Live data from Hacker News

The No More Ransom Project

nomoreransom.org

181–190 of 241 posts

Re: The No More Ransom Project

#181
post #170

Earlier quoted context omitted.

> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or if your backup solution is—from the perspective of the computer being backed up—an append-only store. Like a box of tapes, or Tarsnap using restricted keys, or Arq pointed at a versioned S3 bucket, or a NAS exposing an iSCSI target backed by an LVM thin pool LV with automatic daily snapshots. Sadly, as far as I…

I've contemplated setting up a small home server with write-only shares for backups, but ended up not doing it because of the cost and time. If there were a reasonably priced off-the-shelf product for this, I'd recommend it to everyone I know. On the other hand, if there were an off-the-shelf product for this, it would probably have unpatched security issues two weeks after you bought it, and if it were in common use…

> if there were an off-the-shelf product for this, it would probably have unpatched security issues two weeks after you bought it

I'm waiting for the NAS "appliance" that's actually running CoreOS, and then just relies on running the :latest tag of some popular Docker image (and not a fork of it that they'll forget to update eventually; the original upstream image), plus a bit of config-file glue generated into a shared volume from a web-UI service running in another container. (Bonus points if the second container is only started up, for an hour at a time, when you press a button on the NAS, WPS-style.)

Such a design is essentially the same as shipping the device's OS as "firmware" with auto-updates, but for the fact that the vendor themselves isn't anywhere within the path of creating or distributing those updates. Which, in the end, makes all the difference.

Re: The No More Ransom Project

#182
post #133
post #111

Earlier quoted context omitted.

What you say is true, however I am afraid permissions are not the solution either. Look at android ecosystem - they have tons of permissions, but who actually looks at them? People just click "accept" 99.9% of the time. Same will be on desktop OSes. Granted, more granular permissions make Android somewhat safer - but it also makes many things harder to do. If you did this on desktop, users would scream and demand to…

Seems like there should be a sort of av layer looking for suspicious activity between the software and privileged calls.

The problem is it's very hard to distinguish legit from non-legit without asking the user. Users do a lot of stuff and malware can mimick any of it. And if you do ask the user, the malware can make the user answer yes - usually by means as simple as "The OS will be displaying a confirmation dialog, please click YES for this program to work". Yes, it won't work with 100% of people, but it's a game of numbers - it will work for significant number of them.

Re: The No More Ransom Project

#183
post #170

Earlier quoted context omitted.

When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it. That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if y…

> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or if your backup solution is—from the perspective of the computer being backed up—an append-only store. Like a box of tapes, or Tarsnap using restricted keys, or Arq pointed at a versioned S3 bucket, or a NAS exposing an iSCSI target backed by an LVM thin pool LV with automatic daily snapshots. Sadly, as far as I…

I've seen this in practice - the two person business with a file server, and a NAS they backed up onto. For the size of the business, they were doing everything right.

Every time I say this, someone chimes in and says that in their office, they air gap tape drives and do all sorts of things with storage snapshots. If you're an enterprise - great. A large proportion of "two laptops" businesses have no backups at all, or a "I selectively place important things in Dropbox" setup. This team went and bought a NAS and setup backups. Good on them. It was sad to see cryptolocker take down both desktops, and all backups on the NAS.

The email he received sent him to a website with a convincing looking download, which came up 0/55 on virustotal. He even told me he wouldn't have run an executable - but it was a Word document. It can be truly depressing to see who cryptolocker affects sometimes.

Re: The No More Ransom Project

#184

Earlier quoted context omitted.

To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...

It's more like a part of a post-sales than customer support (a cost centre).

Although in this case they may be trying to reduce the volume of people who get the police involved. If they are pleasant to deal with throughout that seems likely to diminish people's enthusiasm for demanding legal consequences for the perpetrators.

Re: The No More Ransom Project

#185

Is there any case where versioned backups wouldn't completely solve a ransomware situation? Assuming, of course, that the ransomware doesn't somehow spider out and compromise all your past backups as well. Let's assume your past backup versions are safe.

Are the versioned backups physically separated from the infected machine? Otherwise what stops it from just encrypting your backups hard drives as well, everytime you connect them?

Yes – good backups would be somewhat resistant to malicious tampering, so that old versions are not immediately lost no matter what happens on the source computer.

Re: The No More Ransom Project

#186
post #48

For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

That actually happened to me. Friends of mine run a business I did some low level setting up of IT and design work for. Recommended they use Dropbox for important data in a folder I shared with them. One day, I keep getting notifications from Dropbox. Temporarily disable it on my machine because it annoyed the heck out of me. A few hour later, I get the "I think we have a virus" call.

Turns out that me being annoyed means I now have a fully intact version of the data and nobody had to pay anything.

Re: The No More Ransom Project

#187

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

That's great until the ransomware gets clever and encrypts your backups too. I'm extremely skeptical of the people that say ransomware is good for the economy or whatever. Broken window fallacy. Sure it creates an incentive to protect against hackers. But isn't that a bit circular? Hackers are good because they create inventive to protect against hackers? Ransomware is by far the most economically damaging kind (and…

I saved my dad from ransomware using the Crashplan backups I set up. Ransomware can't retroactively encrypt remote (incremental) backups (unless they hack the service). Admittedly, I now realize they could have deleted them, so I need to enable the password protection in the app, so nothing can be changed without the password. However, I don't think it's worth it for the builders to invest in that: the number of people that could rescue themselves in such a way is probably negligible.

Re: The No More Ransom Project

#188
post #62

Earlier quoted context omitted.

Good comment. I've interacted with ransomware scammers on several occasions. Each time I couldn't help but be impressed by their operations. In one case, the scammers provided an email address for customer support once the victim paid the ransom. They were courteous, helpful and professional - more so than many customer response teams I've had to interact with in legitimate companies. To be clear, I also don't recomm…

Y'all make this all sound so appealing.

Stockholm Syndrome exists for good reason.

Re: The No More Ransom Project

#189
post #91

Earlier quoted context omitted.

"If it gets out that you paid and you didn't get unlocked then no one would pay." Sounds like an easy way to get rid of ransomware. Just spread rumors that you didn't get your files back even though you paid. Somehow I have a feeling that wouldn't work, though. Many people would still pay.

Another way then: create a script that sends hundreds of emails to the victim from different addresses (wallets) and different amounts; the victim cannot identify which email is from the actual scammer, therefore he will pay none and the scam chances of success would reduce, and with it -eventually- the number of scammers.

Do they really communicate by email after encrypting? Wouldn't it make more sense to communicate via a file on the owned desktop?

Re: The No More Ransom Project

#190
post #15

Earlier quoted context omitted.

It's been pointed out in the past that most ransomware services have better customer support than paid services. That's because they stand to gain $XXX from each successful interaction and they stand to lose substantially more if they have a reputation of not returning the data.

The market works!

The invisible hand.
Post reply on HN