So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…
"If it gets out that you paid and you didn't get unlocked then no one would pay." Sounds like an easy way to get rid of ransomware. Just spread rumors that you didn't get your files back even though you paid. Somehow I have a feeling that wouldn't work, though. Many people would still pay.
The No More Ransom Project
91–100 of 241 posts
Re: The No More Ransom Project
#92Earlier quoted context omitted.
That's just hilariously twisted.
It's such a perfect example of how human systems are molded by underlying incentives. Of course, the incentives themselves arise within immense cultural and technological contexts. Hopefully one day we see further past the dense fog of complexity. Assuming we aren't adding to it at a faster rate...
To twist it even further, note that the shifts of culture and technology are directed by aggregated incentives of people. What a nice and strong feedback loop there. Only shows how little control societies have over where they're going.
Re: The No More Ransom Project
#93Earlier quoted context omitted.
In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.
Or we could be slightly less nefarious and create ransomware that decrypts everyone's stuff after the allotted time but leaves a congratulatory "thank you for not cooperating with criminals" message to the people that didn't pay...
Please don't do this. People (some would call them victims of cyber crime but not me) are EVIL and if they can trace it back to you, they will sue you. Doing this is not a good idea except as a thought experiment.
It is probably obvious to a lot of people but there are still good people out there who believe in the goodness of people so I thought I should spell it out.
Re: The No More Ransom Project
#94> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…
> For your particular case it could be the best solution to just pay - as even police departments have done before. It could be the best solution for you to pay - if you don't care that you'll finance the attacks on other people and cause more harm overall. So yes, from a purely egoistic perspective it makes sense. The question you should ask is not "is it worth paying xxx for my data?", it's "is it worth paying xxx…
The other option gives you an immediate, personal loss - "your files are gone" - together with an all but unobservable, mid- to longterm benefit for society.
You can of course hope for the majority to take the second option, but hope is the first step on the path to disappointment.
Re: The No More Ransom Project
#95Earlier quoted context omitted.
If enough people do that, then attackers will start attacking dropbox, as well.
Hence my question. They'll ransom my Dropbox but Dropbox keeps deleted files and old versions around, so I'd be safe unless they specifically target Dropbox and Dropbox can't mitigate it.
But if you are a concerned customer, why don't you just head over to their help pages and see what the features and limits regarding history and file deletion are?
Re: The No More Ransom Project
#96My mini Ask HN: Do you trust makers of security software?
Re: The No More Ransom Project
#97Earlier quoted context omitted.
In that case, the victims could refuse to pay ransom and the criminals will go out of business.
But a virus has zero marginal cost. Even one guy paying and they make money.
Re: The No More Ransom Project
#98Earlier quoted context omitted.
If enough people do that, then attackers will start attacking dropbox, as well.
Hence my question. They'll ransom my Dropbox but Dropbox keeps deleted files and old versions around, so I'd be safe unless they specifically target Dropbox and Dropbox can't mitigate it.
Re: The No More Ransom Project
#99> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…
> What bothers me about their advice is that it is only correct macroeconomically. That's because it's the correct advice. Ransom is a very old business, and experience throughout history shows you should never pay the danegeld[1] . > ignores that it is in cybercriminals' best interest to let you decrypt after you paid That isn't being ignored. Paying the ransom is short-term thinking. Of course they will let you dec…
Re: The No More Ransom Project
#100This is a Windows phenomenon only right? I'd just restore from Time Machine and go along on my way.