Live data from Hacker News

The Worsening State of Ransomware

cacm.acm.org

61–70 of 139 posts

Re: The Worsening State of Ransomware

#61
post #11

Earlier quoted context omitted.

I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information li…

There are USB drives that do vaguely similar things but it's all in software. It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't. For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though. You can do something conceptually similar with any sort of NAS that provides immutable snapsho…

Are there any NAS devices with out-of-band management actually available, though?

Re: The Worsening State of Ransomware

#63
post #27
post #12

Earlier quoted context omitted.

A number of major drug cartels would be at least on the Fortune 1000 if they were publicly traded corporations. They have management structures, accountants, IT and security professionals, logistics, HR practices, and so on...

I'm wondering if they also have Scrum Masters and other consultants.

> I'm wondering if they also have Scrum Masters

If you want a really wacky use of scrum, try The Rhesus Chart [0] by Charles Stross, in which (mild spoiler) ...

a bunch of newly transformed vampires use scrum to quickly figure out how to acquire lots of fresh human blood without alerting the authorities by a trail of suspicious murders.

[0] https://en.wikipedia.org/wiki/The_Laundry_Files#The_Rhesus_C...

Re: The Worsening State of Ransomware

#64
post #25

Earlier quoted context omitted.

Once you work in a large corp and see parallels with government, you start to realize it's just organizational theory all the way down, except some use physical violence, others don't.

Wait, are we talking here about the state or organized crime?

Both?

Re: The Worsening State of Ransomware

#65
post #11

> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…

I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information li…

GDPR may require active online systems to delete data in response to a stream of realtime requests, so while the availability solution is to make deletion a hard, manual process or a process controlled only by an isolated infrastructure team, as you automate GDPR deletion requests you will need to start exposing deletion APIs accessible to end users. This is why a lot of the comments about making read-only backups or offline backups are very challenging for firms to do if they are taking GDPR seriously.

Re: The Worsening State of Ransomware

#66

The article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments im…

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

For this to work, the blacklist should apply to the receiving wallet AND CASCADE through to wallets to which that wallet issued any subsequent transfers.

Coins used to pay ransomware should effectively taint and freeze everything they touch.

Re: The Worsening State of Ransomware

#67

The article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments im…

Ransomware isn’t lucrative enough to be the primary transactional or consumptive use case of crypto.

Comical world view, to me.

Of course, the nature of cryptocurrency makes both of our claims unfalsifiable. I would suggest hanging out in crypto-adept communities more, being privy to a 300-participant transaction or other things communities get excited about, to give you a different view of how people use it.

Re: The Worsening State of Ransomware

#68
post #25

Earlier quoted context omitted.

Once you work in a large corp and see parallels with government, you start to realize it's just organizational theory all the way down, except some use physical violence, others don't.

Wait, are we talking here about the state or organized crime?

Yes.

Re: The Worsening State of Ransomware

#69
post #14

Ransomware provides a useful service and should be legal. Businesses with poor security practices deserve to be punished for their negligence.

I get that you're trying to say that Ransomware is a kind of evolutionary pressure to force IT ecosystems to adapt and improve, but that's far from saying it should be legal.

It's like trying to justify armed robbery as a method of convincing people to take self defense lessons, or burglary as a method to get people to upgrade their windows to lexan.

The middle ground, which is always a bit in flux, does already exist. It's known as Bug/Security bounties, similar to what HackerOne tries to make above-board.

Re: The Worsening State of Ransomware

#70
post #48
post #3

> These "customers," who have zero coding skills or software expertise, take advantage of a ransomware-as-a-service (RaaS) model to gain sophisticated capabilities > Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets" What a crazy world…

what is las Vegas

The Meadows.
Post reply on HN