Live data from Hacker News

The ransomware surge

bbc.com

31–40 of 216 posts

Re: The ransomware surge

#31

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

100% agree. It's a trick that criminal con-men have been using forever in the physical world. There's no reason to kick a door down (draw attention to yourself) when you can convince someone inside to open it.

"My puppy just got hit by a car! Can I come in and use your phone to call for help?"

Re: The ransomware surge

#33
post #10

Ransomware wouldn't be a problem if the software industry took quality assurance seriously (or was regulated to do so), like every other engineering industry. There's little difference to me between an insecure program that allows hackers to hold your data for ransom, and a defective home appliance that occasionally starts electric fires.

Well every home appliance could easily start a fire if random malicious actors got to fuck with it while it was plugged in. You'll note that other engineering disciplines would also fall apart if hostile actors were constantly throwing explosives at the things they make 24/7.

Yeah but software engineers know that hostile actors come with the territory any time they expose a networked device or service. It's no different than corrosion or any number of other inevitabilities that engineers have to deal with.

When's the last time a civil engineer designed a bridge without accounting for corrosion or the fact that people will be driving over it?

Re: The ransomware surge

#34

> "The hackers were the Ryuk ransomware gang and they demanded we pay them 45 Bitcoin, which was about half a million dollars. Make no mistake: this ransomware surge is 100% enabled / facilitated by Bitcoin and possibly other cryptocurrencies. This would not have been so bad if cryptocurrencies would actually provide anything of really significant value to our societies, but no. Aside from a mixture of Ponzi scheme,…

Crypto also risks the ability of central banks to print infinite amounts of money

Re: The ransomware surge

#35

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

Implicit in this comment is the assumption that current technology is pretty much the best we can do? > IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Why is it that even slightly old systems are so buggy that they are trivially hackable for a moderately well funded group? Modern security…

> Why is it that even slightly old systems are so buggy that they are trivially hackable for a moderately well funded group?

because software is tremendously complex with a large surface area to attack. And many OS features were designed when wide-scale hacking was not a problem.

Re: The ransomware surge

#36
post #3

This is going to be the rationale given for the heavy-handed cryptocurrency regulation they're going to bring down on all the exchanges that US persons can access. Pretty soon all you'll be able to legally access as a USian is "Bitcoin!(tm)"[1] (like what PayPal is doing), not the actual uncut blockchain bitcoin that you can send and receive at will. [1]: https://www.epsilontheory.com/in-praise-of-bitcoin/

Will increase the utility of decentralized exchanges like Uniswap and DeFi in general. The more CEX gets regulated the less people will want / need to use them.

Re: The ransomware surge

#37

> "The hackers were the Ryuk ransomware gang and they demanded we pay them 45 Bitcoin, which was about half a million dollars. Make no mistake: this ransomware surge is 100% enabled / facilitated by Bitcoin and possibly other cryptocurrencies. This would not have been so bad if cryptocurrencies would actually provide anything of really significant value to our societies, but no. Aside from a mixture of Ponzi scheme,…

Crypto is like an unregulated bank with no depositors' insurance. Those were forbidden (in most places) for a reason! What if a crypto software network goes all ... Geocities ... on owners? Or pick any other discontinued web or software service out of the wreckage of tech disruption. There isn't a M&A strategy to rescue these things....

Re: The ransomware surge

#38

Can someone tell me where I'm wrong here: The solution to ransomware is to daily mirror every system to an append only backup and then just flash everything back if you get hit. You lose a few days...

Your data has still been leaked. A few days ago there was a story about a ransomware gang threatening to expose police informants if they didn't get paid.

Seems a bit risky attacking other criminals - you never know if they might have contacts in the hard to extradite countries they work in.

Re: The ransomware surge

#39

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

Is it true that hack any random staff / computer of the company can lead to the ransomware attack of the machine holding the crucial data of the company?

Re: The ransomware surge

#40

Earlier quoted context omitted.

Well every home appliance could easily start a fire if random malicious actors got to fuck with it while it was plugged in. You'll note that other engineering disciplines would also fall apart if hostile actors were constantly throwing explosives at the things they make 24/7.

Yeah but software engineers know that hostile actors come with the territory any time they expose a networked device or service. It's no different than corrosion or any number of other inevitabilities that engineers have to deal with. When's the last time a civil engineer designed a bridge without accounting for corrosion or the fact that people will be driving over it?

How is wear and tear equivalent to hostile humans purposefully trying to fuck it up? Even military installations needs armed guards to stop people from just cutting through the fence. Wear and tear is more equivalent to keeping your site from going down to high traffic. Show me a road that's still safe when three guys with guns are standing in the middle of it shooting at passing drivers.
Post reply on HN