Live data from Hacker News

The No More Ransom Project

nomoreransom.org

51–60 of 241 posts

Re: The No More Ransom Project

#51
post #48

For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

If enough people do that, then attackers will start attacking dropbox, as well.

Re: The No More Ransom Project

#52

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

This comment contains a policy suggestion. I want it to become law in the United States and elsewhere. I can't quite use the word "literally" but I almost can so I'll do so anyway: if you pay a ransom, you are literally paying for your party to attack someone else. And you are actually literally (not metaphorically) funding their next attack. Paying a ransom should be a criminal act that is twenty times worse than as…

Anyone down voting this should read Thomas Schilling's Strategy of Conflict. At one point in time in England it was punishable by death to pay ransom to pirates.

Re: The No More Ransom Project

#53
post #48

For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

If enough people do that, then attackers will start attacking dropbox, as well.

Hence my question. They'll ransom my Dropbox but Dropbox keeps deleted files and old versions around, so I'd be safe unless they specifically target Dropbox and Dropbox can't mitigate it.

Re: The No More Ransom Project

#54
post #28
post #23

Earlier quoted context omitted.

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

> Someone could create ransomware that will never decrypt, even after the ransom is paid. This already exists: http://arstechnica.com/security/2016/07/posing-as-ransomware... > "Once it executes it, it pops up a ransom message looking like any other ransomware," Earl Carter, security research engineer at Cisco Talos, told Ars. "But then what happens is it forces a reboot, and it just deletes all the files. It doesn't…

In that case, the victims could refuse to pay ransom and the criminals will go out of business.

Re: The No More Ransom Project

#55
post #28

Earlier quoted context omitted.

> Someone could create ransomware that will never decrypt, even after the ransom is paid. This already exists: http://arstechnica.com/security/2016/07/posing-as-ransomware... > "Once it executes it, it pops up a ransom message looking like any other ransomware," Earl Carter, security research engineer at Cisco Talos, told Ars. "But then what happens is it forces a reboot, and it just deletes all the files. It doesn't…

In that case, the victims could refuse to pay ransom and the criminals will go out of business.

But a virus has zero marginal cost. Even one guy paying and they make money.

Re: The No More Ransom Project

#56
post #15

Earlier quoted context omitted.

It's been pointed out in the past that most ransomware services have better customer support than paid services. That's because they stand to gain $XXX from each successful interaction and they stand to lose substantially more if they have a reputation of not returning the data.

That's just hilariously twisted.

It's such a perfect example of how human systems are molded by underlying incentives.

Of course, the incentives themselves arise within immense cultural and technological contexts. Hopefully one day we see further past the dense fog of complexity. Assuming we aren't adding to it at a faster rate...

Re: The No More Ransom Project

#57
post #41

Is using a VM to surf the web a reasonable answer? Are there any VMs (for my MBP for example) that are reasonably fast, don't take a lot of battery, and not clumsy? Can't this be built into the OS so I don't actually have to do it?

There are indeed approaches by Microsoft to run some IE edge processes in micro VMs.

The hard part is figuring out how much communication to allow with the rest of the OS. Do you want to allow sites to set cookies? For every domain, or just for the target domain? If the latter, what happens with a cookie set after a redirect to a different domain? Do you want to allow downloads to reach the host OS?

The more secure you make things, the more usability suffers, so you have to think really hard about all such problems.

Re: The No More Ransom Project

#58

Do Google Drive / Dropbox cloud backups help in this situation? Or do the encrypted versions propagate into the cloud and irreversibly overwrite the plaintext versions?

Not if it's versioned. If you're really afraid of that, just use time machine.

If this happened to me, I think I'd just buy a new SSD and restore from backup.

Re: The No More Ransom Project

#59

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

This happens quite often at medical offices. Five and even six digit ransoms are not unheard of. On the plus side, it helps encourage Windows updates and IT responsibility.

Re: The No More Ransom Project

#60

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

They don't need anyone to trust them and they have nothing to gain from decrypting your files.

They may be a 14 year old kid who ran some kit that somebody else made. If they collect $50 from 25 people, they will be stoked.

Or they may be a sophisticated criminal organization that want to built long term viability.

It's impossible to know which it is. But it is guaranteed that they are criminal and inherently untrustworthy. It is also guaranteed that any money you pay will finance the next wave of more sophisticated malware.

So, no, you cannot trust them to do good. You can trust them to do bad. Now, make your microeconimic choice.

Post reply on HN