Live data from Hacker News

The No More Ransom Project

nomoreransom.org

141–150 of 241 posts

Re: The No More Ransom Project

#141
How can a ransomware infect my computer when I visit a website? This site claims it can happen. I understand how the attachment version works but not this one. I'm a security newb.

Re: The No More Ransom Project

#142
So a thought on why attackers make "flawed" ransomware. They want to get paid as soon as possible, and a target pays a potentially heavy opportunity cost for noncompliance (waiting for someone to break the rw). The opt-outs are already not going to be "customers", and the "customers" you do get would pay even if they were only going to be locked out for 3 months. You get no extra money for making unbreakable ransomware

Edit: this may be similar economically to the Nigerian prices' aversion to English class.

Re: The No More Ransom Project

#143

OT question: is there no way to flag that bitcoin address in any way (so it gets locked / they cannot withdraw anything)?

The original purpose of Bitcoin was to create digital cash. It is possible to track the transaction history of funds in a bitcoin address, but there is currently no central authority who can blacklist/lock addresses, and most of the major participants in the bitcoin system (users, miners, exchange operators, darknet drug markets) are not interested in changing that.

Re: The No More Ransom Project

#144
post #74

Earlier quoted context omitted.

The ransomware scheme only works because the users actually get their files back and the prices are pretty reasonable for many victims. The perpetrators spend a lot of time on the ransomware and its backend. The better it works works, the more people will pay. They rely on people like us to spread the word that it's not a scam, it's real and it works. Now that I think about it: It would really damage the whole ransom…

I'm kind amazed at the tone deafness of several comments in this thread. I get that as a larger effect, reducing the success rate of scammers hurts their business, but if I'm dealing with someone who's been hit because they weren't adequately prepared, I'm gonna recommend they pay the ransom if they want their stuff back. Because I'm trying to recommend what's best for them. People could be losing their entire family…

When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it.

That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if you have offsite backups with drives that didn't mount to your computer recently.

Re: The No More Ransom Project

#145
post #52

Earlier quoted context omitted.

This comment contains a policy suggestion. I want it to become law in the United States and elsewhere. I can't quite use the word "literally" but I almost can so I'll do so anyway: if you pay a ransom, you are literally paying for your party to attack someone else. And you are actually literally (not metaphorically) funding their next attack. Paying a ransom should be a criminal act that is twenty times worse than as…

Anyone down voting this should read Thomas Schilling's Strategy of Conflict. At one point in time in England it was punishable by death to pay ransom to pirates.

Yet the modern world decided to go back on that.

The principle being that you are not (as) responsible for what you do under duress.

Re: The No More Ransom Project

#146

This is a Windows phenomenon only right? I'd just restore from Time Machine and go along on my way.

I don't know of any Mac specific variants off the top of my head, but there is no reason why Mac would be immune to it. And the "good" versions of these do things like encrypt or outright delete things like time machine before encrypting the rest.

You may remember an incident with Transmission recently. That was a bundled mac ransomware.

https://blog.malwarebytes.com/cybercrime/2016/03/first-mac-r...

Re: The No More Ransom Project

#147
If you are willing to pay the ransomware demands who are you going to pay when your HDD fails? I'm not saying ransomware isn't a problem in itself but from a user's perspective it's indistinguishable from HDD failure and should be dealt with by using backups.

Re: The No More Ransom Project

#148

Earlier quoted context omitted.

They are probably located in a country where it is easy to bribe the policemen, and factor that into their cashflow calculation.

It really depends on how much noise/attention they attract. Bribing one policeman or a department, or a national level LE body, and so on? Due to the nature of the internet and social media there is an ever decreasing chance of flying under the radar. Even if a country's entire infrastructure is corrupt, you would still have to deal with a never ending list of 'beaks to wet'.

Bribing a LEO seems to be a risky business - how risky depends on the conditions. If you're the only one bribing an officer, you'd better ensure you have that consistent cashflow. It's easier if everyone is bribing the police. But still, the moment you interact with law enforcement, you appear on their radar. It's always better to avoid that unless absolutely necessary.

> Due to the nature of the internet and social media there is an ever decreasing chance of flying under the radar.

I disagree with this statement though. I think that Internet as it is now only makes it easier to fly under the radar - simply because people generate such a huge amount of noise that it's barely possible to handle. As long as you don't get too greedy, you can get away with a lot, simply because nobody is going to bother looking for you (hence e.g. spam).

Re: The No More Ransom Project

#149

So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…

That's great until the ransomware gets clever and encrypts your backups too.

I'm extremely skeptical of the people that say ransomware is good for the economy or whatever. Broken window fallacy. Sure it creates an incentive to protect against hackers. But isn't that a bit circular? Hackers are good because they create inventive to protect against hackers? Ransomware is by far the most economically damaging kind (and personally damaging, for all the people that lose their family photos...)

Theres a lot of blame to go around for this situation. Shitty anti virus companies that sell a false sense of security and barely work. The broken security model of windows and most software. How inconvenient and expensive it is to actually do backups, so because of most basic human psychology most people put it off... If they are even technically minded enough to know they should, and most people aren't. Programs that pollute my home folder and documents with garbage that increases the space necessary to backup (OK that's just my personal issue.)

Re: The No More Ransom Project

#150
post #70

Earlier quoted context omitted.

To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...

Oh yes, of course. Without question the superior customer support is a selfish incentive. But I still find it incredibly interesting.

I agree. There has to be an MBA case study in there somewhere. As others have said, they clearly is it as a profit centre (not cost centre).
Post reply on HN