Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

301–310 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#301

Earlier quoted context omitted.

Because now we can watch those funds and know how much money they made, we can watch them to see if they make a mistake. If every address was different we'd have no idea how much money they're making and only funds paid by people who also reported them would be tainted by the long eyeball of the law.

Probably not viable right now because of the ridiculously high transaction fees.

Transaction fees only need to be high if you are in a hurry. If you can wait a week or two you can go with very small TX fees. As you can see in this graph even very low (5 to 10 Satoshi per byte) fee transaction are confirmed eventually. https://jochen-hoenicke.de/queue/#24h

Re: Another Ransomware Outbreak Is Going Global

#302

Earlier quoted context omitted.

Interesting. If I was Posteo I don't think I would've been so quick to ban the email, this will potentially cause a lot of harm. What about all the people that need their data back? They have no way to get it now. Plus many people are still going to post the money only to get no response from the email.

This is indeed a heavily debated topic. It will cause a major headache for those who pay and will hopefully make people learn to distrust ransomware, in turn making it less lucrative. On the other hand, that requires a fair number of "acceptable casualties" so to speak. I personally think both sides of this are valid and don't know what the best option really is. It will be interesting to watch how things evolve at l…

>will hopefully make people learn to distrust ransomware, in turn making it less lucrative.

Ransomware will never ever not be lucrative. Preventing people from getting their data back doesn't discourage future campaigns and primarily hurts the victims of the ransomware.

Re: Another Ransomware Outbreak Is Going Global

#304

Earlier quoted context omitted.

In Ukraine, banking services nationwide as well as credit card payments on the metro in Kiev, and the airport IT systems, are all down. At what point do we call it massive? When US banks and airports start having trouble?

That's interesting. I've heard a lot about Russia testing out cyberwarfare in Ukraine as a possible proving ground for future targets. Was Ukraine the hardest hit by this latest one? It'd be interesting if this were actually made to take down infrastructure under the guise of ransomware.

Apparently initially the thing spread through the update of a popular Ukrainian accounting software [1], infecting a lot of networks of Ukrainian companies.

[1] me-doc.com.ua

Re: Another Ransomware Outbreak Is Going Global

#305

Earlier quoted context omitted.

Great. Maybe we can finally put a price on lack of security protocol.

I dream of seeing a "security first" development process adopted ..

I predict that this is might be a start of a something akin to few catastrophic bridge collapses that really showed the importance of credentials in engineering. Maybe the era of software "engineers" will come to an end eventually

Re: Another Ransomware Outbreak Is Going Global

#307

Earlier quoted context omitted.

I dream of seeing a "security first" development process adopted ..

I predict that this is might be a start of a something akin to few catastrophic bridge collapses that really showed the importance of credentials in engineering. Maybe the era of software "engineers" will come to an end eventually

What does it have to do with credentials?

Re: Another Ransomware Outbreak Is Going Global

#308

Earlier quoted context omitted.

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

Is it not cryptographically possible to create a transparent provably-operational decryptor on top of something like ethereum?

It's a marketing issue. People likely to get hit with ransomware are incredibly unlikely to understand what that means. Hell, even main devs have trouble writing contracts, so even if a user knew there was a smart contract, verifying it would be another thing. So it'd get reduced to "guys on Twitter said this one works".

I like the idea though.

Re: Another Ransomware Outbreak Is Going Global

#310

Earlier quoted context omitted.

Great. Maybe we can finally put a price on lack of security protocol.

I dream of seeing a "security first" development process adopted ..

What I really want to see is security being integrated into the development process as a conscious tradeoff teams have to make.

When a new feature is proposed, it's rare to hear someone object on the grounds that it could potentially add new vulnerabilities, but in the long run an approach that recognizes and considers those risks would be beneficial.

At the same time, this is incredibly hard to do - managers celebrate employees who develop things that look cool and awesome, not employees who can mitigate risk and manage security effectively (hopefully this changes, but I can't imagine that many unaffected CEOs are calling up their sysadmins right now and congratulating them on their diligence in making sure all their machines are patched).

Post reply on HN