Live data from Hacker News

The No More Ransom Project

nomoreransom.org

171–180 of 241 posts

Re: The No More Ransom Project

#171

Earlier quoted context omitted.

This is a good and important point. However is data ransom this kind of duress? In a sense, paying a ransom is taking the law into your own hands -- rather than say to the FBI, "criminals have asked me for ransom" you are interacting with the criminals directly. On a literal level you are literally transferring cold hard cash to them. You make a good argument for why the policy suggestion I made is not a good idea, b…

Yes, it's duress. I'm sure you having 10 years of your life locked up in an encrypted vault would put a cramp in your style. >transferring cold hard cash to them So? If I go to the 7-11 and buy a soda, and the cashier has been skimming the till, I am transferring cold hard cash to a thief. The difference you keep skipping over is mens rea and I suggest you read up on it before you sound more foolish than you already…

That last sentence was really uncalled-for. I think you don't really understand that I was discussing an economic argument.

Regarding putting a cramp in your style - how about if a thief has stolen your phone with valuable something on it that isn't anywhere else, but you have an application that tells you where the phone is and you own a shotgun. Can you go and get your phone back by force if in your calculation it has a higher chance of actually solving your immediate problem, than involving the police? Why or why not? It's your phone. The thief knows what he did. The thief knows that it's yours.

I am not saying that there is no argument on your side of letting people take care of issues directly with criminals (whether by force or transferring ransoms), but there are important arguments on the other side as well. It's certainly not so clear-cut that you can start ending with petty insults (and please check your reply to be substantive if you reply to this.)

Re: The No More Ransom Project

#172
post #145
post #52

Earlier quoted context omitted.

Anyone down voting this should read Thomas Schilling's Strategy of Conflict. At one point in time in England it was punishable by death to pay ransom to pirates.

Yet the modern world decided to go back on that. The principle being that you are not (as) responsible for what you do under duress.

The point of such a law is not to punish ransom payers but to make it so that they never are asked for ransom in the first place.

Re: The No More Ransom Project

#173

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

That's great until the ransomware gets clever and encrypts your backups too. I'm extremely skeptical of the people that say ransomware is good for the economy or whatever. Broken window fallacy. Sure it creates an incentive to protect against hackers. But isn't that a bit circular? Hackers are good because they create inventive to protect against hackers? Ransomware is by far the most economically damaging kind (and…

> Ransomware is by far the most economically damaging kind

is it though, compared to malware ? Consider an elderly person who gets infected with malware/spyware, making his user experience frustrating and confusing. 2 or 3 trips to the Geek Squad for $150 a visit and you're at the same financial loss as paying a ransom. I'm sure there are also people who just dont use their computers due to infections.

Plus, malware has got to be much more prevalent, at least for a long time it was, not sure what the state of it is now. So in total, I would wager that many more dollars have been spent for techs to remove it than have been spent on ransomware.

Re: The No More Ransom Project

#174
post #141

How can a ransomware infect my computer when I visit a website? This site claims it can happen. I understand how the attachment version works but not this one. I'm a security newb.

I didn't see that on the site. Where does it say that? However, vulnerabilities do exist in browsers and that is how that could happen.

Re: The No More Ransom Project

#175
The pro-active approach would be, actually ditch your current setup every 3 months. Like others have said, you shouldn't be keeping valuables around on your laptop.

Incidentally, this is (or used to be) the trial period for a copy of Windows.

Generally I find the data I care about is k in size, the terabytes I seem to accumulate are mostly garbage.

Given how large the size of drives of today are, and how small the data that means anything to any of us remains, the size of storage space and the almost effortless ability to replicate are the primary indication of ransomwares general irrelevance.

Re: The No More Ransom Project

#176
post #170

Earlier quoted context omitted.

When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it. That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if y…

> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or if your backup solution is—from the perspective of the computer being backed up—an append-only store. Like a box of tapes, or Tarsnap using restricted keys, or Arq pointed at a versioned S3 bucket, or a NAS exposing an iSCSI target backed by an LVM thin pool LV with automatic daily snapshots. Sadly, as far as I…

I've contemplated setting up a small home server with write-only shares for backups, but ended up not doing it because of the cost and time. If there were a reasonably priced off-the-shelf product for this, I'd recommend it to everyone I know.

On the other hand, if there were an off-the-shelf product for this, it would probably have unpatched security issues two weeks after you bought it, and if it were in common use you'd see ransomware targeting it. Tough problem to solve if you're not running and maintaining your own devices.

I suppose tarsnap or S3 would be the way to go, I'm just not that into cloud backups. Maybe it's time to get over that.

Re: The No More Ransom Project

#177
post #170

Earlier quoted context omitted.

When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it. That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if y…

> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or if your backup solution is—from the perspective of the computer being backed up—an append-only store. Like a box of tapes, or Tarsnap using restricted keys, or Arq pointed at a versioned S3 bucket, or a NAS exposing an iSCSI target backed by an LVM thin pool LV with automatic daily snapshots. Sadly, as far as I…

Fortunately, there do exist several inexpensive and user-friendly incremental cloud backup solutions. For a few bucks a month you can back up everything to Cloudflare or Backblaze and be fine even if your primary copy and recent backups all get hosed.

Re: The No More Ransom Project

#178

Is there any case where versioned backups wouldn't completely solve a ransomware situation? Assuming, of course, that the ransomware doesn't somehow spider out and compromise all your past backups as well. Let's assume your past backup versions are safe.

Are the versioned backups physically separated from the infected machine? Otherwise what stops it from just encrypting your backups hard drives as well, everytime you connect them?

What about a versioned filesystem (like ZFS)?

Re: The No More Ransom Project

#179
post #95
post #53

Earlier quoted context omitted.

Hence my question. They'll ransom my Dropbox but Dropbox keeps deleted files and old versions around, so I'd be safe unless they specifically target Dropbox and Dropbox can't mitigate it.

Last time I used Dropbox, you can always get deleted versions back. They might make it difficult though, spamming the log with a gazillion created/deleted files. And maybe there is actually a limitation of, say, 10 deleted versions of the same file path (that might make sense)... but I don't remember seeing any of those limitations last time I looked at it (which was a few years ago). But if you are a concerned custo…

Versions are kept for a month. I once had a few hundred versions of one file a while back.

Re: The No More Ransom Project

#180

I've had plenty of people lose vital files on borked hard disks and pay thousands to get those files back via drive recovery firms. I've only had one person ask me about ransomed files whom I advised to pay the $400-ish demanded. I told him that most of my clients pay 10x as much to learn how important backups are. All data storage devices will fail . What will you do when yours does?

The worst place I have seen this is in scientific labs. Professors and graduate students are terrible about keeping backups, making data easy to understand to others, and maintaining data.

My old professor lost more than 2 years of work when one grad student in our had a car crash and his laptop was destroyed in the crash.

Post reply on HN