын

    My backdoors off limits until at least the 3rd date

  • @david6532

    @david6532

    3 жыл бұрын

    My back door is intact.

  • @ayeapprove
    @ayeapprove7 жыл бұрын

    5:36 but like you said Port 445 should not be open on your WAN interface but it still spread to other networks. This just proves that big router companies had also been exploited by the NSA, don't you think? Also the NSA does not only engage in counter terrorism. They engage in every way to influence world politics to the benefit of their country.

  • @Cryo_Gen

    @Cryo_Gen

    5 жыл бұрын

    They hate us too dont worry

  • @tahu8766
    @tahu87667 жыл бұрын

    thanks for the explain !, this channel help so much

  • @adamwheeler7310
    @adamwheeler73107 жыл бұрын

    Can you please make a video on how exactly the EternalBlue exploit and the DoublePulsar exploit worked? From what I understand it's a buffer overflow, but I'd love to see a detailed analysis on how the actual exploit works, It'd be very interesting and you always explain everything perfectly! Thanks!