Live data from Hacker News

The No More Ransom Project

nomoreransom.org

191–200 of 241 posts

Re: The No More Ransom Project

#191
post #74

Earlier quoted context omitted.

The ransomware scheme only works because the users actually get their files back and the prices are pretty reasonable for many victims. The perpetrators spend a lot of time on the ransomware and its backend. The better it works works, the more people will pay. They rely on people like us to spread the word that it's not a scam, it's real and it works. Now that I think about it: It would really damage the whole ransom…

Exactly, but it will never be zero. There will always be scammers trying to get rich quick on the trust users have placed in the (more) honest scammers. All organized crime has to deal with some amount of posers trying to cash in on their reputation. Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Traditionally this would be breaking people's knees, and I…

> ... trust users have placed in the (more) honest scammers.

> Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme.

Are you really trying to frame some extortionists/scammers as honest and some as dishonest? How about they all are criminals, extorting money as they do from random people, they don't care about?

Re: The No More Ransom Project

#192

About prevention there is something more that I am not sure has been mentioned, some tools are taking a new, broader approach to the problem, which is to constantly monitor for encrypted files and stop the associated processes, this way often limiting the loss to a few files, these are the links: Criptostalker https://github.com/unixist/cryptostalker Ransomwhere (macOS) https://objective-see.com/products/ransomwhere.…

In principle it's super easy to detect, encrypted files look like random data and it's unlikely users would be replacing every file with random data on purpose. Its a never ending war though. If you got enough users to do this, the hackers would then switch to encryption that mimics what normal files look like to fool the detector.

Most users never start writing to all the files on their disk, why can't a rate limiter and warning kick in if that happens?

Re: The No More Ransom Project

#193

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

That's great until the ransomware gets clever and encrypts your backups too. I'm extremely skeptical of the people that say ransomware is good for the economy or whatever. Broken window fallacy. Sure it creates an incentive to protect against hackers. But isn't that a bit circular? Hackers are good because they create inventive to protect against hackers? Ransomware is by far the most economically damaging kind (and…

Use tools like Seafile and Owncloud that keep old versions and offsite. They offer both hosted service and self-installation option. The client notifies you that "files X,Y changed" which can make you notice anything untoward is happening to files you are not working with at the moment.

Re: The No More Ransom Project

#194

Earlier quoted context omitted.

You do realise guns have other uses other than shooting people don't you. There's nothing remotely shocking or abhorrent about guns.

Police officers in the UK don't even carry guns! They do just fine without them. Only specially "firearms units" carry them. While that's very unusual even in Europe, it goes to show that as long as not every idiot can buy a gun, things are just fine without such a deadly weapon. That said, shooting at a range is immense fun. ;)

Yes I'm aware. I live in the UK. Guns are used for sport, pest control, shooting laptops, etc.

Re: The No More Ransom Project

#195
post #103

I had no idear this was such a massive problem. How often are nefarious purps holding people's private data hostage? Seems overblown.

It's a very big problem, Cryptolocker in 2013 was able to score it's creators around $27 million. That was 3 years ago, it's a pretty dangerous and persistent threat.

Re: The No More Ransom Project

#196
post #147

If you are willing to pay the ransomware demands who are you going to pay when your HDD fails? I'm not saying ransomware isn't a problem in itself but from a user's perspective it's indistinguishable from HDD failure and should be dealt with by using backups.

Ransomware can infect your backups to though. HDD failures aren't contagious.

Ever heard about bitrot?

Re: The No More Ransom Project

#197
post #191

Earlier quoted context omitted.

Exactly, but it will never be zero. There will always be scammers trying to get rich quick on the trust users have placed in the (more) honest scammers. All organized crime has to deal with some amount of posers trying to cash in on their reputation. Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Traditionally this would be breaking people's knees, and I…

> ... trust users have placed in the (more) honest scammers. > Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Are you really trying to frame some extortionists/scammers as honest and some as dishonest? How about they all are criminals, extorting money as they do from random people, they don't care about?

Some scammers can be honest. You might say "Transfer X amount of money to me. If you don't, you can never get your data back". Saying and acting on that doesn't make you dishonest, it makes you an asshole.

Re: The No More Ransom Project

#198
post #191

Earlier quoted context omitted.

> ... trust users have placed in the (more) honest scammers. > Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Are you really trying to frame some extortionists/scammers as honest and some as dishonest? How about they all are criminals, extorting money as they do from random people, they don't care about?

Some scammers can be honest. You might say "Transfer X amount of money to me. If you don't, you can never get your data back". Saying and acting on that doesn't make you dishonest, it makes you an asshole.

That depends on your definition. Googling brings up "dishonest: not honest; disposed to lie, cheat, or steal; not worthy of trust or belief"

Thus I think a scammer can be called dishonest.

Re: The No More Ransom Project

#199
post #198

Earlier quoted context omitted.

Some scammers can be honest. You might say "Transfer X amount of money to me. If you don't, you can never get your data back". Saying and acting on that doesn't make you dishonest, it makes you an asshole.

That depends on your definition. Googling brings up "dishonest: not honest; disposed to lie, cheat, or steal; not worthy of trust or belief" Thus I think a scammer can be called dishonest.

An honest kidnapper would have mentioned the Lindbergh baby was already dead...
Post reply on HN