Live data from Hacker News

How My Mom Got Hacked

nytimes.com

81–90 of 111 posts

Re: How My Mom Got Hacked

#81
post #9

I'm surprised that no one has fingerprinted the patterns that these apps take to encrypt the files, then created an antivirus definition for them. Surely they can't be that polymorphic that no one can catch them?

The problem is that the signature-based antivirus model assumes 1980s-speed networking where an attacker releases a single program which has months or years to spread around the world. In the Internet era, the attacker receives the same AV updates when you do and can tweak an executable until it's no longer detected locally before immediately deploying it. This approach can even be automated both to permute the executable until it passes and to stop spreading it after it starts being flagged.

Re: How My Mom Got Hacked

#82

So the title is "How My Mom Got Hacked" and the only thing it actually says about that actual title is: The virus is thought to infiltrate your computer when you click on a legitimate-looking attachment or through existing malware lurking on your hard drive, ... So, there's really nothing about how his mom got hacked. Don't get me wrong, it's an interesting article, interesting to read about the process that ensues o…

Jesus. The publisher is the New York Times, writing a story about a real threat to ordinary people. It's not a great headline, but neither is it really misleading either. It effectively communicates what the article is about to SNYT readers.

Apparently anything that is not 100% dull now is clickbait.

Re: How My Mom Got Hacked

#83
post #75

The article doesn't seem answer the question raised in the title. How did Mom get hacked? Actually it's buried in there: > "So what can we all do to protect ourselves? Keep our computers backed up [...] and most of all, Beware the Attachment." Ah, so the Attachment is what got Mom! You know, the above should really be "Beware the Attachment processed on a Microsoft Windows box using the default and/or most popular ha…

That's effectively saying that non-experts should only use something like iOS or maybe ChromeOS. The same class of attacks works against any user using any operating system which allows them to install arbitrary code - Mac, Android, Linux, etc. all have past examples of successful attacks which started with an email attachment, browser drive-by, etc.

That actually may be a very good idea. It's not that non-experts should be forbidden from using these thing it is that we should stop handing people guns that they end up using to shoot themselves in the foot with.

Re: How My Mom Got Hacked

#84
post #50

You'd think Putin might be persuaded to take action against some of the guilty parties. I know that has not been the Russian tradition but things could change.

The guilty parties (where known) are local heroes. The US has a bad reputation in much of the world.

Re: How My Mom Got Hacked

#85
post #83
post #75

Earlier quoted context omitted.

That's effectively saying that non-experts should only use something like iOS or maybe ChromeOS. The same class of attacks works against any user using any operating system which allows them to install arbitrary code - Mac, Android, Linux, etc. all have past examples of successful attacks which started with an email attachment, browser drive-by, etc.

That actually may be a very good idea. It's not that non-experts should be forbidden from using these thing it is that we should stop handing people guns that they end up using to shoot themselves in the foot with.

Agreed – I'm not cheerful about the implications of making things less user-serviceable but … it's not like we don't know how well that's worked out.

If you haven't already read it, SwiftOnSecurity's “A story about Jessica” is rather good for illustrating how badly we've failed as an industry to produce devices which are safe for non-experts to use:

http://swiftonsecurity.tumblr.com/post/98675308034/a-story-a...

Re: How My Mom Got Hacked

#87

Earlier quoted context omitted.

Isn't this a pretty strong argument against encryption? Isn't this a pretty strong argument against cash? Isn't this a pretty strong argument against email attachments?

> Isn't this a pretty strong argument against encryption? No; totally different arena. > Isn't this a pretty strong argument against cash? Cash is a lot more traceable than bitcoin transactions. > Isn't this a pretty strong argument against email attachments? ? :)

(gp was being sarcastic)

Re: How My Mom Got Hacked

#88

Apparently CryptoWall does a dumb copy of the files before encrypting them and do not zero-out after deleting. If it still proceeds this way, that makes it fairly easy to do some recovery. Source: http://www.wyattroersma.com/?p=108

Hey, that's really useful/helpful info! I'll endorse TestDisk/PhotoRec as a mechanism for recovering deleted files, should be appropriate for most (though you might want a trusted tech savvy person to execute this recovery). The System Rescue CD includes these packages.

http://www.cgsecurity.org/wiki/PhotoRec

http://www.sysresccd.org/SystemRescueCd_Homepage

Re: How My Mom Got Hacked

#89
post #82

So the title is "How My Mom Got Hacked" and the only thing it actually says about that actual title is: The virus is thought to infiltrate your computer when you click on a legitimate-looking attachment or through existing malware lurking on your hard drive, ... So, there's really nothing about how his mom got hacked. Don't get me wrong, it's an interesting article, interesting to read about the process that ensues o…

Jesus. The publisher is the New York Times, writing a story about a real threat to ordinary people. It's not a great headline, but neither is it really misleading either. It effectively communicates what the article is about to SNYT readers. Apparently anything that is not 100% dull now is clickbait.

It's not about being dull, or exciting, and it's not about click-bait or otherwise. It's about accuracy, reporting, and expectations. The heading was "How My Mom Got Hacked" so I expected to see something about how her mom got hacked.

But I didn't. It was a great story about what happened after her mom got hacked, and it was interesting, and mildly engaging, but it simply wasn't what it said.

Calling it something like "Paying the hackers" or something like that would have been accurate and just as intriguing.

Is it too much to ask reporters to title the article with something that actually refers to what is in it?

Re: How My Mom Got Hacked

#90

Earlier quoted context omitted.

Not really. Most useful technologies can be used in crime and we'd get nowhere if we allowed that fact to be used as an argument against the technology. Pre-Bitcoin, the scammer would have her call an expensive foreign premium-rate phone number or mail cash to a foreign address.

How about when in a few years time there's a scalable, functioning market for hits/murders with bitcoin as payment? I love the elegance of the bitcoin protocol, but I am worred that the civilized world will have to clamp down on it. You just can't have a place where anyone with enough money (a few k EUR/USD) can perform murders without any reasonable risk of being exposed. This will effectively turn us into a bandit…

> You just can't have a place where anyone with enough money (a few k EUR/USD) can perform murders without any reasonable risk of being exposed.

Your 'reasonable risk of being exposed' is when you plan and execute the hit. It's pretty difficult to do. Also, when your target winds up dead, the first investigation is into whether anyone might want that person dead (motive), not the money trail.

Any hitman worth his salt will already today know to get paid in cash or similar liquid assets. As opposed to the ransom situation, the payment of a hit can be arranged long before investigators start looking, so you can easily ship a boxful of cash to a dead drop and avoid ever meeting the hitman in person.

And even if there was a money trail, you couldn't hope to get to a hitman by following it unless you have the other end to start down - ie. you know the "customer", who's the bigger criminal anyway.

> This will effectively turn us into a bandit country like Russia.

No, the availability of anonymous payments is not the defining difference between Russia and 'us'. The rule of law is.

Post reply on HN