Live data from Hacker News

The Worsening State of Ransomware

cacm.acm.org

11–20 of 139 posts

Re: The Worsening State of Ransomware

#11

> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to…

I want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information like this), but it would be a nice product for people with simpler needs than yours. If the backup system can write only incremental changes then the storage requirements would likely be fine for many users.

Re: The Worsening State of Ransomware

#12
post #3

> These "customers," who have zero coding skills or software expertise, take advantage of a ransomware-as-a-service (RaaS) model to gain sophisticated capabilities > Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets" What a crazy world…

A number of major drug cartels would be at least on the Fortune 1000 if they were publicly traded corporations. They have management structures, accountants, IT and security professionals, logistics, HR practices, and so on...

Re: The Worsening State of Ransomware

#13
post #2

Ransomware only really works due to the lack of diversity of operating systems and software. If individuals and businesses were all running different stuff it would be nearly impossible to target them en mass. You could only target them one at a time.

While that is a solution, I don't think it is the solution. Another non-solution would be removing all Internet access. Ransomware problem solved, a whole bunch of other problems created.

Re: The Worsening State of Ransomware

#15
post #3

> These "customers," who have zero coding skills or software expertise, take advantage of a ransomware-as-a-service (RaaS) model to gain sophisticated capabilities > Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets" What a crazy world…

Is this any different from the mafia in many places?

[deleted]

Re: The Worsening State of Ransomware

#16
> Some, including the U.S. Treasury, have promoted the idea of making it illegal to pay a ransom, though the idea has not gained widespread support.

That's probably the only solution, besides the obvious ones like actually protecting the systems.

Re: The Worsening State of Ransomware

#17
post #14

Ransomware provides a useful service and should be legal. Businesses with poor security practices deserve to be punished for their negligence.

Kidnapping provides a useful service and should be legal. Schools, kindergardens and parents with poor security practices deserve to be punished for their negligence.

Re: The Worsening State of Ransomware

#18
post #2

Ransomware only really works due to the lack of diversity of operating systems and software. If individuals and businesses were all running different stuff it would be nearly impossible to target them en mass. You could only target them one at a time.

Yes, a complete lack of interoperability would make it really hard for criminals to target them.

However, a complete lack of interoperability would make it really hard to, you know, interact with other businesses and systems.

This isn't throwing the baby out with the bathwater so much as drowning the baby in the bathwater.

Re: The Worsening State of Ransomware

#19
post #9

> Not surprisingly, dozens of major ransomware gangs now exist worldwide, including in Russia, Eastern Europe, and North Korea. To what extent should ransomware activity be considered low-grade economic warfare by nation-states who can't or won't police cyber-criminals, and thus justification for robust national responses such as sanctions?

To the extent that you'd be willing to cut off your nose to spite your face[1] (Impose economic tariffs on the countries in question, thus hurting your own domestic consumers, and strengthening economic bonds between the nation in question, and their other trading partners), or be willing to kill people over money (Go to war with the nation in question.)

[1] This point is debatable, some people feel that tariffs are not 'both-sides-lose' games. Depending on the tariff, and the situation, I too feel that way - but neither I, nor those people hold to an orthodox understanding of neo-liberal economics. [2]

[2] Which as of 2021 are the primary drivers of trade policy in the Western world. This may, or may not change in the decades to come.

Re: The Worsening State of Ransomware

#20
post #17
post #14

Ransomware provides a useful service and should be legal. Businesses with poor security practices deserve to be punished for their negligence.

Kidnapping provides a useful service and should be legal. Schools, kindergardens and parents with poor security practices deserve to be punished for their negligence.

It also ignores the perverse game being played.

Defense has to work every time. Attackers just have to get through once. That's a game that favors the attackers.

Post reply on HN