Live data from Hacker News

How My Mom Got Hacked

nytimes.com

71–80 of 111 posts

Re: How My Mom Got Hacked

#71
The article doesn't seem answer the question raised in the title. How did Mom get hacked? Actually it's buried in there:

> "So what can we all do to protect ourselves? Keep our computers backed up [...] and most of all, Beware the Attachment."

Ah, so the Attachment is what got Mom!

You know, the above should really be "Beware the Attachment processed on a Microsoft Windows box using the default and/or most popular handlers for its file type."

Also: "beware of letting naive users use the same Windows PC's for Internet-based consumption activities net surfing and e-mail, and for production/retention of important content."

Re: How My Mom Got Hacked

#72

Isn't this a pretty strong argument against Bitcoin and other cryptocurrencies? (I am being serious.)

Isn't this a pretty strong argument against encryption?

Isn't this a pretty strong argument against cash?

Isn't this a pretty strong argument against email attachments?

Re: How My Mom Got Hacked

#73
post #67

Has anyone ever done a serious technological evaluation of one of these programs? I'd be very interesting in learning more specifically about its encryption mechanism. For example, To be able to decrypt (edit: used to say encrypt) the files, it has to store the private key (and obviously the public key) somewhere on the computer, whether in memory or elsewhere to decrypt the files. In addition to this, if this is a v…

Also, wouldn't it be possible to recover the files on most filesystems, assuming the disk is too not full? The program has to encrypt them, unlink the files, and save the encrypted files / archive. If the filesystem needs more space later, it writes over those (discarded) files, right? Everything else would increase disk wear and decrease performance. Edit: of course excluding SSDs with TRIM/discard enabled.

The problem is that "needs more space later" can occur as soon as the malware moves on to the next file to encrypt.

Also, overwriting discarded files can happen even before the filesystem runs out of space; it depends on the allocation strategy. To maximally preserve the possibility of undeleting files, there would have to be a policy of using the least recently freed blocks for new allocation. That could be pessimistic in other regards, like minimizing fragmentation and seek time.

Re: How My Mom Got Hacked

#74
post #47
post #31

Earlier quoted context omitted.

The problem is not the ransomware neither the criminals ... it's the way internet/computer users became completely unaware of what they are using and blindly trusting everything. Think of this as a natural balance to the ridiculously insecure internet and people's tech culture. If we are all going to live in a world where we use internet and technologies everyday, we should have a minimum of knowledge on how it works…

I bet you don't know how the power circuit in your fridge works and still you expect it not to burn down your kitchen while you sleep.

Not quite. A better analogy here is this: there is a supplier of fridges that is notorious for unreliable power circuits. People know this, and buy those fridges anyway, hoping that it won't happen to them, because the fridges are popular and have a particular copyrighted layout of the door and shelves so that they don't have to learn anything new when visiting friends or moving to different house. Initially, the fires weren't the people's fault; but when the people kept buying and installing those fridges in spite of the problem, they expressed their disregard for the issue with their dollars. At that point, they began to deserve the consequences. (Of course, the analogy is quite flawed because not everyone knows; there are always some new users who think they are getting a safe fridge, and are cheerfully sold the death trap.)

Re: How My Mom Got Hacked

#75

The article doesn't seem answer the question raised in the title. How did Mom get hacked? Actually it's buried in there: > "So what can we all do to protect ourselves? Keep our computers backed up [...] and most of all, Beware the Attachment." Ah, so the Attachment is what got Mom! You know, the above should really be "Beware the Attachment processed on a Microsoft Windows box using the default and/or most popular ha…

That's effectively saying that non-experts should only use something like iOS or maybe ChromeOS. The same class of attacks works against any user using any operating system which allows them to install arbitrary code - Mac, Android, Linux, etc. all have past examples of successful attacks which started with an email attachment, browser drive-by, etc.

Re: How My Mom Got Hacked

#77

Isn't this a pretty strong argument against Bitcoin and other cryptocurrencies? (I am being serious.)

Isn't this a pretty strong argument against encryption? Isn't this a pretty strong argument against cash? Isn't this a pretty strong argument against email attachments?

> Isn't this a pretty strong argument against encryption?

No; totally different arena.

> Isn't this a pretty strong argument against cash?

Cash is a lot more traceable than bitcoin transactions.

> Isn't this a pretty strong argument against email attachments?

? :)

Re: How My Mom Got Hacked

#78

Isn't this a pretty strong argument against Bitcoin and other cryptocurrencies? (I am being serious.)

Not really. Most useful technologies can be used in crime and we'd get nowhere if we allowed that fact to be used as an argument against the technology. Pre-Bitcoin, the scammer would have her call an expensive foreign premium-rate phone number or mail cash to a foreign address.

> Pre-Bitcoin, the scammer would have her call an expensive foreign premium-rate phone number or mail cash to a foreign address.

A foreign address is still an address, which if used to perpetrate crime on a large scale, would represent a point of vulnerability for the criminals even in a somewhat lawless country. Bitcoin's role in these crimes is analogous to an alternate universe, lawless by design, where criminals can retrieve ransoms anonymously and with impunity.

Re: How My Mom Got Hacked

#79

And that is why I have the "if you don't have backup, I won't bother to help you with your lost files" policy when friend or family come crying. I make only one exception from this rule. Cryptolocker is not the problem. The lack of reliable backup is. 15 years into the internet age, and 5 into the cloud you have no excuse.

Indeed, having a recent valid backup turns the cryptolocker variety of virus quite ineffective, you only lose some time to restore vs files you can't replace. But how is this related to the internet or the cloud in any way? Putting backups into the cloud is a terrible idea and transferring large data collection over a residential Internet connection makes little sense. Backups for home users became a possibility with…

> Backups for home users became a possibility with the advent of cheap storage, first burners and cheap blank discs and now with large hard drives and flash media.

Now your home users need to start regular media rotation with scheduled integrity checks with a full copy stored off-site in a geographically diverse location. Are you starting to reconsider your assertion that “putting backups into the cloud is a terrible idea”?

Re: How My Mom Got Hacked

#80

Earlier quoted context omitted.

Isn't this a pretty strong argument against encryption? Isn't this a pretty strong argument against cash? Isn't this a pretty strong argument against email attachments?

> Isn't this a pretty strong argument against encryption? No; totally different arena. > Isn't this a pretty strong argument against cash? Cash is a lot more traceable than bitcoin transactions. > Isn't this a pretty strong argument against email attachments? ? :)

> Cash is a lot more traceable than bitcoin transactions.

This is extremely false. How did you get this idea?

Post reply on HN