Live data from Hacker News

University pays $20,000 to ransomware hackers

bbc.co.uk

31–40 of 80 posts

Re: University pays $20,000 to ransomware hackers

#31

Earlier quoted context omitted.

It's difficult to create backups if you can't write into the backups storage.

The way I do it is I create backups locally and then copy them to my NAS over ftp(with a password), instead of samba. Hopefully, that way any ransomeware would not be able to encrypt my nas as well, as it does not have any publicly accessible folders on the network.

The problem is that ransomware doesn't have to activate immediately, so you can end up with multiple copies throughout your backups before it takes effect. Hence, restoring from backups may not solve an infection.

Re: University pays $20,000 to ransomware hackers

#32

Microsoft really needs to build ransomware behavior detection directly into Windows. The behavior of these programs is quite distinctive. The advent of cryptocurrency was the missing link to enable all manner of anonymous extortion schemes, and this one in particular seems to now be a mainstream threat. Microsoft should be all over this.

Ransomware detection is just a (perhaps necessary) band-aid. By default all applications should be sandboxed. Why should a random application be able to read/write to every user directory? We enforce process separation in memory, we should do the same on disk.

> all applications should be sandboxed.

not a bad plan, but also, all data should be backed up. In this 'cloud age' of computing, there's no reason, and no excuse. I certainly don't want to blame the victims of ransomware, but if that data was so important that they paid ransom to get it back, why didn't they back it up ?

Re: University pays $20,000 to ransomware hackers

#34

People asking for ransoms are shady to begin with, but to target a university? That's past gangster, that's just wrong.

universities charge fees that are tantamount to "ransom" in order to get your degree. They aren't much better (at least US ones ) than the thieves.

Re: University pays $20,000 to ransomware hackers

#35

Earlier quoted context omitted.

> Why openly announce that you're paying the ransom? An effective thing they could have done is to announce that they paid the ransom, but that the decryption did not work (even though it did). That has the advantage of discouraging other people from paying up, and therefore reduces the incentive to create more ransomware attacks. Hell, the government could step in and recruit people and companies to falsely claim th…

> Hell, the government could step in and recruit people and companies to falsely claim that they were ransomware victims who paid up, but never got decryption keys and were screwed over. That could put a damper on ransomware psychology. This actually did happen to me. Paid the money, got the key, couldn't unlock my files. Damn shame.

I'm sorry to hear that. Being Hacker News I think we'd all be very interested if you are able to share some details such as:

- how your system got compromised?

- did you have backups? (and did the backups get encrypted?)

- how much did you pay and by what method?

- why do you think the key didn't work?

EDIT: It now occurs to me that you're following my suggestion about falsely claiming to be a ransomware victim to discourage ransom payments. Whoosh!

Re: University pays $20,000 to ransomware hackers

#36

Earlier quoted context omitted.

> Why openly announce that you're paying the ransom? An effective thing they could have done is to announce that they paid the ransom, but that the decryption did not work (even though it did). That has the advantage of discouraging other people from paying up, and therefore reduces the incentive to create more ransomware attacks. Hell, the government could step in and recruit people and companies to falsely claim th…

> Hell, the government could step in and recruit people and companies to falsely claim that they were ransomware victims who paid up, but never got decryption keys and were screwed over. That could put a damper on ransomware psychology. This actually did happen to me. Paid the money, got the key, couldn't unlock my files. Damn shame.

I see what you did there.

Re: University pays $20,000 to ransomware hackers

#37

Earlier quoted context omitted.

> Hell, the government could step in and recruit people and companies to falsely claim that they were ransomware victims who paid up, but never got decryption keys and were screwed over. That could put a damper on ransomware psychology. This actually did happen to me. Paid the money, got the key, couldn't unlock my files. Damn shame.

I'm sorry to hear that. Being Hacker News I think we'd all be very interested if you are able to share some details such as: - how your system got compromised? - did you have backups? (and did the backups get encrypted?) - how much did you pay and by what method? - why do you think the key didn't work? EDIT: It now occurs to me that you're following my suggestion about falsely claiming to be a ransomware victim to di…

> you're following my suggestion about falsely claiming to be a ransomware victim

effective, isn't it!

Re: University pays $20,000 to ransomware hackers

#38
post #2

Why openly announce that you're paying the ransom? Here's some major disadvantages that I can think of: 1. Announces to world that you have poor security/backup practices which encourages more attacks against you 2. Announces to world that making and distributing ransomware is good business which encourages more attacks against everyone I understand that public institutions needs financial transparency in order to be…

The school’s vice-president of finance and services said why they openly disclosed it:

As for why the U of C admitted it paid the ransom, as well as releasing the cost, Dalgetty said it’s an effort to be transparent. “We’re a public sector organization and we pride ourselves on our openness,” she said. Source: http://calgaryherald.com/news/local-news/university-of-calga...

Personally, I am glad they disclosed it. For example this incident raises the awareness that having a solid backup policy is important. Maybe this very story will help IT staff from other universities convince upper management to invest funds into developing a more solid backup policy.

Re: University pays $20,000 to ransomware hackers

#39

People asking for ransoms are shady to begin with, but to target a university? That's past gangster, that's just wrong.

universities charge fees that are tantamount to "ransom" in order to get your degree. They aren't much better (at least US ones ) than the thieves.

> US universities charge fees...

FTFY.

The University that this story is about is Canadian.

Re: University pays $20,000 to ransomware hackers

#40

Easy solution - the government writes into law it's illegal to pay ransomware hackers. Sure hackers might get the occasional payee after this but the likelihood goes down dramatically removing much incentive, especially for larger organisations to be targeted.

Just classify them as terrorists.

It's immoral to pay criminals.

Post reply on HN