Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

1–10 of 147 posts

Re: The Oncoming Ransomware Storm

#3
"A future in which ransomware and mass data theft are so ubiquitous they’ve worked their way into our daily lives"

>>> True

"The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency"

>>> False

Re: The Oncoming Ransomware Storm

#4
post #3

"A future in which ransomware and mass data theft are so ubiquitous they’ve worked their way into our daily lives" >>> True "The singular reason why these attacks are even possible is due entirely to rise of cryptocurrency" >>> False

Right, it's definitely a contributing factor as to why it's profitable, but the attacks themselves could be done entirely out of malice if they wanted to.

Re: The Oncoming Ransomware Storm

#5
Ransomware is great.

1. Creates a huge financial incentive to try and break PGP encryption.

2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand.

3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers.

4. Gives the insurance companies enough room to attribute attacks to nation-state actors, making them "acts of war," and thus uninsurable. If companies can't half-ass this stuff and let their insurer clean up the mess, they're going to stop half-assing this stuff.

5. Put an end to the "I dunno, I pulled it off Dockerhub" madness.

Re: The Oncoming Ransomware Storm

#6
As somebody who's not that familiar with how financial institutions handle fraud/money laundering detection, is it possible for ransomware to have become so prevalent without cryptocurrencies? I know HSBC was in the news a few years ago for turning a blind eye towards a drug cartel, but would this type of attack at scale be tolerated by the major banks/credit unions?

Re: The Oncoming Ransomware Storm

#7
post #6

As somebody who's not that familiar with how financial institutions handle fraud/money laundering detection, is it possible for ransomware to have become so prevalent without cryptocurrencies? I know HSBC was in the news a few years ago for turning a blind eye towards a drug cartel, but would this type of attack at scale be tolerated by the major banks/credit unions?

I don't think cryptocurrencies are the only solution. Before the rise of cryptocoins, you'd just shuttle physical gift cards around.

But cryptocoins are definitely more efficient than traditional forms of money laundering.

Re: The Oncoming Ransomware Storm

#8
"Imagine a world in which every other month you’re forced to bid for your personal data back from hackers who continuously rob you. And a world where all of this is is so commonplace there are automated darknet marketplaces where others can bid on your data, and every detail of your personal life is up for sale to the highest bidder. Every private text, photo, email, and password is just a digital commodity to be traded on the market. Because that’s what the market demands and that’s what capitalism left unchecked will provide."

Maybe I'm in a minority, but I think I'd air-gap my personal data if this world ever came to pass...I'm considering it already to be perfectly honest.

Would the general population just give up if things got that bad? As per TFA, I imagine state level actors will step in if things get much worse, lest people start unhooking en masse due to the risk/reward ratio flipping.

Re: The Oncoming Ransomware Storm

#9
Banning cryptocurrency only fixes one side of the global-internet-being-security-broken problem. If you're a nation-state actor and you can still break into computer systems throughout the world, you can still:

- Manipulate and profit in foreign stock markets by short/long selling based on insider information

- Choose who gets elected by making dirty laundry public

- See military planning by the enemy, live, as it happens

- Trick critical foreign infrastructure into self-destruction

- Discover and cultivate corporate espionage assets based on what you know about their personality from emails/SMS/metadata/etc

- Plant incriminating evidence against political or corporate adversaries, for example by using their home internet connection for something nefarious

The future hell described in the article is not a future hell. It is the present hell. Ransomware is just one small part of it.

Re: The Oncoming Ransomware Storm

#10
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

Also the most likely tonic to platform churn, reinvented wheels, codebase growth. The culture will flip towards lambasting anything that hasn't been put through the wringer as "untrustworthy".
Post reply on HN