Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

41–50 of 147 posts

Re: The Oncoming Ransomware Storm

#41
post #39
post #24

Earlier quoted context omitted.

Items 2 and 3 will increase massively as people who don't know what they're doing attempt to cover their butts.

a steep climb in the short term that falls off a cliff in the not-so-short-term as those employers cease to exist.

That's not how the world works my friend.

Re: The Oncoming Ransomware Storm

#42

Why are arguments of this form so pervasive? Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide? Is it an appeal to emotion? Fear?

Why are comments in the form of putting words into someone's mouth which they didn't say, so pervasive? The blog says "reign in and regulate", not "ban". But, to address your point, because they're good arguments. "We need to regulate $thing" has saved lots of lives. No longer can you sell plain river water to drink, dump sewage directly back into rivers, dump industrial waste into rivers, build houses which collapse…

The author has multiple articles calling for an outright blanket ban on all cryptocurrencies. So in the author's own words, he is calling for a ban on all cryptocurrency.

Re: The Oncoming Ransomware Storm

#43

Why are arguments of this form so pervasive? Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide? Is it an appeal to emotion? Fear?

It's an appeal to authoritarianism. The author wants "someone" with power to tell everyone what they're allowed, and not allowed to do. " The free flow of money from US banks to cryptocurrency exchanges is the root cause and needs to halt. " Direct quote. Author is in London, but believes that #TeamAmericaWorldPoliece needs to step in because the only viable on/off ramp to cryptocurrencies is the US Bank System.

The article has the veneer of being well thought out, however if you look at their other writing & twitter there's definitely a I think I'm smart & didn't invent/make money/gain referential power from crypto so it's a scam & they now have ego tied up in being right/seeing the state clamp down on it.

Re: The Oncoming Ransomware Storm

#44
post #41
post #39

Earlier quoted context omitted.

a steep climb in the short term that falls off a cliff in the not-so-short-term as those employers cease to exist.

That's not how the world works my friend.

so long as encryption-as-we-know-it holds-up, there's no rescue for orgs that repeatedly get hit and can't get their backup strategy together. Sure, you make a regulatory mis-step and you have friends in high places, they will look the other way. This indeed, is how the world works. If your entire infrastructure is encrypted into a solid block of nothingness it doesn't matter if your dad is a senator, you're done.

Re: The Oncoming Ransomware Storm

#45
post #2

Things enabled by BTC/crypto: ransomewear, climate change, overnight speculation millionaires! Also article is a bit dystopian and blaming capitalism (per usual these days).

But not entirely inaccurate. I mean, 20 years, maybe even just 10 years ago we would've shrugged off the type of attacks happening now as "pure science fiction".

30 years ago there was ransomware in the wild:

1989 -Popp/ AIDS trojan 2005 - GPCoder trojan 2017 - notpetya (AKA the moller maersk hack) https://actzero.ai/resources/white-paper/the-rise-of-ransomw...

Re: The Oncoming Ransomware Storm

#46
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

why do we need an incentive to break PGP?

Let me explain, the basics:

Any system that has a case where key collisions can occur less than random is the only incentive you need...large use of bitcoin ensures that case all by itself with the rule that you use a new key for every transaction.

LEOs use this track down illicit money.

crypto in practical terms is not secure in that the key collision when it occurs and it will unmasks you not directly but indirectly and the cost to do the work of that lowers as it ages and does not go up computation wise.

It's somewhat perverse where when the world uses more bitcoin the more key collisions occur.

Re: The Oncoming Ransomware Storm

#47
post #23

I remember reading about malware like this some time back. I tried everything I could to prepare but got vetoed at every turn by management. My idea was to do "pull" backups to a server, instead of "push" backups to shares, instead my boss's boss bought some commercial backup package that while ok, when it bombed a t-log chain, they blamed microsoft's implementation of native sql server backups, and of course was now…

GPT-3

heh

interestingly enough, I've learned that machine learning is a trend in malware protection nowadays and rather than being signature based, it watches for malware like behavior. after the attack, we installed something like that, and it removed some of the very small vb programs I had put my heart and soul into.

Re: The Oncoming Ransomware Storm

#48
post #21

Governments should make it illegal to pay ransom. Only the government should be allowed to pay (in the name of victims) but under very strict conditions. EDIT: slightly different but I wasn't the only one with an idea in this direction: https://www.reuters.com/article/us-treasury-cyber-idUSKBN26M...

That's not exactly going to do what you think it does.

It potentially makes the victims criminals. That's just not what the law should be doing. It is decidedly unjust. It also drives the whole thing further from the public eye as no one will admit they're being held up for ransom because paying is now illegal.

If making something illegal was a perfect solution, ransomware wouldn't be a thing in the first place.

Re: The Oncoming Ransomware Storm

#49
post #21

Governments should make it illegal to pay ransom. Only the government should be allowed to pay (in the name of victims) but under very strict conditions. EDIT: slightly different but I wasn't the only one with an idea in this direction: https://www.reuters.com/article/us-treasury-cyber-idUSKBN26M...

What's the punishment for paying? A fine? Then you might as well add that to the ransom and pay...

Snark aside, there's just no simple, hand-waving solution to this. Even if you held the company owners criminally liable for paying a ransom, pretty much any small company will shut down for not being able to afford top-notch security.

It also opens the door to blackmail:

> We've encrypted your files. Pay us $AMOUNT BTC by tomorrow, or your files are gone. And with a recurring payment of $AMOUNT BTC per month, I promise not to report you to the FBI for paying!

Re: The Oncoming Ransomware Storm

#50
post #31

Earlier quoted context omitted.

Incentives matter. Bitcoin incentivizes certain types of criminal activity. As Bitcoin grows the negative externalities will become more pronounced. I truly don’t get the ethics of it. It is killing people, literally blood money as a great new technology. Bonus points for incentivizing climate destruction and burning of fossil fuels. I don’t understand the ethics of it.

Replace "Bitcoin" with "Banks", in your argument. Doesn't change anything

It only works if you ignore everything in the “pro” column. Try to imagine what a world without credit would look like. It’s a much poorer world.
Post reply on HN