Microsoft: NSA’s Bug Hoarding To Blame For WannaCry Ransomware Spread

Microsoft’s President and Chief Legal Officer, Brad Smith, called the NSA the main actor to blame for the global spread of WannaCry ransomware. The attack started on Friday, when many companies were ending their work days, especially in Asia, and it has already spread to over 150 countries. We may see many more reports about WannaCry infections starting today, as organizations around the world see how their networks have been impacted over the weekend.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • COLGeek
    When tools (and their knowledge/flaws) like these escape into the wild, you don't get to choose who uses (abuses) them. This is true whether the intentions are honorable, or not.
    Reply
  • problematiq
    And so Microsoft will be charging double for the information they sell to the NSA in this backlash. Also, don't leave RDP and SMB/CIFS exposed to the net, it's just stupid.
    Reply
  • TheAfterPipe
    Blaming Microsoft for this issue is pretty weak.
    Reply
  • IceMyth
    Imagine if Apple agreed to allow CIA/other agencies or gave them a way to break their phone security to access the phone!!!
    Reply
  • -Fran-
    19693702 said:
    Blaming Microsoft for this issue is pretty weak.

    It is their software, so they are accountable for it.

    That doesn't mean what they're saying is not correct: if you discover a bug, and more importantly, a SECURITY HOLE, it is your duty to report it. Unfortunately, there's no gap-closing between what is (and we should all agree here) morally right and legally right. I would imagine, if there's a way to prove it, MS could sue the agencies, but that is just getting into the pockets of tax payers at the end of the day... So many things gone wrong here for everyone it's amazing this is not getting more regular press. Or maybe I'm under a rock, lol.

    Cheers!
    Reply
  • InvalidError
    19693708 said:
    Imagine if Apple agreed to allow CIA/other agencies or gave them a way to break their phone security to access the phone!!!
    The way Apple's Secure Enclave is designed, Apple shouldn't be able to even if it wanted to unless it issued an OS update to decrypt phones the next time they are unlocked and stopped using SE-based encryption afterward.

    19693716 said:
    19693702 said:
    Blaming Microsoft for this issue is pretty weak.

    It is their software, so they are accountable for it.
    Microsoft can't be blamed for not fixing bugs that haven't been disclosed. Let us hope that this will serve as a lesson for every intelligence agency advocating intentional backdoors in software and systems. Secrets want to be shared and if you want to keep backdoors or exploit secret, you had better be ready for the consequences when they inevitably get leaked or re-discovered in the wild.
    Reply
  • Microsoft knew for this exploit, it is Microsoft who let them do it. Those f. crooks at Microsoft have courage to even f. comment it. I don't blame NSA for anything. It is f. MS. to blame for cause they are the ones who made the f. deal with NSA to start with.
    Reply
  • COLGeek
    Just keep in mind that not only MS products have been exposed by the leaked NSA knowledge/tools. This is a broader issue and affects far more than just the MS landscape.
    Reply
  • -Fran-
    19693754 said:
    Microsoft can't be blamed for not fixing bugs that haven't been disclosed. Let us hope that this will serve as a lesson for every intelligence agency advocating intentional backdoors in software and systems. Secrets want to be shared and if you want to keep backdoors or exploit secret, you had better be ready for the consequences when they inevitably get leaked or re-discovered in the wild.

    I don't know if "blamed", but they are "accountable". That is why I used that word in particular.

    Cheers!
    Reply
  • motocros1
    "Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage." Ya I bet they were "leaked" and no money was exchanged.
    Reply