Earlier quoted context omitted.
> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…
As someone working in infosec for a largish 2000 seat organisation - it's honestly not inaccurate. No matter how much accessible information security training we try to provide and the EDR controls we implement, >95% of our incidents involve an end-user following (sometimes extremely obvious) phishing links. And contrary to what you've said, Windows Defender (in conjunction with Airlock) has actually saved us from ra…
Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
201–210 of 229 posts
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#202As someone using a Russian keyboard, I still got my fair share of viruses back in the day, before I knew the basics of cybersecurity. I wonder how prevalent that actually is in the grand scheme of things, or if it's overblown in the article.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#203One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#204Earlier quoted context omitted.
I don't think this is done on purpose at the state level in Russia or China, It's just that sometimes government don't pay attention to those who do it if this is done in relation to somehow unfriendly countries. But the US also uses hacking for hostile purposes. For example, Stuxnet and some other cases. Yes, it's not ransomware, but the difference is not that huge. Western-backed countries like Ukraine are also doi…
When Russia arrests a hacker they're turned over to the GRU and told who to target. Western governments use hacking for intelligence gathering not economic warfare. The ochko123 fraudster was very connected with the Russian government, it's state policy. No, just using Linux doesn't make you safe.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#205> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#206> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
Not a windows user, but couldn't a sysadmin enable this keyboard but disable the shortcut to switch keyboards?
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#207If you make your machine look like a malware execution sandbox, a lot of malware will terminate to avoid being analyzed. This is just part of the cat and mouse game.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#208Earlier quoted context omitted.
> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…
Isn't "Controlled folder access" part of that protection? Also restore points?
Difficult to be effective when it's disabled by default.
>Also restore points?
By using System Restore, you can undo these changes without affecting your personal files
https://support.microsoft.com/en-au/windows/system-restore-a...
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#209Earlier quoted context omitted.
Isn't "Controlled folder access" part of that protection? Also restore points?
>Isn't "Controlled folder access" part of that protection? Difficult to be effective when it's disabled by default. >Also restore points? By using System Restore, you can undo these changes without affecting your personal files https://support.microsoft.com/en-au/windows/system-restore-a...
Thus System
> Difficult to be effective when it's disabled by default
The initial goalpost was lack of any protection / no alternatives to onedrive
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#210Earlier quoted context omitted.
There are many reasons someone might have to use Windows. I have a Windows box because a number of games I play don’t support Linux, even with WINE and Proton.
I found that ProtonDB is quite helpful in figuring out how many games will or won’t run well: https://www.protondb.com/ You can even log in with Steam and get the summary for your exact library, for anyone curious.