Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

61–70 of 147 posts

Re: The Oncoming Ransomware Storm

#61
post #54

FYI, the author has a huge conflict of interest whenever he writes about cryptocurrency, seeing as he's the founder of Adjoint, Inc, a company which digitizes cash and settlement processes for multinational corporates. So it's easy to see why he hates a technology that renders his entire company useless.

Something that would be relevant. Would love to know who's downvoting you.

[deleted]

Re: The Oncoming Ransomware Storm

#62
post #56

Why are arguments of this form so pervasive? Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide? Is it an appeal to emotion? Fear?

1- Crypto is made to evade government control. 2- Government are there to ensure law and order. Result: Crypto is a great tool to evade law and order Governments will have to control crypto or governments will stop working

I'd say crypto is made to remove government control on money, not to evade law and order. That's certainly doable, but you can also evade law and order with normal fiat currency (ex: HSBC laundering billions of dollars for cartels).

Re: The Oncoming Ransomware Storm

#63
post #23

I remember reading about malware like this some time back. I tried everything I could to prepare but got vetoed at every turn by management. My idea was to do "pull" backups to a server, instead of "push" backups to shares, instead my boss's boss bought some commercial backup package that while ok, when it bombed a t-log chain, they blamed microsoft's implementation of native sql server backups, and of course was now…

GPT-3

This guy, and not the amygdala-hijacked no-theory-of-minders that rolled in the other day?

Re: The Oncoming Ransomware Storm

#64

My big question, and I would love an answer: Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"? People are going to click on shit. That's a 100% guaranteed fact - be it intentional or not. But WHY is our computing and communications paradigm so brittle that any Jack or Jane can click a link and pwn the infrastructure?

https://www.cisecurity.org/resources/advisory/?type=advisory

Take a quick look at all the vulnerabilities out there. Google has been releasing 1-2 fixes a week for the last month or so. It's a constant battle keeping this stuff patched.

Re: The Oncoming Ransomware Storm

#65
post #55

Are there any active non-Windows ransomware infections going on? I don’t recall seeing any macOS / Linux / Android / iOS attacks.

I’m willing to bet SaaS ransomware will be up next. Imagine a user is tricked into adding a browser addon (common), and the malicious addon encrypts all the data in a salesforce, Dropbox, and online mail account

And then users are going to be thankful that their data is not encrypted at rest. Classic pincer maneuver

Re: The Oncoming Ransomware Storm

#66
post #55

Are there any active non-Windows ransomware infections going on? I don’t recall seeing any macOS / Linux / Android / iOS attacks.

I’m willing to bet SaaS ransomware will be up next. Imagine a user is tricked into adding a browser addon (common), and the malicious addon encrypts all the data in a salesforce, Dropbox, and online mail account

One of the reasons why it's so important to disable the ability for users to consent on behalf of the organization for applications in suites such as 365 where the default is to allow the user to do so.

Re: The Oncoming Ransomware Storm

#67

Earlier quoted context omitted.

I don't think cryptocurrencies are the only solution. Before the rise of cryptocoins, you'd just shuttle physical gift cards around. But cryptocoins are definitely more efficient than traditional forms of money laundering.

The big corporate targets and the >1m ransoms aren't doable with gift cards. A large hospital chain in San Diego[1] last week was hit with a $100m[2] ransomware attack that shut down the hospital. Can't pay that with gift cards. [1] - https://www.sandiegouniontribune.com/news/health/story/2021-... [2] - Source internal said that was the ransom amount

You'd ask for cash. A middleman would pick it up, convert it to gift cards or Tide laundry detergent (so that the traced cash would go cold) and then pass it forward through the criminal network.

The middleman needs to be paid because it's high risk (cops would trace the cash to the middleman... but no further). So cryptocoin are way cheaper. But still, there's plenty of ways to do things using old school techniques.

Re: The Oncoming Ransomware Storm

#68
post #21

Governments should make it illegal to pay ransom. Only the government should be allowed to pay (in the name of victims) but under very strict conditions. EDIT: slightly different but I wasn't the only one with an idea in this direction: https://www.reuters.com/article/us-treasury-cyber-idUSKBN26M...

> Governments should make it illegal to pay ransom.

That won't really change anything, other than add 'break a law' to 'lose tons of $$' and 'lose data/time' to the list of bad things a company will deal with to recover from a ransomware attack.

Re: The Oncoming Ransomware Storm

#69
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

I did some searching and didn't find anything about use of the OpenPGP standard in ransomware. It appears that ransomware creators don't care about interoperability, which makes sense for their biz.

A doubt that anyone has ever been motivated to try to break an encryption method just because it was used in some particular ransomware. The methods used are generally not breakable, the mistakes come from stuff like leaving keys laying around in memory or even on the disk.

Re: The Oncoming Ransomware Storm

#70

My big question, and I would love an answer: Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"? People are going to click on shit. That's a 100% guaranteed fact - be it intentional or not. But WHY is our computing and communications paradigm so brittle that any Jack or Jane can click a link and pwn the infrastructure?

As I've told someone today, we're shooting lightning through sand and somehow it all works.

There are network effects of network effects at work inside computer systems. We can harden a path. Two paths, sure. Three, why not. 4 billion? No way to be sure.

It's also a matter of it being an aggressor's game. The defense has to be perfect every single time. The offense just has to win once. And they get infinite tries. And they suffer no penalty for failure.

Post reply on HN