Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

111–120 of 147 posts

Re: The Oncoming Ransomware Storm

#111
post #95
post #78

Earlier quoted context omitted.

>>governments will stop working hmm... seems like all positive to me

Yay, anarchy. The half-life of anarchy is measured in hours. Then the gangs show up. Gangs are basically governments, except even less responsive to your needs and more openly committed to enriching their own leadership.

You got the first part right... Governments are gangs....

However I have to completely disagree that governments are responsive to anyone needs, or that they are not committed to their own enrichment

Re: The Oncoming Ransomware Storm

#112
post #107

I'm not an unequivocal fan of cryptocurrencies or any particular cryptocurrency by any means, but it appears this author really hates cryptocurrency and this is just an opportunity for them to argue that governments should ban cryptocurrency. Which is completely understandable and obviously in good faith given ransomware is bad and they think cryptocurrencies are bad, but I just wanted to point out their stance and t…

This is just an ad hominem response to Stephen's argument.

It 100% is an ad hominem response. I'm not trying to address his arguments whatsoever and am very low on Graham's hierarchy of disagreement. And again, I do agree with many of his points.

I just personally don't think banning cryptocurrencies (or pretty much anything) is the answer, and the very "ban-happy" attitude colors my impression of all of this and makes it less likely that I'd want to attempt to address their arguments, because I know they've very likely already made up their mind that they think the only solution is a government crackdown.

Re: The Oncoming Ransomware Storm

#113

Earlier quoted context omitted.

How about this article, titled "The Political Case for a Blanket Cryptocurrency Ban"? https://www.stephendiehl.com/blog/banbitcoin.html The author is extremely prolific and vocal about his support for outright banning cryptocurrency. It's all over his blog, it's all over his Twitter. He is proud to admit it. It could have taken you 30 seconds to verify what I was saying, but instead you chose to double down on your i…

That article doesn't call for a ban ? It says: The most expedient actions would be fourfold: Halt all wire transfers of dollars in and out of cryptocurrency exchanges. Halt foreign entities trading in dollar cash-equivalent crypto assets. Add Chinese and other foreign cryptocurrency exchanges hiding in tax-havens to sanctioned entities lists. Regulate the sale of any existing cryptocurrency assets to US persons by cl…

Here is a tweet where he literally says "crypto should be outright banned": https://twitter.com/smdiehl/status/1391655510760431617

There, can you stop being so obtuse now? You are wrong. My point is that the author is calling for a ban and that nobody was putting words in his mouth, as you suggested.

Re: The Oncoming Ransomware Storm

#114
post #101

Earlier quoted context omitted.

I'm not sure how satirical the parent's comment was, but every single point is completely inaccurate, irrelevant, and/or nonsensical.

How so? Seems it's spot on. Since the birth of the internet companies haven't given a damn about leaks and there're no real consequences. Now they care because it hurts them instead of just us.

I work in infosec and agree with the point that a lot of companies are overly lax, ignorant, and negligent about security. But I could probably write like a 10 page essay disputing all of those points. For a summarized version, I wrote some semi-relevant comments about this in another ransomware thread from the other day, so this is a lazy answer but you could Ctrl+F my username in https://news.ycombinator.com/item?id=27096137

Basically, I agree in general that a large percentage of the industry is a massive joke, but at the same time, I think in many cases there's more victim-blaming than is warranted. Ransomware isn't what it used to be. Being hit or ruined by a ransomware attack doesn't necessarily imply negligence or lack of care (even if a high percentage of the victims probably are negligent simply due to the high base rate of such companies).

Re: The Oncoming Ransomware Storm

#115
post #107

I'm not an unequivocal fan of cryptocurrencies or any particular cryptocurrency by any means, but it appears this author really hates cryptocurrency and this is just an opportunity for them to argue that governments should ban cryptocurrency. Which is completely understandable and obviously in good faith given ransomware is bad and they think cryptocurrencies are bad, but I just wanted to point out their stance and t…

This is just an ad hominem response to Stephen's argument.

It shows a clear bias on the part of the author and a reason to believe they would argue in bad faith.

The author being a founder a company for which cryptocurrencies are competitors makes this doubly true.

Re: The Oncoming Ransomware Storm

#116
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

6. Put and end to our data hording. Turns out I don't need to keep all the data we have because it's now a liability.

Re: The Oncoming Ransomware Storm

#117

My big question, and I would love an answer: Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"? People are going to click on shit. That's a 100% guaranteed fact - be it intentional or not. But WHY is our computing and communications paradigm so brittle that any Jack or Jane can click a link and pwn the infrastructure?

Impacts were small.

Just a few years ago, one of the most high profile financially-motivated ransomware attacks, WannaCry, hit the NHS and various other government agencies and companies around the world and demanded the unbelievable sum of $300 per computer [1], an amount that most of those organizations could only find by looking through their pocket lint for amounts so small. They spent 100x-1000x more money solving the residual problems than they did or would have needed to pay dealing with the ransom itself.

Just a few years ago, the worst case impacts were so small that the problem was not even worth caring about. What they did not realize is that the amounts were small because the ransomware groups likely consisted of young people with more technical ability than business sense. They did not realize how deep the money well went and how much they could really ask for, the criminal equivalent of a bunch of college students making a B2B startup and being worried that their $1k price tag might be too expensive since they would personally think that is a lot to spend. This is borne out by the fact that the targets even a few years earlier were mostly personal computers of random people who might actually have a problem paying $300 to get their family photos back. However, these ransomware groups have been rapidly wising up and now realize they were doing the effective equivalent of robbing the bank for their pens. They are starting to ask for reasonable amounts of money that businesses might actually worry about and with that money they are expanding their operations as fast as they can to try to exploit the entire market. They just have not gotten there quite yet since they do not have access to vast gobs of VC cash and need to instead bootstrap themselves up to a multi-billion dollar criminal enterprise.

The unfortunate problem for all of their targets is that none of their things work and they did not think the problem was serious since the impact of failure was so small. They did not realize that was not because more could not be done, but because the people doing it did not know what they were doing and that they were actually at the start of a serious exponential ramp.

If you want more technical reasons, it is because every commercially available solution is completely inadequate for an environment where people with modest amounts of money want to attack your system. Nobody selling commercial IT systems has the first clue how to make systems that are actually robust against credible threat actors. The absolute best of the best can maybe protect a system against attacks funded at the ~$10M level, but when you are talking about companies with literally $100B revenue streams, that is a rounding error of a rounding error. Exactly 0 executives at such a company would think that being defenseless against attackers with $10M is acceptable if told directly and I think most of their shareholders and customers would be horrified if they had to put that in their commercials in big bold letters, but that is the best that they can get.

[1] https://en.wikipedia.org/wiki/WannaCry_ransomware_attack

Re: The Oncoming Ransomware Storm

#118
post #86

Earlier quoted context omitted.

I agree, the author contradicts themselves immediately. Cryptocurrency is not the "singular" reason, and it is not why these attacks are even "possible." The hypothetical they picked might not work. The methods that ransomware was using for decades to extort hundreds of thousands of dollars did, and will continue to work.

You are still taking words out of context. Clearly the author agrees that cryptocurrency is not the singular reason behind *all* ransomware, considering he states it is not a new phenomenon. The sentence you took out of context relates to *modern* ransomware: > The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency.... Modern ransomware could not exist without Bitcoin, it ha…

I agree, it's very poorly written.

"These attacks" are defined as "automated exploitation of computer networks that aims to extract cash from the owner of that network" and "cryptocurrency" is "the singular reason" why "these attacks" are "even possible."

Later on the author shamelessly tries to shift that definition to "modern ransomware" (the same trick you're attempting here).

Why do they need to resort to that? Because they're wrong.

Re: The Oncoming Ransomware Storm

#119
post #101

Earlier quoted context omitted.

How so? Seems it's spot on. Since the birth of the internet companies haven't given a damn about leaks and there're no real consequences. Now they care because it hurts them instead of just us.

I work in infosec and agree with the point that a lot of companies are overly lax, ignorant, and negligent about security. But I could probably write like a 10 page essay disputing all of those points. For a summarized version, I wrote some semi-relevant comments about this in another ransomware thread from the other day, so this is a lazy answer but you could Ctrl+F my username in https://news.ycombinator.com/item?i…

I see nothing there that invalidates any of those points. At best it weakens points 1, 4 and 5 on the basis that companies will get away with it by paying ransoms[0], and ransomers have a incentive to not be so extractive that they kill the hosts they're parasitising, but that's still a idiot tax for said companies.

0: rather than their previous strategy of ignoring the problem entirely because other poeple's privacy doesn't show up on their balance sheet

Re: The Oncoming Ransomware Storm

#120

Earlier quoted context omitted.

I work in infosec and agree with the point that a lot of companies are overly lax, ignorant, and negligent about security. But I could probably write like a 10 page essay disputing all of those points. For a summarized version, I wrote some semi-relevant comments about this in another ransomware thread from the other day, so this is a lazy answer but you could Ctrl+F my username in https://news.ycombinator.com/item?i…

I see nothing there that invalidates any of those points. At best it weakens points 1, 4 and 5 on the basis that companies will get away with it by paying ransoms [0], and ransomers have a incentive to not be so extractive that they kill the hosts they're parasitising, but that's still a idiot tax for said companies. 0: rather than their previous strategy of ignoring the problem entirely because other poeple's privac…

Indeed, I'd need to explicitly address each point to explain exactly why and how I disagree.

They're not exactly wrong in a general sense (which I know sounds a little contradictory given I said "every single point is completely inaccurate, irrelevant, and/or nonsensical"), but I think they're wrong in a fundamental way when talking about the ransomware problem. And point 1 is a total non-sequitur in at least three different ways.

It's a complex topic. Basically, I just think that even though a ton of cynicism (about this, about the infosec industry, about companies' approach to security) is absolutely and overwhelmingly warranted, they're being too cynical.

Post reply on HN