Live data from Hacker News

The ransomware surge

bbc.com

11–20 of 216 posts

Re: The ransomware surge

#11
> "The hackers were the Ryuk ransomware gang and they demanded we pay them 45 Bitcoin, which was about half a million dollars.

Make no mistake: this ransomware surge is 100% enabled / facilitated by Bitcoin and possibly other cryptocurrencies.

This would not have been so bad if cryptocurrencies would actually provide anything of really significant value to our societies, but no.

Aside from a mixture of Ponzi scheme, Pyramid scheme, and MLM + the energy waste, this ransomware is yet another terrible effect on our world.

It is time we effectively ban cryptocurrencies. Let’s end this madness. Please.

I am dead serious. I think cryptocurrencies and blockchain technology is the asbestos of the software world.

Re: The ransomware surge

#12

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

Why do twitter scams work so well? Because the margins are high enough from the few ppl who still fall for the scams. Awareness only does so much. You spread malware to millions of ppl, just a few conversions makes it worthwhile.

Re: The ransomware surge

#15
post #10

Ransomware wouldn't be a problem if the software industry took quality assurance seriously (or was regulated to do so), like every other engineering industry. There's little difference to me between an insecure program that allows hackers to hold your data for ransom, and a defective home appliance that occasionally starts electric fires.

Well every home appliance could easily start a fire if random malicious actors got to fuck with it while it was plugged in. You'll note that other engineering disciplines would also fall apart if hostile actors were constantly throwing explosives at the things they make 24/7.

Re: The ransomware surge

#16
post #7
post #3

This is going to be the rationale given for the heavy-handed cryptocurrency regulation they're going to bring down on all the exchanges that US persons can access. Pretty soon all you'll be able to legally access as a USian is "Bitcoin!(tm)"[1] (like what PayPal is doing), not the actual uncut blockchain bitcoin that you can send and receive at will. [1]: https://www.epsilontheory.com/in-praise-of-bitcoin/

Personally, I don't see the problem. 1. Bitcoin drives up GPU costs. 2. Bitcoin makes it ridiculously easy to commit certain forms of crime. 3. And Bitcoin's energy footprint hurts the planet.

4. It snuffs those pesky troublemakers and brings them back in line through monetary inflation across generations.

Re: The ransomware surge

#17

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

Why do twitter scams work so well? Because the margins are high enough from the few ppl who still fall for the scams. Awareness only does so much. You spread malware to millions of ppl, just a few conversions makes it worthwhile.

It's interesting that twitter isn't automatically filtering those. It's basically a solved problem, they're just not doing it.

I'm not saying it'd be easy to do, but rather that it'd be a nice thing for the world if they did.

Re: The ransomware surge

#18

Exchanges are good at blacklisting BTC ,so this means it will be hard for hackers to cash out. Just converting BTC into XMR is not a trivial process, as it needs to go through an exchange. Trustless cross chain transactions are still in infancy .

> Trustless cross chain transactions are still in infancy .

They can technically exist?

Re: The ransomware surge

#19
post #10

Ransomware wouldn't be a problem if the software industry took quality assurance seriously (or was regulated to do so), like every other engineering industry. There's little difference to me between an insecure program that allows hackers to hold your data for ransom, and a defective home appliance that occasionally starts electric fires.

In the case of ransomware though, this really is pointing firmly at the operating system. It's not (generally) insecure programs that lead to ransomware succeeding - ransomware works so effectively (and is a force multiplier for malicious actors) specifically because it runs with normal user privileges, and isn't needing to "exploit" anything.

It runs as a user, and just makes do with the access that user has to files.

Before we hold application software to account (and we really do need to), we need to start with the fundamentals - operating systems need to move beyond a "software runs as the current user" model. Otherwise I don't see how we can fix this with assurance/regulation - the root issue seems to be inherent design flaws in modern GUI/desktop operating systems. The tools are there to protect yourself (binary whitelisting, applocker, santa etc.), but they are seen as more inconvenient to use than doing nothing... Hence most companies do nothing, as that's cheaper.

Re: The ransomware surge

#20
Can someone tell me where I'm wrong here:

The solution to ransomware is to daily mirror every system to an append only backup and then just flash everything back if you get hit. You lose a few days...

Post reply on HN