Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

211–220 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#211

Earlier quoted context omitted.

I think wikipedia got the details wrong there. Crassus didn't offer to buy the burning buildings, he offered to put fires out. At least, that's how I understood it years ago and that's what Wiki's own source shows-- http://www.trivia-library.com/b/richest-people-in-history-ma... . edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.

That's interesting - I definitely have heard it taught the way Wikipedia has it. But I suppose some website here or there doesn't really count as much of a source when we're talking of events so far in the past. Maybe someone can provide a primary source or two?

Hmm, I dug further. The story probably comes from Plutarch (Lives), "[Crassus] would buy houses that were afire, and houses which adjoined those that were afire, and these their owners would let go at a trifling price owing to their fear and uncertainty"[1].

Plutarch was closer to Crassus than I am so I guess I can't argue.

[1] https://penelope.uchicago.edu/Thayer/e/roman/texts/plutarch/...

Re: 80% of orgs that paid the ransom were hit again

#212
post #164

Earlier quoted context omitted.

The privately owned fire brigades in NYC 100 years ago weren't much better. The free market at work: https://www.youtube.com/watch?v=9zoXk1vnmcg The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires. https://en.wikipedia.org/wiki/Bowery_Boys

Setting fires on other peoples' property is not "the free market at work".

But the rest of it was. The part in the first half of my message and the linked video is entirely free-market.

Also, please do the work to expound on your claim.

Re: 80% of orgs that paid the ransom were hit again

#213

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

Many people’s backup routines aren’t good enough. Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.

That's why you have a combination of rotating backups, say 7, one a day, and non-rotating permanent backups, say once a week.

Also, one should use "append only" backups (such as tape), or a disk drive designed to be append only with hardware write enables.

Re: 80% of orgs that paid the ransom were hit again

#214

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

Which is why you need a level above the individual to protet from attacks.

It sucks locking things down for each employee, and subjecting them to bureaucracy to unlock things they need to do, but it's better than ransomware.

It's unrealistic to expect every employee to catch hacking attempts 100% of the time.

Re: 80% of orgs that paid the ransom were hit again

#215

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

How do you go about testing your personal backups? I find my own desktop is harder to verify than a server with automated tests

What I do is see if it can be read by an independent system. For example, many dvd players can read media files plugged into a USB port. Put some media files on your backup drive, and see if your dvd player can read them.

Re: 80% of orgs that paid the ransom were hit again

#216

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

> they can successfully call themselves a mob Or Backblaze's evil twin.

[deleted]

Re: 80% of orgs that paid the ransom were hit again

#218

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

> Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups.

Why? Secretary gets a call from a nigerian prince, starts that letter.exe she gets in her e-mail, her computer gets fscked, IT takes her drive, restores a clean image, and she gets back to work.

If the only copy of some important document is on his/her pc, or that pc can overwrite/delete the only copy, then they've fscked up by design... and yes, now better backups would help.

Re: 80% of orgs that paid the ransom were hit again

#219

How long do major companies keep back ups? It seems like all of these companies that keep getting hit with ransomware Only have last weeks back up laying around. Why can’t you go back eight months? True the data is going to be lacking, but at least the structure is going to be there. I completely understand that a Trojan or a virus can get locked into a back up and it just keeps getting backed up, but if you go far e…

I have yearly backups for three years. Right now, we could use one of those. At my last place, they only kept 1 year and monthly, but the problem was it was hundreds of terabytes of data on lots of VMs. We tried to restore backups and it was going to take longer than the long weekend just for file transfer. I don’t know what normal process is, but I believe I saw file locker Trojan that didn’t hit every byte of the d…

The company I work for does nightly back ups and we keep them for five years in cold storage. Our CTO got hit with an attack years ago that almost cost him his job at another company, and he vowed to never let it happen again. Are we unusual for this?

Re: 80% of orgs that paid the ransom were hit again

#220
post #202

Earlier quoted context omitted.

I’m not arguing philosophy. I’m arguing how absurd the statement “it’s crazy hard to get people to sacrifice themselves for the better good” is, as if OP would sacrifice his or herself for anyone here they didn’t know. What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality. Maybe you watch a little bit too much television, but there…

If you don't see the chasm between "people should sacrifice themselves for the greater good" (which I'd generally disagree with, particularly if you're not defining what the greater good is) and "there is no greater good than defending one’s self" then I can't help you.

[deleted]
Post reply on HN