Live data from Hacker News

The Worsening State of Ransomware

cacm.acm.org

51–60 of 139 posts

Re: The Worsening State of Ransomware

#51

The article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments im…

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

It is quite difficult to have global, functioning blacklist system. I would guess for example some country in Asia might have quite different blacklist compared to let's say to some country in Europe.

From criminals perspective they probably have money launderers on darknet markets who are willing to take the dirty crypto, deduct their hefty fee and offer clean crypto instead.

Re: The Worsening State of Ransomware

#52

Earlier quoted context omitted.

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

If there's a centralized government blacklist of certain bitcoins that everyone has to follow, doesn't that defeat the point of cryptocurrency? Also a hacker could just buy something with the coins between the time the victim sends the money and the time the government is notified.

There are already blacklists and sanctioned bitcoin addresses. It might defeat your point of bitcoin, whatever that is, but not mine... There is no universally agreed "point of BTC".

Re: The Worsening State of Ransomware

#53

How is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?

The OS, files and configuration which can be unchangeable are trivially replaceable and thus does not really need to be protected.

The configuration and data which gets changed all the time is valuable (the effort that was made in making those changes) and the prime target of ransomware, and it can't be write-protected because, well, it needs to get changed. I mean, if "reimage all these computers to the default configuration" would be a viable solution, everybody would just do that instead of paying large ransoms.

Re: The Worsening State of Ransomware

#54

Earlier quoted context omitted.

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

If there's a centralized government blacklist of certain bitcoins that everyone has to follow, doesn't that defeat the point of cryptocurrency? Also a hacker could just buy something with the coins between the time the victim sends the money and the time the government is notified.

Depends on what you think the point of cryptocurrency is. I’ve heard a lot of different explanations over the years. I believe the most popular one currently is an inflation resistant store of value, which should be compatible with blacklists.

As for timing, either blocking spending or tracing the transaction back to a person is equally valuable as a deterrent.

Re: The Worsening State of Ransomware

#56

How is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?

Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.

If the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible.

No matter what the application does, it can't access the backups in such a system.

Re: The Worsening State of Ransomware

#57

Earlier quoted context omitted.

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

It is quite difficult to have global, functioning blacklist system. I would guess for example some country in Asia might have quite different blacklist compared to let's say to some country in Europe. From criminals perspective they probably have money launderers on darknet markets who are willing to take the dirty crypto, deduct their hefty fee and offer clean crypto instead.

A bitcoin that couldn’t be spent anywhere outside of e.g. China would be far less valuable than one that could be spent anywhere. At very least this would reduce the profitability of ransomware attacks.

Re: The Worsening State of Ransomware

#58
post #37
post #20

Earlier quoted context omitted.

It also ignores the perverse game being played. Defense has to work every time. Attackers just have to get through once. That's a game that favors the attackers.

Game 1: Every time offence scores, they get $100 of defense's money. Game 2: Every time offence scores, they get $100 of my money. Defense loses nothing. Neither is fair to defence, but game 2 is unfair to me , and that's what's important.

[deleted]

Re: The Worsening State of Ransomware

#59

How is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?

Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.

Especially since the user is the one being tricked into executing the ransomware.

Re: The Worsening State of Ransomware

#60
post #11

> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…

I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information li…

[deleted]
Post reply on HN