Live data from Hacker News

The Worsening State of Ransomware

cacm.acm.org

121–130 of 139 posts

Re: The Worsening State of Ransomware

#121
post #109

Earlier quoted context omitted.

And there are plenty of ways to circumvent that, including converting it to various privacy coins, using mixer services, using it to buy mining power, etc., etc., etc. Heck, crypto may have even more ways to launder money than cash, and those won't go away with blacklists - which will just make the "privacy" coins, services, etc. more valuable. The only way it could even plausibly work is for every visible and darkne…

Nothing is ever perfect. It doesn’t mean you shouldn’t at least try to track down criminals. Which has essentially been the West’s response to ransomware so far.

No question, nothing is ever perfect, and best efforts should be made to utilize the available tracking. Especially so, when the threat is rising to the level of national security concerns as attacks start moving to infrastructure, and are sponsored or unofficially sanctioned by criminal nation-sates, where the response should be kinetic.

The problem is that to kill ransomware, we would need a near-perfect system, and that is extremely unlikely, or thee will be substantial leakage, and continued profit for ransomers. I'd say it'd be easier to entirely shut down crypto globally than to ransomware-proof existing crypto.

Probably means that the real solution will be to do both. Sanction only fully traceable cryptocurrencies and shut down the rest.

Re: The Worsening State of Ransomware

#122

Earlier quoted context omitted.

Are there any NAS devices with out-of-band management actually available, though?

Spin up a FreeBSD box, enable ZFS snapshots and disable SSH? You’d only be able to destroy the snapshots from a monitor and keyboard under normal circumstances.

Well, yeah. I was more asking "does somebody make such a thing purpose-built?"

Re: The Worsening State of Ransomware

#123

Earlier quoted context omitted.

Yeah, but to read the backup you've got to attach it to your compromised system. Boom, it's corrupted. A physical read-only switch is required.

There are USB to SATA controllers that default to read only - typically used for forensics reasons. About $250 if I remember correctly.

A physical switch costs what, a nickel?

Just think of all the security issues that would just go away with physical write-enable switches.

Heck, I'd go further, and demand from disk makers a physical write enable switch for a separate volume. Use that volume for the system software.

Re: The Worsening State of Ransomware

#124

Earlier quoted context omitted.

> with permissions Even more secure would be hardware write only storage. CD-ROMs fit in this category, but they aren't big enough. But all we need are hard disk drives with a physical write-enable switch. Turn it on, write your backup, turn it off. No software can then alter it. A stupidly simple idea, and yet every time I mention it in HN it gets dismissed, denigrated, etc. Apparently people like malware, ransomwar…

Perhaps, but I once had two hard drives die on me within the space of a few days (different brands), and since then I like to have a copy of my data in the cloud somewhere. Non-writeable doesn't help much if you can't read it either!

I've had many hard drives fail on me over the decades, and keep multiple backups. Keep in mind your cloud storage service can go dark any time for any reason.

Re: The Worsening State of Ransomware

#125
post #25

Earlier quoted context omitted.

Once you work in a large corp and see parallels with government, you start to realize it's just organizational theory all the way down, except some use physical violence, others don't.

Wait, are we talking here about the state or organized crime?

And normal corporate / state non-crime!

Re: The Worsening State of Ransomware

#126
post #121

Earlier quoted context omitted.

Nothing is ever perfect. It doesn’t mean you shouldn’t at least try to track down criminals. Which has essentially been the West’s response to ransomware so far.

No question, nothing is ever perfect, and best efforts should be made to utilize the available tracking. Especially so, when the threat is rising to the level of national security concerns as attacks start moving to infrastructure, and are sponsored or unofficially sanctioned by criminal nation-sates, where the response should be kinetic. The problem is that to kill ransomware, we would need a near-perfect system, an…

I don't see this going in the direction of a heavily enforced response, although some places may talk big. While a collective ban is rationally sensible, nations are made of individuals and every person will do a calculation of personal benefit relative to national interest. Crypto is valuable as a refuge, so a recurring story is currently playing out in destabilized nations all over the world where crypto is used to escape the inflated local currency: the government gets wishy-washy about what it's going to do with the stuff, with different officials taking wildly different stances according to their own self-interest. They talk of a ban, and then of national cryptocurrency, and then of nationalized mining. Everyone is looking for safe harbor but pulls in a different direction.

Focusing on controlling onramps and offramps to cryptocurrency, like controlling goods import/export, is a relatively straightforward compromise to this internal dilemma and allows the government to be a player in the space without much direct oversight, even if some folks are slipping through the cracks. A sloppy, haphazard enforcement is likely to prevail.

And there's another way to reassert state control within that framework. If the bad cryptocriminals come for your stuff, the government can bail you out - if you play by their rules. The loss compensation mechanism is a simple plan to mitigate dangers, since it's easy for governments to create and redistribute credit internally and doing so can build consent.

Submitting to this framework does mean that the government is truly in competition with decentralisation to provide a better, more trustworthy service to handle central credit, and has to massively step up security efforts in the process. Everyone started "asleep at the wheel" on this, with individual tech firms all building out their own insecure house-of-cards fiefdoms and relying on the intellectual property law framework to keep them up. But everyone knows it's flawed - of course you can copy, what's important is if you can get credit, and that part is also changing with the crypto sector - assignment of credit is the whole thing of NFTs in a nutshell. The nation that can grasp this the quickest and turn it into a coherent part of their economic framework will cruise ahead.

Re: The Worsening State of Ransomware

#127

Earlier quoted context omitted.

Depends on what you think the point of cryptocurrency is. I’ve heard a lot of different explanations over the years. I believe the most popular one currently is an inflation resistant store of value, which should be compatible with blacklists. As for timing, either blocking spending or tracing the transaction back to a person is equally valuable as a deterrent.

Here’s how blacklists destroy your “store of value” argument: Transactions don’t require the receiver’s consent. It’s easy to find large wallets (wallet balance is public record), and then once you’ve carried out your ransomeware attack and gotten paid, your black wallet sends to whatever poor schmuck you want to destroy. Because sends blacken anything they touch, you’ve just turned a lot of money into nothing, at th…

Destroy? All the wallet needs to do is send it back. Or not use it. Simple and probable.

Re: The Worsening State of Ransomware

#128

Earlier quoted context omitted.

For now. If it becomes a common mitigation strategy, malware will start detecting and corrupting those backups.

Write only setting perhaps

No, because you’re reading the local file system using the local processor, which could corrupt reads or writes. Even DMA reads won’t solve it - malware could encrypt/decrypt transparently for a period undetected, then toss away the decryption key once it’s likely that backups are no longer viably usable..

Re: The Worsening State of Ransomware

#129
post #16

> Some, including the U.S. Treasury, have promoted the idea of making it illegal to pay a ransom, though the idea has not gained widespread support. That's probably the only solution, besides the obvious ones like actually protecting the systems.

I'm not sure how such a rule could be enforced. But let's assume that it could. I think this would cause a huge shift in IT. For example, companies would be more eager to switch from Windows to something more secure. Or if they continued to use Windows, it would be in the form of ephemeral VMs, perhaps on AWS, that lack an attach surface area. But I would hope that financial pressure - like insurance companies not in…

> For example, companies would be more eager to switch from Windows to something more secure

Windows is not inherently insecure. Executing a malicious program would work just as well under Linux. (Presumed) technical superiority does not help when it's basically social engineering all the way. Ephemeral VMs don't help too much, either. So I highly doubt this would reduce windows market share in any significant way.

Re: The Worsening State of Ransomware

#130
post #87

My prediction: Ransomware will be the scapegoat that leads the way on making the use of encryption a criminal offence. This is exactly what many governments want. Up till now, the best argument against encryption is "we can't see what criminals are doing", but that isn't very tangible for many people. Just wait until a powergrid or water treatment plant in the US is down for weeks due to being "attacked with encrypti…

This is one of the reasons crypto sucks. I'm building a list: - Attacks sovereign currencies and ability of countries to set fiscal and monetary policy. Instead, it rewards "crypto geniuses" that got in early. I'm not sure these are the people that should have power over our elected governments. - A waste of human and resource capital that could be spent solving more important problems - Hugely bad for the environmen…

The person you respond to is talking about encryption, not crypto currencies.
Post reply on HN