Earlier quoted context omitted.
This applies to average people too. I wonder who among us can say they meet your (reasonable) standard. Like you said, backups are annoying and unglamorous. Yet, the data on my laptop is the only thing I could not replace. It's more important to me than my passport or my birth certificate. Its preservation is certainly worth a bit of thought.
> Like you said, backups are annoying and unglamorous. It’s called having a network attached storage (NAS) device. I have a Synology NAS, which I backup to, continuously at 5 minute intervals. Warning: Microsoft image and file backups sometimes do not work. I recommend Acronis True Image instead, which comes with antivirus. It pretty much always works, never falter never fail. Get the version that allows you to back…
The ransomware surge
111–120 of 216 posts
Re: The ransomware surge
#112Earlier quoted context omitted.
It sounds like a problem the IT department should solve. No?
It is, but solving that problem would entail re-training staff, reduce "productivity", and moreover, cost money... Many companies have cut their IT provision below what is needed to simply stand still. IT is a cost to their business, not a revenue source. They don't consider the counter-factual of "well, what if we didn't use IT and computers and the internet" when valuing what IT is bringing to their business. If th…
Re: The ransomware surge
#113I don't get why everybody cares so much about the ransomware/cryptominer part, but not the data being exfiltrated and sold/used for criminal activity part..
If you offered my company our competitors source code for free, we wouldn't take it - we have some ethics. I think most of you are in the same boat - even if you don't have strong company ethics are quick check would discover that you already know how to do everything they are doing, so time looking at their code is time you aren't adding those features to yours. (the one exception would be their file format which are valuable)
Even if the data is valuable, can they use it? I know the database admins in my company are registered with the SEC as not able to trade some things because we have insider information from our customers. Even if someone got that data though, they would have to figure out the database, what it means, AND be lucky enough to do that when there is something non-public that can be traded. Most of the time the expected supply is the same as actual supply, so that fact that we have insider information on the actual supply isn't actually useful. (the above is a different department from mine so I don't know the details very well)
Thus the example of a police department is an outlier as the data is sensitive for a long time.
Re: The ransomware surge
#114Can someone tell me where I'm wrong here: The solution to ransomware is to daily mirror every system to an append only backup and then just flash everything back if you get hit. You lose a few days...
Your data has still been leaked. A few days ago there was a story about a ransomware gang threatening to expose police informants if they didn't get paid.
Re: The ransomware surge
#115Earlier quoted context omitted.
> Like you said, backups are annoying and unglamorous. It’s called having a network attached storage (NAS) device. I have a Synology NAS, which I backup to, continuously at 5 minute intervals. Warning: Microsoft image and file backups sometimes do not work. I recommend Acronis True Image instead, which comes with antivirus. It pretty much always works, never falter never fail. Get the version that allows you to back…
Can ransomware leak on to your always-connected NAS?
But, this is a basic overview of how to prevent NAS ransomware attacks: https://www.howtogeek.com/435452/how-to-secure-your-synology...
There is better advice elsewhere but this is a good start.
This may be a good comment to look at: https://news.ycombinator.com/item?id=25618346
This may be another good comment to take a look at: https://news.ycombinator.com/item?id=24860863
Re: The ransomware surge
#116Exchanges are good at blacklisting BTC ,so this means it will be hard for hackers to cash out. Just converting BTC into XMR is not a trivial process, as it needs to go through an exchange. Trustless cross chain transactions are still in infancy .
Re: The ransomware surge
#117Earlier quoted context omitted.
Yeah but software engineers know that hostile actors come with the territory any time they expose a networked device or service. It's no different than corrosion or any number of other inevitabilities that engineers have to deal with. When's the last time a civil engineer designed a bridge without accounting for corrosion or the fact that people will be driving over it?
How is wear and tear equivalent to hostile humans purposefully trying to fuck it up? Even military installations needs armed guards to stop people from just cutting through the fence. Wear and tear is more equivalent to keeping your site from going down to high traffic. Show me a road that's still safe when three guys with guns are standing in the middle of it shooting at passing drivers.
But since it isn't a regular thing I don't bother with that. My car wouldn't survive long in a real battle and I'm okay with that as I don't expect to have to drive my car in a real battle.
The warning is out to everything network connected: it is time to invest in the equivalent of armor and bullet proof glass.
Re: The ransomware surge
#118Backups. I cannot emphasize enough the importance of backups. Take backups, verify your ability to restore from them, and keep them segregated from the rest of your infrastructure. It doesn't matter how inelegant and hacky your backup solution is, so long as you can restore from it. Any backup you can restore from is better than no backup. You might get a call from one of your application engineers shortly before bed…
They want restores.
Re: The ransomware surge
#119Interestingly they target mostly Windows users. If you are Linux or BSD user you are less likely to be targeted.
Re: The ransomware surge
#120This is going to be the rationale given for the heavy-handed cryptocurrency regulation they're going to bring down on all the exchanges that US persons can access. Pretty soon all you'll be able to legally access as a USian is "Bitcoin!(tm)"[1] (like what PayPal is doing), not the actual uncut blockchain bitcoin that you can send and receive at will. [1]: https://www.epsilontheory.com/in-praise-of-bitcoin/
Already happening with 'unhosted' wallets being blocked or heavily scrutinized. My personal experience is as follows: Sent over 20 transactions from US exchange -> US exchange and no problems. Sent a single transaction from my unhosted software wallet -> US exchange, and got my account locked. Questioned on everything including my employer's information, had do re-do advanced KYC, source of funds etc. (The unhosted w…