Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

11–20 of 147 posts

Re: The Oncoming Ransomware Storm

#11
Why are arguments of this form so pervasive?

Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide?

Is it an appeal to emotion? Fear?

Re: The Oncoming Ransomware Storm

#12
post #2

Things enabled by BTC/crypto: ransomewear, climate change, overnight speculation millionaires! Also article is a bit dystopian and blaming capitalism (per usual these days).

But not entirely inaccurate.

I mean, 20 years, maybe even just 10 years ago we would've shrugged off the type of attacks happening now as "pure science fiction".

Re: The Oncoming Ransomware Storm

#13
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

6. You used to need to wonder: Have I been hacked? How bad? Now you get an invoice day-of.

Re: The Oncoming Ransomware Storm

#14
post #3

"A future in which ransomware and mass data theft are so ubiquitous they’ve worked their way into our daily lives" >>> True "The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency" >>> False

Right, it's definitely a contributing factor as to why it's profitable, but the attacks themselves could be done entirely out of malice if they wanted to.

Sure it can be done entirely out of malice, but it is now clear that cryptocurrencies enable the incentive of doing it for money.

It is becoming more and more evident that ransomware attacks are the killer app of crypto.

Re: The Oncoming Ransomware Storm

#15
I remember reading about malware like this some time back. I tried everything I could to prepare but got vetoed at every turn by management. My idea was to do "pull" backups to a server, instead of "push" backups to shares, instead my boss's boss bought some commercial backup package that while ok, when it bombed a t-log chain, they blamed microsoft's implementation of native sql server backups, and of course was nowhere near my dream "pull" server thing, heck, I don't know if my idea was even valid, I'm not that smart a guy honestly, you gotta know your limits.

I wanted flash removed from my desktop, because being the intellectual slug I am, I google everything, like how to get the correct date and time. My previous job was as a convenience store clerk, and as I'm in the process of getting fired right this very week, I suspect it'll be my next job too. I was told by my boss's boss and his cousin the gaming guy who built servers that "our firewall blocks everything".

Of course, I got a text message one morning from my boss, while I don't remember the exact text, I remember it included the word "armagghedon". I came in to work carrying my uninfected laptop, and heck, my pc looked pretty normal except the icons had changed and sort of "doubled up", each second version contained the same message, you know the drill.

I'm an sql guy, I know I'm not all CS smart like everyone here but I gotta say it was obvious even to me what was coming, its like an enemy doing bombing raids in the next city over and people are still out there watering their lawns like nothing is happening. Friggin malware, I guess it pays well tho.

Re: The Oncoming Ransomware Storm

#16
I don't really have any answers. I don't think cryptocurrency really makes the 'ransomware storm' possible. Maybe it makes it easier or easier to get away with the cash.

I do know that I work at a company with very tight controls on what we can and can't do with our computers. But we're free to install Chrome extensions as we please. Which doesn't strike me as a great idea, but maybe that's not really even the problem.

A lot of what I see in big corp environments comes down to finger pointing. I'm on a weeks old thread this very day where different groups are saying 'this isnt X's fault it's Y's fault' and it is going nowhere. At the end of the day we need to stop assigning blame and work together to fix problems. But that means we have to be able to actually admit 'maybe this system isnt as fool proof as we thought' which, of course, opens the company up to legal liability. It's a tough and complex problem, I think. Because no one wants to 'admit fault' for fear of being sued, but not admitting fault ends up obscuring root cause. And round and round we go.

Re: The Oncoming Ransomware Storm

#17
post #3

"A future in which ransomware and mass data theft are so ubiquitous they’ve worked their way into our daily lives" >>> True "The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency" >>> False

Incentives matter. Bitcoin incentivizes certain types of criminal activity. As Bitcoin grows the negative externalities will become more pronounced. I truly don’t get the ethics of it. It is killing people, literally blood money as a great new technology. Bonus points for incentivizing climate destruction and burning of fossil fuels. I don’t understand the ethics of it.

Re: The Oncoming Ransomware Storm

#18
post #6

As somebody who's not that familiar with how financial institutions handle fraud/money laundering detection, is it possible for ransomware to have become so prevalent without cryptocurrencies? I know HSBC was in the news a few years ago for turning a blind eye towards a drug cartel, but would this type of attack at scale be tolerated by the major banks/credit unions?

I don't think cryptocurrencies are the only solution. Before the rise of cryptocoins, you'd just shuttle physical gift cards around. But cryptocoins are definitely more efficient than traditional forms of money laundering.

The big corporate targets and the >1m ransoms aren't doable with gift cards.

A large hospital chain in San Diego[1] last week was hit with a $100m[2] ransomware attack that shut down the hospital. Can't pay that with gift cards.

[1] - https://www.sandiegouniontribune.com/news/health/story/2021-... [2] - Source internal said that was the ransom amount

Re: The Oncoming Ransomware Storm

#19

Banning cryptocurrency only fixes one side of the global-internet-being-security-broken problem. If you're a nation-state actor and you can still break into computer systems throughout the world, you can still: - Manipulate and profit in foreign stock markets by short/long selling based on insider information - Choose who gets elected by making dirty laundry public - See military planning by the enemy, live, as it ha…

^ ^ ^ If there's any Keanu-pill to swallow, it's this. Intelligence agencies don't "make us safe," they drive financial gain for insiders. I'd bet the ratio of effort spent on "market manipulation" versus "find the evil doers" to be 10:1.

Re: The Oncoming Ransomware Storm

#20
> The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency. And is entirely enabled by this one technology, it could not exist otherwise.

Huh, cryptocurrency existed in 1989, when the first ransomware was active? Did the author even google the word "ransomware?"

Wire transfers and all types of pre-paid voucher services were used well before cryptocurrencies were even created.

Post reply on HN