Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

71–80 of 147 posts

Re: The Oncoming Ransomware Storm

#71

Banning cryptocurrency only fixes one side of the global-internet-being-security-broken problem. If you're a nation-state actor and you can still break into computer systems throughout the world, you can still: - Manipulate and profit in foreign stock markets by short/long selling based on insider information - Choose who gets elected by making dirty laundry public - See military planning by the enemy, live, as it ha…

But that only applies to targets who are "in the game." If you are a government entity or listed company or act as their agents, then you know that security is an issue and are paid well enough to make a decent effort. Whether you do or not is a different issue.

Grandma doesn't have security audits, wouldn't know how to do one, and couldn't afford it if she did. She is the victim here. She might call the police but they will file a report and forget it. The only chance of getting caught is some larger agency like the FBI picking it up and going after you. This is highly unlikely.

The only thing stopping Grandma from getting ransomed is making it difficult to pay. If your ransom depends on walking Grandma through the 15 step process of paying you, then it's unlikely to happen or be profitable.

Re: The Oncoming Ransomware Storm

#72
post #63
post #23

Earlier quoted context omitted.

GPT-3

This guy, and not the amygdala-hijacked no-theory-of-minders that rolled in the other day?

I managed to wire up sirc to a perl eliza implementation once. My cobol instructer in community college thought I was a pervert for doing so and in hindsight she was probably right, I think I only ran it once honestly. Nowadays I just run an old eliza in another terminal when I chat on irc and copy and paste between the two terminals, this gets rid of the ethical concerns as there is a human between the interface acting as a guard against AI run amuck so I think I'm good.

Re: The Oncoming Ransomware Storm

#73
Today is the beginning 'wild west' stage of the information technology industry. Software ate the world and now security is starting to matter to the bottom line.

GDPR and privacy are another big factor which I think will push the professionalization of the industry.

I do think the worst case scenario outlined in this article is unlikely. We can build systems that are not that vulnerable to ransomware. You can have backups that are safely stored off network. It is just that old industries have slowly computerized without updating their processes and view of themselves.

Every company is a tech company now.

Re: The Oncoming Ransomware Storm

#75
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

I'm not sure what point 3 refers to?

Re: The Oncoming Ransomware Storm

#76

My big question, and I would love an answer: Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"? People are going to click on shit. That's a 100% guaranteed fact - be it intentional or not. But WHY is our computing and communications paradigm so brittle that any Jack or Jane can click a link and pwn the infrastructure?

You're completely right in your thinking that it's largely ridiculous and avoidable. The answer is generally lack of separation of duties and least privilege. That L1 tech in a smaller organization might be a member of the domain admins group. And to avoid UAC prompts, might sign into his computer as domain admin account. If something runs as him, it runs as admin. Large file shares where every user has edit permissions are also extremely prevalent. Every user has the ability to destroy the shared drive. I've seen a lot of small organizations where the owner insisted on being an admin, despite having no technical knowledge. He clicks something wrong and the malware's got carte blanche. Old line of business applications will often require exact versions of Flash/Java/whatever which are riddled with security holes.

Outside that, there's the 0 days and exploits. But a lot of what I see are setups that grew from small, insecure setups where it didn't matter to big, insecure setups where it did. Combine that with the ROI on security not being immediately tangible, and it's hard to get approval for projects to fix it. Even if you design the most secure systems, unless you've got a seat at the executive table someone will probably overrule you and make exceptions.

Re: The Oncoming Ransomware Storm

#77

Why are arguments of this form so pervasive? Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide? Is it an appeal to emotion? Fear?

Perhaps the key is that most people do not perceive huge benefits from these, but they perceive huge danger from the downsides. People usually both underestimate their own downstream benefits because of large inferential distance between the thing (encryption) and themselves, and overestimate the dangers of the downsides.

Then we'd have the ages-old dynamic that something that benefits everyone a bit but harms a minority a lot will be pushed out by people.

Re: The Oncoming Ransomware Storm

#78
post #56

Why are arguments of this form so pervasive? Cryptocurrency is bad and must be banned because ransomware. Encryption is bad because pedos, let’s ban Tor and Signal. We need a permanent surveillance state and forfeit most of our rights to privacy because terrorists bad, what do you have to hide? Is it an appeal to emotion? Fear?

1- Crypto is made to evade government control. 2- Government are there to ensure law and order. Result: Crypto is a great tool to evade law and order Governments will have to control crypto or governments will stop working

>>governments will stop working

hmm... seems like all positive to me

Re: The Oncoming Ransomware Storm

#79
post #21

Governments should make it illegal to pay ransom. Only the government should be allowed to pay (in the name of victims) but under very strict conditions. EDIT: slightly different but I wasn't the only one with an idea in this direction: https://www.reuters.com/article/us-treasury-cyber-idUSKBN26M...

> Only the government should be allowed to pay

The gov is the one entity that should not be allowed to pay at any cost, as it has infinite paying power.

Re: The Oncoming Ransomware Storm

#80

Banning cryptocurrency only fixes one side of the global-internet-being-security-broken problem. If you're a nation-state actor and you can still break into computer systems throughout the world, you can still: - Manipulate and profit in foreign stock markets by short/long selling based on insider information - Choose who gets elected by making dirty laundry public - See military planning by the enemy, live, as it ha…

But that only applies to targets who are "in the game." If you are a government entity or listed company or act as their agents, then you know that security is an issue and are paid well enough to make a decent effort. Whether you do or not is a different issue. Grandma doesn't have security audits, wouldn't know how to do one, and couldn't afford it if she did. She is the victim here. She might call the police but t…

I believe that subversion of the democratic process and economic efficiency hurts everyone, if not initially or obviously. Recent election cycles have been tumultuous.

Grandmas are currently targeted by scammers who ask for iTunes gift card numbers and not Bitcoin, I'm not sure that much will change. I've yet to hear people call for a ban on iTunes gift cards, but maybe we will get there.

Post reply on HN