Live data from Hacker News

The No More Ransom Project

nomoreransom.org

101–110 of 241 posts

Re: The No More Ransom Project

#101

My mini Ask HN: Do you trust makers of security software?

Not very much, no.

But in the context of ransomware, the advice presented here is game-theoretically sound (and proven by thousands of years of experience in dealing with criminals demanding ransom), so I do trust it.

Re: The No More Ransom Project

#102
post #65

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

> What bothers me about their advice is that it is only correct macroeconomically. That's because it's the correct advice. Ransom is a very old business, and experience throughout history shows you should never pay the danegeld[1] . > ignores that it is in cybercriminals' best interest to let you decrypt after you paid That isn't being ignored. Paying the ransom is short-term thinking. Of course they will let you dec…

You can guarantee that it is an isolated event by backing up your files in the future. I imagine most victims are embarrassed and try to think of it as an expensive lesson.

Re: The No More Ransom Project

#104
post #67
post #5

Earlier quoted context omitted.

Anytime you're in a similar dilemma just disable JavaScript. There are even plugins that allow you to do that with one click.

The better advice is imo to keep your browser up-to-date. JS exploits have been come increasingly rare these days, mostly due to Chrome's excellent example of patching quickly and paying good money for exploits (e.g. Pwn2Own). JS 0days are imo far too valuable now to waste them on normal users. So no, disabling JS wouldn't make much sense, if your have an evergreen browser. Disable Flash & Java and try to minimize do…

What do the JS 0days get used for nowadays?

Re: The No More Ransom Project

#105
post #67
post #5

Earlier quoted context omitted.

Anytime you're in a similar dilemma just disable JavaScript. There are even plugins that allow you to do that with one click.

The better advice is imo to keep your browser up-to-date. JS exploits have been come increasingly rare these days, mostly due to Chrome's excellent example of patching quickly and paying good money for exploits (e.g. Pwn2Own). JS 0days are imo far too valuable now to waste them on normal users. So no, disabling JS wouldn't make much sense, if your have an evergreen browser. Disable Flash & Java and try to minimize do…

[deleted]

Re: The No More Ransom Project

#107

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

It doesn't ignore any of the things you said. Yes, it's most likely better for you to pay. This kind of selfish thinking is, like many other kind of selfish thinking, what enables this type of crime in the first place . Sure the criminals will release your files. Just like with regular, "meatspace" ransom, only a stupid criminal would not release hostages after having their demands met. It's in their best interest to…

I'd say just like in real life, stupid criminals exist. If criminal A says to criminal B "I'll sell you a solution that encrypts their files and I'll host the decryptor for 5$ a month" I can totally see a dumb criminal B being fully willing to rely on the reputation of ransomware as working to not pay that 5$ a month.

To a certain criminal any effort no matter how miniscule at all in actually providing a way to decrypt the files is useless, and I think with the reputation that's spread about ransomware we're at a point where more scammers will start to piggyback on reputation and stop following through

Re: The No More Ransom Project

#108
post #34

Even in an issue about software, americans pull out guns. Have you noticed how noone else does this? It's shocking and abhorrent.

You do realise guns have other uses other than shooting people don't you. There's nothing remotely shocking or abhorrent about guns.

Most guns are designed to kill people. Very few guns are designed to disable laptops. GP's point would have been valid if he had said "typical and pathetic" or "cliched and unimaginative" rather than "shocking and abhorrent". b^)

Re: The No More Ransom Project

#109

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

That problem comes up with collective action all the time. Workers rights in developing countries for example... if all of the workers banded together to resist their employer's unfair treatment then... blah blah blah.. but in reality average people are awful at joining together to create a change that results in a greater good. When people are isolated and feel the impact of some injustice, they tend to give up fairly quickly without any thought given to what would be best for the greater good. That's my experience of life anyway. Rationality doesn't work very well in abstracted problems that involve reasoning about how you should suffer in this moment for the greater good of everyone suffering such moments. So the scammers are smart to make the cost of cooperating fairly low in a lot of cases. It's definitely easier to pay up than to try to make a federal case out of it. And honestly your inconvenience is not going to cause the wheels of law enforcement to spin fast to figure out which international gang is targeting you. If you don't pay you probably won't ever get anything back and law enforcement won't do anything about it. So really what's the point of personal heroics here other than rational arguments about what the right move would be from a game theoretic point of view? Just pay and move on.

Re: The No More Ransom Project

#110
I started writing about this but just a personal safeward. Yesterday I dropped my phone by accident, it cracked and doesn't work anymore. But besides the monetary loss, everything was backed-up from the day before so no problem.
Post reply on HN