Earlier quoted context omitted.
It is, and it has proven very effective. Robberies against banks and stores have been cut in half during the last ten years, as cash is getting harder to access. Many store open after 19:00 don't have much cash on hand so robbing them is not really attractive any more. There are almost no bank robberies, as even banks doesn't actually have cash. The people who get mugged are normally forced to go to an ATM to withdra…
That's not a function of banning cash however, its on account of the rise of credit cards. No one sacrificed or was inconvenienced to get here, it was just natural progression with good side effects.
Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
181–190 of 267 posts
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#182Ransomware attacks against the United States should be met with covert assassinations against these hacking groups on foreign soil. Enough of this insanity - these are acts of war, and those responsible should be dealt with through covert, proportional military strikes.
These are unlikely to be acts of war. War requires state-level actors, who are interested in geopolitical changes, not piddling little ransoms.
What you’re talking about is revenge, not justice. Each of those done well breeds more of itself. Successful revenge breeds more violence and hatred, leading to more revenge; look up the history of vendettas. Successful justice breeds more justice. Societies should choose the virtuous cycle, not the vicious one.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#183Earlier quoted context omitted.
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
This level of corporate hacking existed prior to cryptocurrencies, the difference is that it was used for stock market manipulation and profiting on short or long positions. It appears that this is even more profitable than ransomware, in the hundreds of millions or possibly even billions of dollars. [1][2] [1] https://www.wired.com/2010/03/manipulated-stock-prices/ [2] https://www.reuters.com/article/us-cybercyberse…
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#184Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#185Earlier quoted context omitted.
How do you know that we’re not less secure? It wouldn’t surprise me at all if our systems are on average far less secure simply because so much more is online now, to speak nothing of increases in the complexity of and opportunities for errors and misconfigurations in today’s systems.
Because twenty years ago computer security was an absolute and utter shambles. Exploiting a vulnerability today is orders of magnitude harder than it was twenty years ago. Massive strides have been made.
Yes but once an exploit is found it can be tried on a whole lot more systems and the weakest link becomes a target. There is also a lot more interest hence brains in hacking/ransomware.
I lot of critical systems should simply be airgapped
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#186There are threats which emerge when a viability threshold is crossed and realised. For cities, recurring plauges began occurring during Roman times and limited maximum city populations to about 1 million until the advent of modern sanitation, hygiene, public health, waste removal, and food quality. (Actual medical care and treatment had little to do with this, though vaccines and antibiotics helped.) Industrial pollu…
My impression is that most of these start with phishing, and probably even tailored phishing for larger organizations. A particular phishing campaign then just needs to include an encryption key, while the decryption key is kept elsewhere; this process is still quite easy to automate.
Hell, you could even just let loose lots of malware with different encryption keys, with the decrypting keys stored in a spreadsheet. When one succeeds, display a hash of the encryption key to the victim, and have them read it back to you when they call in to negotiate. And then just look up the paired decryption key when it's needed. No need to track anything, or bother with command+control.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#187Earlier quoted context omitted.
Anticipate a problem with your IT staff leaving the write-enable switch on? Have the drive maker add a (again, physical ) clock circuit (could just be an RC delay) to turn it off again automatically. (Even if you don't anticipate a problem with your IT staff, it's just good engineering to automatically turn off the write-enable. Nobody's perfect. I've gone to the airport without my passport once. It really sux when y…
This is a system I put together at my first IT job. Backups get pushed from devices between 1AM and 3AM each day, so the primary backup server enables it's network card at 1 and disables it at 3. Primary backup server also has a second network card, that in turn is attached to a small subnet containing it and the secondary backup server only. The secondary backup server pulls a copy from the primary on a weekly basis…
One thing you could do is get one of those mechanical lamp timer clocks from the hardware store, and have it turn the power on/off the network card on schedule.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#188Earlier quoted context omitted.
> how much is this worth stopping? Having a physical write-enable switch on the backup devices costs about three cents.
And the guy required to set that all up is 100K.
If you meant write some software to activate the switch, that kinda misses the point!
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#189Ransomware attacks against the United States should be met with covert assassinations against these hacking groups on foreign soil. Enough of this insanity - these are acts of war, and those responsible should be dealt with through covert, proportional military strikes.
When was the last time covert assassinations or military strikes actually solved a problem? Mostly they inflict further suffering. Mostly they affect people other than the perpetrators. These are unlikely to be acts of war. War requires state-level actors, who are interested in geopolitical changes, not piddling little ransoms. What you’re talking about is revenge, not justice. Each of those done well breeds more of…
These are absolutely acts of war, and I wouldn’t lose a second of sleep if American lead ended up in these actors.
Covert assassinations here aren’t justice. They are deterrence.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#190Earlier quoted context omitted.
This level of corporate hacking existed prior to cryptocurrencies, the difference is that it was used for stock market manipulation and profiting on short or long positions. It appears that this is even more profitable than ransomware, in the hundreds of millions or possibly even billions of dollars. [1][2] [1] https://www.wired.com/2010/03/manipulated-stock-prices/ [2] https://www.reuters.com/article/us-cybercyberse…
Your comment makes it sound like stock markets were manipulated by hacking the companies that issued the stock. In one of your stories brokerage accounts were compromised and used to pump penny stocks. In the other someone hacked a few companies that distributed press releases to get early access to them and traded on the information. Stocks weren't even manipulated in that case, they simply placed trades based on ho…
Ransomware appears to be a less profitable and less clever use of hacking.