> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…
The Worsening State of Ransomware
71–80 of 139 posts
Re: The Worsening State of Ransomware
#72Re: The Worsening State of Ransomware
#73How is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?
The OS, files and configuration which can be unchangeable are trivially replaceable and thus does not really need to be protected. The configuration and data which gets changed all the time is valuable (the effort that was made in making those changes) and the prime target of ransomware, and it can't be write-protected because, well, it needs to get changed. I mean, if "reimage all these computers to the default conf…
Precisely the wrong way to think about this.
If the OS can't protect itself, you've got a system with zero security.
Re: The Worsening State of Ransomware
#74Earlier quoted context omitted.
Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.
Especially since the user is the one being tricked into executing the ransomware.
Re: The Worsening State of Ransomware
#75> These "customers," who have zero coding skills or software expertise, take advantage of a ransomware-as-a-service (RaaS) model to gain sophisticated capabilities > Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets" What a crazy world…
A number of major drug cartels would be at least on the Fortune 1000 if they were publicly traded corporations. They have management structures, accountants, IT and security professionals, logistics, HR practices, and so on...
Re: The Worsening State of Ransomware
#76Funny that nightly tape backups, a very old and established technology, would pretty much fix the problem.
Re: The Worsening State of Ransomware
#77Earlier quoted context omitted.
Users need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.
If the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible. No matter what the application does, it can't access the backups in such a system.
And if the gang get's admin rights on the box your backups are gone.
Re: The Worsening State of Ransomware
#78Re: The Worsening State of Ransomware
#79Earlier quoted context omitted.
If there's a centralized government blacklist of certain bitcoins that everyone has to follow, doesn't that defeat the point of cryptocurrency? Also a hacker could just buy something with the coins between the time the victim sends the money and the time the government is notified.
Depends on what you think the point of cryptocurrency is. I’ve heard a lot of different explanations over the years. I believe the most popular one currently is an inflation resistant store of value, which should be compatible with blacklists. As for timing, either blocking spending or tracing the transaction back to a person is equally valuable as a deterrent.