Live data from Hacker News

The No More Ransom Project

nomoreransom.org

21–30 of 241 posts

Re: The No More Ransom Project

#21

Earlier quoted context omitted.

Why are you afraid to click the link?

> Why are you afraid to click the link? Because ransomware criminals would probably love to take over that site and start distributing ransomware or other malware from it. And I have no way to judge how well that site's owners have protected it from that sort of attack. When I'm in doubt, I tend to err on the side of caution.

> Because ransomware criminals would probably love to take over that site

I assume most people reading the website would be those already infected.

The criminals are more likely to take over any other high traffic website and infect computers of clueless people who have never heard of ransomware.

Re: The No More Ransom Project

#22
post #5

Earlier quoted context omitted.

Anytime you're in a similar dilemma just disable JavaScript. There are even plugins that allow you to do that with one click.

JS is not the only attack surface in a browser. There have been exploitable bugs in image parsers, font renderers, etc. Tracking is possible without JS as well. Maybe try lynx?

> Maybe try lynx?

Or just use VPS when surfing the web.

Re: The No More Ransom Project

#23

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

Re: The No More Ransom Project

#24
post #15

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

It's been pointed out in the past that most ransomware services have better customer support than paid services. That's because they stand to gain $XXX from each successful interaction and they stand to lose substantially more if they have a reputation of not returning the data.

That's just hilariously twisted.

Re: The No More Ransom Project

#25
post #20
post #17

Earlier quoted context omitted.

> For your particular case it could be the best solution to just pay - as even police departments have done before. It could be the best solution for you to pay - if you don't care that you'll finance the attacks on other people and cause more harm overall. So yes, from a purely egoistic perspective it makes sense. The question you should ask is not "is it worth paying xxx for my data?", it's "is it worth paying xxx…

But your individual case isn't going to affect their behavior. If you wanted to change the situation, not paying simply isn't going far enough. You'd need to coordinate with other potential victims or do something like this website and spread defenses. Without putting effort into organization, your thinking that you've helped others is pure egoism because these schemes only require a few people to pay to be profitabl…

> But your individual case isn't going to affect their behavior.

It isn't going to affect them much. But as anybody who runs a business knows, the difference between loss and profit generally hinges on a number of sensitive factors. Note, for example, that drug dealing pays so poorly that many drug dealers live with their moms:

http://articles.latimes.com/2005/apr/24/opinion/oe-dubner24

Refusing to pay on your own doesn't help other people much, but it still helps.

Re: The No More Ransom Project

#26

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

This comment contains a policy suggestion. I want it to become law in the United States and elsewhere.

I can't quite use the word "literally" but I almost can so I'll do so anyway: if you pay a ransom, you are literally paying for your party to attack someone else. And you are actually literally (not metaphorically) funding their next attack.

Paying a ransom should be a criminal act that is twenty times worse than asking for one. It should be illegal for the exact same reason that possession of stolen goods is illegal.

On a microeconomic level it might make sense for you personally to buy stolen goods off the street: the existence of the laws making you a criminal if you do no longer makes this true.

Re: The No More Ransom Project

#27
post #17

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

> For your particular case it could be the best solution to just pay - as even police departments have done before. It could be the best solution for you to pay - if you don't care that you'll finance the attacks on other people and cause more harm overall. So yes, from a purely egoistic perspective it makes sense. The question you should ask is not "is it worth paying xxx for my data?", it's "is it worth paying xxx…

That's a convincing argument.

Re: The No More Ransom Project

#28
post #23

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

> Someone could create ransomware that will never decrypt, even after the ransom is paid.

This already exists: http://arstechnica.com/security/2016/07/posing-as-ransomware...

> "Once it executes it, it pops up a ransom message looking like any other ransomware," Earl Carter, security research engineer at Cisco Talos, told Ars. "But then what happens is it forces a reboot, and it just deletes all the files. It doesn't try to encrypt anything—it just deletes them all."

Re: The No More Ransom Project

#29
post #23

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

Kind of surprised no one's actually done this. I mean, there has to be at least a few really bored trolls and griefers out there who mess around with people's systems for 'fun' rather than money. I'm sure some teen in an ex soviet state somewhere would find it funny to watch someone have a breakdown when their cash doesn't get them their work back.

Or that some criminal group/mafia would use it to try and 'sink' their rivals. After all, a gang in competition with whoever makes these malware programs would probably love to shut down their revenue from ransomware. With say, their rivals name attached to the cruel hoax.

Still, I suspect something like this will happen at one point.

Re: The No More Ransom Project

#30
post #4

Earlier quoted context omitted.

Looks like decryption for badly constructed ransom ware

It isn't just badly made ransomware; in some cases people have stolen the master key or the responsible party has released it. In other cases C&C servers have been seized and keys recovered that way. Ransomware exists thanks to a fundamental mistake in the Unix (+Windows, +others) model that a process' rights to the filesystem automatically inherit from the user's rights. Imagine if all processes running under the sa…

I'm really quite surprised that there are no big and used by default user facing sandboxing solutions for the major OSes out there.

With dynamic prompts akin to the firewall prompts familiar from Windows/Mac.

'The program "Chrome" wants to create the file "/home/username/.config/chrome/config". Allow "Chrome" to access [just this file / the diretory ~/.config/chrome / the diretory /home/username]'

'WARNING: The program "totally_legit_for_reals" wants to overwrite the file ~/.xinitrc. This is potentially dangerous. Allow access? -> Are you sure?'

'ALERT: the unknown program "xxx" has gained superuser privileges and wants to overwrite a critical system file System32/whatever.dll. This is very dangerous....'

Then again, non techie users usually ignore all those prompts and just click accept.

Just look at the mess that is Android permissions. Almost no one actually checks them or rejects apps that ask for way too much.

I'd still really like a kernel level protection mechanism that requires granting each executable the capabilities it requests, with dynamic pin the Linux world there are SELinux, AppArmor grsecurity, which are often cumbersome to use).

Post reply on HN