Live data from Hacker News

The No More Ransom Project

nomoreransom.org

121–130 of 241 posts

Re: The No More Ransom Project

#121
Is there any case where versioned backups wouldn't completely solve a ransomware situation?

Assuming, of course, that the ransomware doesn't somehow spider out and compromise all your past backups as well. Let's assume your past backup versions are safe.

Re: The No More Ransom Project

#122
post #95
post #53

Earlier quoted context omitted.

Hence my question. They'll ransom my Dropbox but Dropbox keeps deleted files and old versions around, so I'd be safe unless they specifically target Dropbox and Dropbox can't mitigate it.

Last time I used Dropbox, you can always get deleted versions back. They might make it difficult though, spamming the log with a gazillion created/deleted files. And maybe there is actually a limitation of, say, 10 deleted versions of the same file path (that might make sense)... but I don't remember seeing any of those limitations last time I looked at it (which was a few years ago). But if you are a concerned custo…

If there are certain restrictions to how far you can go back, they will likely find a way around that. If it's 10 versions of the same file path, they'll overwrite each path with a different single-byte file 11 times.

Re: The No More Ransom Project

#123
post #48

For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

Dropbox has a help article on ransomware: https://www.dropbox.com/help/8408

For mass deletes that are cumbersome to recover using Dropbox's interface, that article mentions you can contact customer support to get assistance recovering from mass deletion events.

Re: The No More Ransom Project

#124
post #74

Earlier quoted context omitted.

The ransomware scheme only works because the users actually get their files back and the prices are pretty reasonable for many victims. The perpetrators spend a lot of time on the ransomware and its backend. The better it works works, the more people will pay. They rely on people like us to spread the word that it's not a scam, it's real and it works. Now that I think about it: It would really damage the whole ransom…

> It would really damage the whole ransomware scheme if there were fake / rogue versions that won't decrypt, wouldn't it? Or a single fake story about how ransom doesn't give your data back, published in a high-profile newspaper. Come to think of it, our news sources write bigger lies every day, here they could actually do some good without any risk to their own reputation.

This wouldn't really help, because much like spam, the costs are extraordinarily asymmetric, it costs essentially nothing to infect somebody and they need 1 payout in 100000 to make it worth it.

Re: The No More Ransom Project

#125

Is there any case where versioned backups wouldn't completely solve a ransomware situation? Assuming, of course, that the ransomware doesn't somehow spider out and compromise all your past backups as well. Let's assume your past backup versions are safe.

There's a new type of ransomware which threatens to release your files to the public if you don't pay. No amount of backups will help you there. :/

Re: The No More Ransom Project

#127
post #62

Earlier quoted context omitted.

Good comment. I've interacted with ransomware scammers on several occasions. Each time I couldn't help but be impressed by their operations. In one case, the scammers provided an email address for customer support once the victim paid the ransom. They were courteous, helpful and professional - more so than many customer response teams I've had to interact with in legitimate companies. To be clear, I also don't recomm…

To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...

It's more like a part of a post-sales than customer support (a cost centre).

Re: The No More Ransom Project

#128
post #62

Earlier quoted context omitted.

Good comment. I've interacted with ransomware scammers on several occasions. Each time I couldn't help but be impressed by their operations. In one case, the scammers provided an email address for customer support once the victim paid the ransom. They were courteous, helpful and professional - more so than many customer response teams I've had to interact with in legitimate companies. To be clear, I also don't recomm…

To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...

It's more like a part of a post-sales than customer support (a cost centre).

Re: The No More Ransom Project

#129
post #74

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

The ransomware scheme only works because the users actually get their files back and the prices are pretty reasonable for many victims. The perpetrators spend a lot of time on the ransomware and its backend. The better it works works, the more people will pay. They rely on people like us to spread the word that it's not a scam, it's real and it works. Now that I think about it: It would really damage the whole ransom…

I'm kind amazed at the tone deafness of several comments in this thread. I get that as a larger effect, reducing the success rate of scammers hurts their business, but if I'm dealing with someone who's been hit because they weren't adequately prepared, I'm gonna recommend they pay the ransom if they want their stuff back. Because I'm trying to recommend what's best for them. People could be losing their entire family's memories for the last two decades here. (I find for many consumers, photos is their singular valuable on their PC.)

Most of us in this thread ARE adequately prepared with backups, so it's easy to forget that yeah, someone should probably value their family memories over an infinitesimal effect on the scammer business by not paying. A lot of people here seem to suggest lying to or misleading people to believing they can't get their stuff back is a solution, while ignoring that it leaves people... unable to get their stuff back.

Re: The No More Ransom Project

#130
post #5

Earlier quoted context omitted.

Anytime you're in a similar dilemma just disable JavaScript. There are even plugins that allow you to do that with one click.

JS is not the only attack surface in a browser. There have been exploitable bugs in image parsers, font renderers, etc. Tracking is possible without JS as well. Maybe try lynx?

I'd assume Chrome is safer than Lynx these days, to be honest.

Not to mention the fact that using Lynx makes you unique enough for it to be a useful tracking indicator.

Post reply on HN