Live data from Hacker News

The No More Ransom Project

nomoreransom.org

201–210 of 241 posts

Re: The No More Ransom Project

#201

My mini Ask HN: Do you trust makers of security software?

Not the big ones that are well-known names in the PC market. There are quite some shady security software vendors out there, and a handful very competent ones that I trust if I have to.

Can you expand on that? Who are the good ones, and the bad ones?

Re: The No More Ransom Project

#202
post #23

Earlier quoted context omitted.

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

...it now occurs to me that if, using one of the million or so compromised ad networks, you wrote something would pop up the following message in people's browsers: "Hi there! Your computer has been infected with a virus which will encrypt one file on your computer at random each day. You can stop this, and decrypt all the files by paying X to bitcoin wallet Y. Don't wait too long, because if you wait too long, we mi…

My neighbour came to me last week to ask for help. Exactly that had happened to him, from of all things a Facebook ad. It was a simple matter of killing the browser, but it had put up a phone number for "support" that he had already called, but which was busy... so I guess they were having a fair amount of success. Wish I'd taken a photo.

Re: The No More Ransom Project

#203
post #123
post #48

For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

Dropbox has a help article on ransomware: https://www.dropbox.com/help/8408 For mass deletes that are cumbersome to recover using Dropbox's interface, that article mentions you can contact customer support to get assistance recovering from mass deletion events.

Great thank you.

Re: The No More Ransom Project

#204

About prevention there is something more that I am not sure has been mentioned, some tools are taking a new, broader approach to the problem, which is to constantly monitor for encrypted files and stop the associated processes, this way often limiting the loss to a few files, these are the links: Criptostalker https://github.com/unixist/cryptostalker Ransomwhere (macOS) https://objective-see.com/products/ransomwhere.…

Highly recommend Ransomwhere for MacOS users. It has actually stopped a ransomware attack on one of my work machines.

Re: The No More Ransom Project

#205
post #41

Is using a VM to surf the web a reasonable answer? Are there any VMs (for my MBP for example) that are reasonably fast, don't take a lot of battery, and not clumsy? Can't this be built into the OS so I don't actually have to do it?

Qubes OS actually aims at this, if you're serious about security. Of course, there is absolutely no way to completely suppress any attack surface, but compartmentalization can help.

Re: The No More Ransom Project

#206
post #191

Earlier quoted context omitted.

Exactly, but it will never be zero. There will always be scammers trying to get rich quick on the trust users have placed in the (more) honest scammers. All organized crime has to deal with some amount of posers trying to cash in on their reputation. Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Traditionally this would be breaking people's knees, and I…

> ... trust users have placed in the (more) honest scammers. > Sometimes the way they keep the dishonest guys in line is by attacking others who try to get in on the scheme. Are you really trying to frame some extortionists/scammers as honest and some as dishonest? How about they all are criminals, extorting money as they do from random people, they don't care about?

Do you really not understand the point that is being made here?

Re: The No More Ransom Project

#207
post #74

Earlier quoted context omitted.

The ransomware scheme only works because the users actually get their files back and the prices are pretty reasonable for many victims. The perpetrators spend a lot of time on the ransomware and its backend. The better it works works, the more people will pay. They rely on people like us to spread the word that it's not a scam, it's real and it works. Now that I think about it: It would really damage the whole ransom…

> It would really damage the whole ransomware scheme if there were fake / rogue versions that won't decrypt, wouldn't it? Or a single fake story about how ransom doesn't give your data back, published in a high-profile newspaper. Come to think of it, our news sources write bigger lies every day, here they could actually do some good without any risk to their own reputation.

> Come to think of it, our news sources write bigger lies every day

Unfortunately they are also cut throat with regard to each other. The first paper that does this risks the rest of them running stories about that source scare mongering and deliberately spreading panic on behalf of [insert conspiracy theory and/or unpopular agency here].

Re: The No More Ransom Project

#208

Earlier quoted context omitted.

I'm kind amazed at the tone deafness of several comments in this thread. I get that as a larger effect, reducing the success rate of scammers hurts their business, but if I'm dealing with someone who's been hit because they weren't adequately prepared, I'm gonna recommend they pay the ransom if they want their stuff back. Because I'm trying to recommend what's best for them. People could be losing their entire family…

When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it. That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if y…

> You're only safe if you have offsite backups with drives that didn't mount to your computer recently.

Or doesn't mount to the source computer(s) at all.

My active machines push backups to intermediate locations, and the true backup locations pull from there and create snapshots. Status information used to verify the backup process is passed back the other way. The active machines don't (in fact can't) authenticate with the main backups and vice versa, reducing the likelihood that someone hacking into one can easily compromise the other at the same time.

I wouldn't expect the man on the street to muck around setting this up though, but many cloud backup solutions effectively do this if they don't have an easy "delete snapshot" API call or similar. I'm surprised that the "soft offline" backup side of it isn't marketed more actively. Maybe no one thinks they can adequately explain the benefit to the man on the street without putting them off by it being a little more complicated than a simple file copy.

Re: The No More Ransom Project

#210
post #198

Earlier quoted context omitted.

Some scammers can be honest. You might say "Transfer X amount of money to me. If you don't, you can never get your data back". Saying and acting on that doesn't make you dishonest, it makes you an asshole.

That depends on your definition. Googling brings up "dishonest: not honest; disposed to lie, cheat, or steal; not worthy of trust or belief" Thus I think a scammer can be called dishonest.

A trivial application of the principle of charity makes it obvious that the meaning here intended is 'truthful'. Splitting semantic hairs rather than discussing substance benefits no one.
Post reply on HN