Live data from Hacker News

The Worsening State of Ransomware

cacm.acm.org

101–110 of 139 posts

Re: The Worsening State of Ransomware

#101

The article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments im…

Bitcoin is not anonymous. there are strict KYC rules in place.

Bitcoin is not for speculators, it's primary use case is a Store of value. There's large demand for a store of value, especially now that the bond market is finished.

Re: The Worsening State of Ransomware

#102
post #97
post #26

Earlier quoted context omitted.

Schools, kindergartens and parents have a legal responsibility for children under their protection. However it has been repeatedly proven that businesses who allow enormous amounts of user's personal and financial data to be leaked will suffer no meaningful consequences. See: Yahoo!, Target, Experian, etc.

"I don't like how these people aren't punished how I want, so let's sanction crime against them" is a ... questionable concept, to phrase it nicely. Lot's of nasty precedents. Are you sure kindergardens are punished reliably enough for lapses of security? Also: Ransomware gangs also target companies that do not have "enormous amounts of user's personal and financial data". Since too many companies didn't pay ransomwa…

No, but the alternative is that they would have stolen the data anyway. So it's either neutral or positive.

>let's sanction crime against them

If it were legal it wouldn't be a crime.

>Are you sure kindergardens are punished reliably enough for lapses of security?

Given that I rarely hear about children being kidnapped out of kindergartens, I would assume so. I'm not well educated on this, though, since I don't have a personal stake in the matter.

Re: The Worsening State of Ransomware

#103

> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…

> with permissions

Even more secure would be hardware write only storage. CD-ROMs fit in this category, but they aren't big enough.

But all we need are hard disk drives with a physical write-enable switch. Turn it on, write your backup, turn it off. No software can then alter it.

A stupidly simple idea, and yet every time I mention it in HN it gets dismissed, denigrated, etc. Apparently people like malware, ransomware, etc. :-(

Re: The Worsening State of Ransomware

#104
post #11

Earlier quoted context omitted.

I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information li…

There are USB drives that do vaguely similar things but it's all in software. It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't. For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though. You can do something conceptually similar with any sort of NAS that provides immutable snapsho…

> There are USB drives that do vaguely similar things but it's all in software.

Sigh. When are people going to accept that software switches are inherently not secure? How many times must these fail?

> It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't.

There's no reason to continue writing anything to a hard drive once the backup to it is finished.

Re: The Worsening State of Ransomware

#105
post #39

> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…

This is one reason I still do manual backups as well as automated backups. The manual backup is to HDDs that sit on a shelf, offline, unplugged.

Yeah, but to read the backup you've got to attach it to your compromised system. Boom, it's corrupted.

A physical read-only switch is required.

Re: The Worsening State of Ransomware

#106

How is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?

Embedded systems can have their software burned into ROMs. It can't be corrupted. But nooooo, people put it into EEPROMs with a software write-enable switch.

Re: The Worsening State of Ransomware

#107
post #81
post #66

Earlier quoted context omitted.

For this to work, the blacklist should apply to the receiving wallet AND CASCADE through to wallets to which that wallet issued any subsequent transfers. Coins used to pay ransomware should effectively taint and freeze everything they touch.

So you want to convert them to a free weapon to freeze random wallets? Guess you could use that dor demanding ransoms...

A government could have a “burner” account where all tainted money could be sent. A system where you are warned of tainted deposits (for example, use a micro-transaction from a “US taint detected” account as the message). You have x days to pay the received tainted money to the burner account, or your account gets tainted too.

Of course every jurisdiction would want to be in on the “free” bitcoins so lots of complications...

Re: The Worsening State of Ransomware

#108
post #9

> Not surprisingly, dozens of major ransomware gangs now exist worldwide, including in Russia, Eastern Europe, and North Korea. To what extent should ransomware activity be considered low-grade economic warfare by nation-states who can't or won't police cyber-criminals, and thus justification for robust national responses such as sanctions?

to the same extent that Hollywood movies function as cultural warfare / propaganda

Re: The Worsening State of Ransomware

#109

The article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments im…

Crypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.

And there are plenty of ways to circumvent that, including converting it to various privacy coins, using mixer services, using it to buy mining power, etc., etc., etc. Heck, crypto may have even more ways to launder money than cash, and those won't go away with blacklists - which will just make the "privacy" coins, services, etc. more valuable.

The only way it could even plausibly work is for every visible and darknet service in the world to subscribe to and abide by the exact same crypto-wallet blacklist. Good luck making that happen when nuclear superpower governments are in fact transnational crime syndicates.

Assuming that the tracing capabilities are useful for anything beyond taking down the amateurs is overly optimistic.

Re: The Worsening State of Ransomware

#110
>>Not surprisingly, dozens of major ransomware gangs now exist worldwide, including in Russia, Eastern Europe, and North Korea. Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets," says Alexander Chaveriat, chief innovation officer at Tuik Security Group. "They buy server space all over the world using cryptocurrency, change servers as needed, and use virtual private networks and other tools to hide their location."

It is getting to the point where the threat is beyond office functions and to manufacturing, infrastructure and IOT.

With the threat escalating to that genuine national security level, and often under sponsorship or blind eye of criminal govts (NK, RUS...), we are not far from the point where the appropriate response is to deliver a kinetic response - as in a cruise missile through the window.

Post reply on HN