WannaCry Ransomware: Microsoft Faulted Over Cyber-Attacks While Shifting Blame to NSA

Advertisement
By Dina Bass, Bloomberg | Updated: 17 May 2017 10:42 IST

There's a blame game brewing over who's responsible for the massive cyber-attack that infected hundreds of thousands of computers. Microsoft is pointing the finger at the US government, while some experts say the software giant is accountable too.The attack started Friday and has affected computers in more than 150 countries, including severe disruptions at Britain's National Health Service. The hack used a technique purportedly stolen from the US National Security Agency to target Microsoft's market-leading Windows operating system. It effectively takes the computer hostage and demands a $300 (roughly Rs. 20,000) ransom, to be paid in 72 hours with Bitcoin.

Microsoft President and Chief Legal Officer Brad Smith blamed the NSA's practice of developing hacking methods to use against the US government's own enemies. The problem is that once those vulnerabilities become public, they can be used by others. In March, thousands of leaked Central Intelligence Agency documents exposed vulnerabilities in smartphones, televisions and software built by Apple, Google and Samsung Electronics.

What Is WannaCry, Who Is Affected, and Everything Else You Need to Know About It

Advertisement

The argument that it's the NSA's fault has merit, according to Alex Abdo, staff attorney at the Knight First Amendment Institute at Columbia University. Still, he said Microsoft should accept some responsibility.

Advertisement

"Technology companies owe their customers a reliable process for patching security vulnerabilities," he said. "When a design flaw is discovered in a car, manufacturers issue a recall. Yet, when a serious vulnerability is discovered in software, many companies respond slowly or say it's not their problem.'"

Advertisement

Microsoft released a patch for the flaw in March after hackers stole the exploit from the NSA. But some organisations didn't apply it, and others were running older versions of Windows that Microsoft no longer supports. In what it said was a "highly unusual" step, Microsoft also agreed to provide the patch for older versions of Windows, including Windows XP and Windows Server 2003.

In 2014, Microsoft ended support for the highly popular Windows XP, released in 2001 and engineered beginning in the late 1990s, arguing that the software was out of date and wasn't built with modern security safeguards. The company had already been supporting it longer than it normally would have because so many customers still used it and the effort was proving costly. Security patches would be available for clients with older machines, but only if they paid for custom support agreements.

Advertisement

But with Microsoft making an exception this time and providing the patch free to XP users, it may come under pressure to do the same next time it issues a critical security update. (These are the most important patches that the company recommends users install immediately). That could saddle the company with the XP albatross for many years past when it hoped to be free from having to maintain the software. The precedent may impact other software sellers too.

"They're going to end up going above and beyond and some vendors are going to start extending support for out-of-support things that they haven't done before," said Greg Young, an analyst at market research firm Gartner Inc. "That's going to become a more common practice."

On Monday, private-sector sleuths found a clue about potentially who's responsible for the WannaCry attack. A researcher from Google posted on Twitter that an early version of WannaCry from February shared some of the same programming code as malicious software used by the Lazarus Group, the alleged North Korean government hackers behind the destructive attack on Sony Corp. in 2014 and the theft of $81 million from a Bangladesh central bank account at the New York Fed last year. Others subsequently confirmed the Google researcher's work.On its own, the shared code is little more than an intriguing lead. Once malicious software is in the wild, it is commonly reused by hacking groups, especially nation-states trying to leave the fingerprints of another country. But in this case, according to Kaspersky Lab, the shared code was removed from the versions of WannaCry that are currently circulating, which reduces the likelihood of such a 'false flag' attempt at misdirection. Some security researchers speculated that if the perpetrators were North Korean, the goal may have been to cause a widespread internet outage to coincide with this weekend's latest missile test.

As for Microsoft, some intelligence agency experts questioned its NSA criticism, saying it's unreasonable for the company to ask governments to stop using its products as a way to attack and monitor enemies.

"For Microsoft to say that governments should stop developing exploits to Microsoft products is naive," said Brian Lord, a managing director at PGI Cyber and former deputy director at the Government Communications Headquarters, one of the UK's intelligence agencies. "To keep the world safe these things have to be done."

He said that intelligence agencies tended to be good and responsible stewards of the hacks and exploits they develop. "Occasionally mistakes happen," he added.

© 2017 Bloomberg L.P.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  2. OTT Releases This Week: The Bads of Bollywood, Article 370, and More
  3. Nothing Ear 3 With 'Super Mic' Feature, Up to 45dB ANC Launched: See Price
  4. DJI Mini 5 Pro With 1-Inch Camera Sensor Launched at This Price
  5. Amazon Great Indian Festival Sale 2025: Check Early Deals on Tablets
  6. Amazon Sale 2025: Check Top Deals on These iQOO Smartphones
  7. UBON Targets 25 Percent Online Business Share with Quick Commerce Push
  8. Biggest Offers on Smartphones During Amazon Great Indian Festival Sale
  9. Xiaomi Announces Offers on These Products Ahead of Amazon, Flipkart Sales
  10. These Companies Fired Over 10K Employees Between July and September 2025
  1. iQOO 15 Design Teased, Pre-Reservation Begins Ahead of China Launch in October
  2. Amazon Sale 2025: Biggest Offers on iPhone 15, Samsung Galaxy S24 Ultra, OnePlus 13R, and More Revealed
  3. Oppo Find X9 Renders Reveal Design, Dolby Vision Support Ahead of October Launch
  4. Nvidia Invests $5 Billion in Intel, to Jointly Develop AI Infrastructure and PC Chips
  5. Google Rolls Out Gemini in Chrome Browser to Introduce AI Agentic Capabilities, Safety Features For Users
  6. iPhone 17 Series, iPhone Air, Apple Watch Series 11, AirPods Pro (3rd Generation) and More Go on Sale in India: See Price
  7. Astronomers Reveal Sudden Explosion of Small Asteroid Over France
  8. Rare ‘Crescent Sunrise’ Solar Eclipse to Grace Skies Over Antarctica and New Zealand
  9. Sun Shows Signs of Rising Activity Following Decades of Weakening, Study Finds
  10. IMAP Space Weather Mission to Lift Off Soon, NASA Confirms Broadcast Plans
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.