Live data from Hacker News

Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

ciphercue.com

31–40 of 101 posts

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#32
Well, given that C levels see cybersecurity has a bad return on investment (read: insurance), Ive seen countless numbers of people laid off these jobs.

So yeah, I'm surprised its only 3x, and not even more.

A good abliterated local LLM is great at finding dumb exploits and writing ransomware code. And the cybersec professionals? Yeah, theyre pivoting elsewhere and gone.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#33
post #18

Earlier quoted context omitted.

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

Sleeper agent malware is a thing especially in high risk situations. If somebody has a dormant RAT installed since year X-1 it’s going to be impossible to solve that in year X by using backups

What about non executable backups? Backup data but not programs?

Not applicable everywhere, but I think it's applicable most places.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#34
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

> damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry

Cybersecurity is not about stopping issues but about compliance and liability. Attend RSA once, and you will see it yourself.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#36

Earlier quoted context omitted.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

Er… Linux has pretty good isolation of users who don’t have super user privileges.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#37
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

> damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry Cybersecurity is not about stopping issues but about compliance and liability. Attend RSA once, and you will see it yourself.

It makes sense when you consider the main threat you are protecting yourself from is lawsuits.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#38

Earlier quoted context omitted.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

Er… Linux has pretty good isolation of users who don’t have super user privileges.

https://xkcd.com/1200/

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#39
post #28

Stopping Ransomware is trivial if governments knew where the money goes. But cryptocurrencies and lax capital control pushed by the uber-rich makes it impossible. The technology is there and it is used to track the average citizens every move. But when it comes to rich people then the money goes and comes without control (and without taxation). Cryptocurrencies are a great solution to enable criminal activity. Their…

It is far from trivial. What are you going to do if the money goes to an enemy country?

And while cryptocurrency are certainly popular with criminals, it is far from the only option for hiding transactions. As for the technology, if it exists, it is not very effective. The shadow economy is going strong even among average citizens, from drug trade to babysitting.

If governments can't stop even the most trivial kind of unreported work in their own country, how to you expect them to stop well organized international gangs, sometimes backed by nation states.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#40
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

This is a similar fact in government. For instance in the UK with the NHS and other services, we often look at total spending and assume that spending has to stay at least constant in real terms or grow, when in reality you want some metric of spending per outcome.
Post reply on HN