Live data from Hacker News

The ransomware surge

bbc.com

171–180 of 216 posts

Re: The ransomware surge

#171
post #161
post #8

Earlier quoted context omitted.

Absolutely this - most ransomware attacks are pretty unsophisticated. You don't need privilege escalation, or an exploit. You can carry out the attack using just basic user permissions. You are exploiting a basic "problem" of most modern OSs (that apps run "as" the user executing them) - the user/group permission model ceases to work in 2021 with non-expert users. Portal-based access to individual files via secure OS…

> most ransomware attacks are pretty unsophisticated As weird as it sounds, this is both correct and incorrect at the same time. It is correct, because ransomware is not particularly sophisticated by today's standards. Couple of decades of R&D has made the building blocks robust and uninteresting. It is also correct in the sense that the attacks used to breach systems are unsophisticated. A vulnerability is published…

A really good point - we should distinguish the sophistication of the attack and the attacker. These are clearly highly organised and sophisticated attackers, many working in shifts etc.

If it gets in through an access broker, you're definitely looking at a sophisticated outfit of attackers.

I guess I'm approaching this as the defender - if the malicious code isn't exploiting anything needing patched (other than decades-outdated assumptions of a threat model where any binary has the ability to act inseparably "as" the user), the actual ransomware is harder to prevent for most organisations, as all the friendly hand-holding type advice they receive from police and governments doesn't save them (patching desktop systems won't prevent the file encryptor payload from running on the first host, after a user runs the bogus docx.exe file and ignores warnings through alert fatigue).

It would be interesting if companies were more willing to (or required to) share details of ingress vectors, to understand the extent to which they're being breached through really advanced attacks involving reversing of recent patches, versus someone popping a pulsesecure VPN that's been warned about for years. Or on-prem Exchange that they've continued to ignore all the warnings about as nothing is on fire. Or just a user clicking a link to a shared file mistakenly emailed to them, called CONFIDENTIAL - PAY SCALE 2022, which phishes their SSO credentials for 365...

Re: The ransomware surge

#172
post #72

“ increase regulation of cryptocurrency services” Hmmm.

Cryptocurrencies are the one sole reason that there is a ransomware epidemic today. Without them, ransomware would be nowhere near as profitable or easy. Kill cryptocurrencies, kill ransomware. Plus, kill a massive source of carbon emissions. It's a massive win on multiple fronts.

I don't think you can just "kill cryptocurrencies." China tried that and most of the mining happens there now.

Plus not all cryptocurrencies waste power the way bitcoin does. And before crypto was big there was malware that asked for money via mailed checks and bank transfers (and there are plenty of scams that just call people and ask for money with no software at all.)

In addition banks make an incredible profit laundering money for drug/human trafficking. I'm sure they could be convinced to put that to use doing other things if crypto wasn't there.

Re: The ransomware surge

#173

Earlier quoted context omitted.

Well every home appliance could easily start a fire if random malicious actors got to fuck with it while it was plugged in. You'll note that other engineering disciplines would also fall apart if hostile actors were constantly throwing explosives at the things they make 24/7.

Things that are exposed to an adversarial environment are usually engineered with that in mind. Locks are (usually) designed to be hard to pick, for instance.

I think locks are about as weak as software security, relatively speaking. The difference is that if an organized gang of criminals physically broke down the doors to a corporation and stole truckloads of computers, the law enforcement response would be significant. (And we mostly wouldn't be sitting around blaming the corporation for not hiring armed guards.)

Re: The ransomware surge

#174
post #36
post #3

This is going to be the rationale given for the heavy-handed cryptocurrency regulation they're going to bring down on all the exchanges that US persons can access. Pretty soon all you'll be able to legally access as a USian is "Bitcoin!(tm)"[1] (like what PayPal is doing), not the actual uncut blockchain bitcoin that you can send and receive at will. [1]: https://www.epsilontheory.com/in-praise-of-bitcoin/

Will increase the utility of decentralized exchanges like Uniswap and DeFi in general. The more CEX gets regulated the less people will want / need to use them.

Yup, and its only a matter of time before a uncollateralized + decentralized stable coin takes over from USDT/USDC…

Re: The ransomware surge

#175
post #122

Earlier quoted context omitted.

I sometimes do infrastructure consulting. One of the first questions I ask is if they have at least one fully independent, full/incremental off-site backup that can't be corrupted from the main infrastructure, and if they have ever checked if they actually work and are restorable. I'm continuously surprised how often the answer turns out to be no after dinner digging, even in larger companies with otherwise well-run…

> Backups are annoying and unglamorous Three years ago, after doing YC Startup School, I built https://www.borgbase.com to offer the simple, but secure backup service I wanted myself. Today it’s a viable business and my customers are all great and value backups as essential part of their own business. Wouldn’t want to be in any other “more glamorous” corner of the industry. Also kudos to anyone - partner or competito…

How did you figure out your pricing strategy?

Re: The ransomware surge

#176
Ransomware got way more viable thanks to crypto. No more need for money mules and shady shell companies, just take moneys in crypto and you’re golden

Re: The ransomware surge

#177
post #172

Earlier quoted context omitted.

Cryptocurrencies are the one sole reason that there is a ransomware epidemic today. Without them, ransomware would be nowhere near as profitable or easy. Kill cryptocurrencies, kill ransomware. Plus, kill a massive source of carbon emissions. It's a massive win on multiple fronts.

I don't think you can just "kill cryptocurrencies." China tried that and most of the mining happens there now. Plus not all cryptocurrencies waste power the way bitcoin does. And before crypto was big there was malware that asked for money via mailed checks and bank transfers (and there are plenty of scams that just call people and ask for money with no software at all.) In addition banks make an incredible profit la…

Of course we can. There just hasn't been much political will to do so yet, because they have been an irrelevant distraction.

That is no longer the case now that they are actively making climate change worse, and disrupting business through ransomware.

Re: The ransomware surge

#178
post #175
post #122

Earlier quoted context omitted.

> Backups are annoying and unglamorous Three years ago, after doing YC Startup School, I built https://www.borgbase.com to offer the simple, but secure backup service I wanted myself. Today it’s a viable business and my customers are all great and value backups as essential part of their own business. Wouldn’t want to be in any other “more glamorous” corner of the industry. Also kudos to anyone - partner or competito…

How did you figure out your pricing strategy?

Prices are fairly similar in this industry. So not much to decide. Early clients did push me to add a medium plan which turned out to be popular.

Re: The ransomware surge

#179
post #125

Earlier quoted context omitted.

Immutable backups are often overlooked. At borgbase.com, we call this “append-only” mode and the large majority of repositories uses it. With S3 (or similar) you would add some policies to disable deletions. So it’s usually doable, but needs to be considered when setting up the backup process.

That’s all well and good for weather data, but if anything in your backup is in any way related to user behaviors or transactions, immutability is a crime.

Immutability in this context doesn't mean "kept forever", it just means the permission to hard-delete is separate from soft-delete.

GDPR requires that good data-stewards keep backups:

the controller and the processor shall implement... the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

https://gdpr-info.eu/art-32-gdpr/

For more details on GDPR and backups, see https://www.backup-systems.co.uk/blog/6-gdpr-implications-on...

It would be inappropriate, for instance, to store user data on the blockchain.

Re: The ransomware surge

#180

Earlier quoted context omitted.

I sometimes do infrastructure consulting. One of the first questions I ask is if they have at least one fully independent, full/incremental off-site backup that can't be corrupted from the main infrastructure, and if they have ever checked if they actually work and are restorable. I'm continuously surprised how often the answer turns out to be no after dinner digging, even in larger companies with otherwise well-run…

> Backups are annoying and unglamorous It gets better (as in worse) someone can easily cut down back-up expenses, and become a hero by "balancing the budget with no disruptions to operations", get a fat bonus, and then after a year or so, leave. Their successors won't get any bonuses by increasing the budget for something that has no ROI. And randsomware is booming!

> Their successors won't get any bonuses by increasing the budget for something that has no ROI.

Possibly, but not if the business has a culture of recognising downside risk. Single events that are not extremely unlikely and that could cripple the business are things that every company should be looking out for.

Post reply on HN