Earlier quoted context omitted.
When Transmission had an infected release a couple of months ago, I remember reading that the malware had in-progress features to encrypt Time Machine drives. It gets installed, waits a couple of days, locks up your hard drive and any backup drives that you connect, and there's nothing to do about it. That's enough to hose 99% of users, even the ones following traditionally sufficient practices. You're only safe if y…
> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or doesn't mount to the source computer(s) at all . My active machines push backups to intermediate locations, and the true backup locations pull from there and create snapshots. Status information used to verify the backup process is passed back the other way. The active machines don't (in fact can't) authenticate…
The No More Ransom Project
221–230 of 241 posts
Re: The No More Ransom Project
#222How can a ransomware infect my computer when I visit a website? This site claims it can happen. I understand how the attachment version works but not this one. I'm a security newb.
Some websites can use security vulnerabilities in different parts of the browser (rendering, image format parsers, Javascript, PDF, fonts, and everything else supported by the browser) to run code on your machine.
Re: The No More Ransom Project
#223Is using a VM to surf the web a reasonable answer? Are there any VMs (for my MBP for example) that are reasonably fast, don't take a lot of battery, and not clumsy? Can't this be built into the OS so I don't actually have to do it?
Re: The No More Ransom Project
#224Earlier quoted context omitted.
> It would really damage the whole ransomware scheme if there were fake / rogue versions that won't decrypt, wouldn't it? Or a single fake story about how ransom doesn't give your data back, published in a high-profile newspaper. Come to think of it, our news sources write bigger lies every day, here they could actually do some good without any risk to their own reputation.
> Come to think of it, our news sources write bigger lies every day Unfortunately they are also cut throat with regard to each other. The first paper that does this risks the rest of them running stories about that source scare mongering and deliberately spreading panic on behalf of [insert conspiracy theory and/or unpopular agency here].
Re: The No More Ransom Project
#225Earlier quoted context omitted.
That depends on your definition. Googling brings up "dishonest: not honest; disposed to lie, cheat, or steal; not worthy of trust or belief" Thus I think a scammer can be called dishonest.
A trivial application of the principle of charity makes it obvious that the meaning here intended is 'truthful'. Splitting semantic hairs rather than discussing substance benefits no one.
Re: The No More Ransom Project
#226Earlier quoted context omitted.
> You're only safe if you have offsite backups with drives that didn't mount to your computer recently. Or doesn't mount to the source computer(s) at all . My active machines push backups to intermediate locations, and the true backup locations pull from there and create snapshots. Status information used to verify the backup process is passed back the other way. The active machines don't (in fact can't) authenticate…
The problem is, the file can get locked and still be available for backup. Smart enough malware will send an encrypted version when accessed over LAN while local access is unimpeded for some time. There is a reasonable chance that your backup will end up with encrypted files. This is why you need more than one.
Re: The No More Ransom Project
#227Earlier quoted context omitted.
Not the big ones that are well-known names in the PC market. There are quite some shady security software vendors out there, and a handful very competent ones that I trust if I have to.
Can you expand on that? Who are the good ones, and the bad ones?
Identifying good vendors and products is generally harder. I've heard good things about canary.tools and bromium, for example. Both explain what they do in terms that don't make a techie roll their eyes (too much at least): https://canary.tools/#how-it-works and https://www.bromium.com/advanced-endpoint-security/our-techn...
A good (but not exhaustive) test is to look at what the vendors promise. If they promise you full protection of your machine or network, you know they are full of shit. If they talk only about one aspect (identifying attackers, reducing the attack surface on a browser), things start to look better.
Re: The No More Ransom Project
#228Earlier quoted context omitted.
That's great until the ransomware gets clever and encrypts your backups too. I'm extremely skeptical of the people that say ransomware is good for the economy or whatever. Broken window fallacy. Sure it creates an incentive to protect against hackers. But isn't that a bit circular? Hackers are good because they create inventive to protect against hackers? Ransomware is by far the most economically damaging kind (and…
I saved my dad from ransomware using the Crashplan backups I set up. Ransomware can't retroactively encrypt remote (incremental) backups (unless they hack the service). Admittedly, I now realize they could have deleted them, so I need to enable the password protection in the app, so nothing can be changed without the password. However, I don't think it's worth it for the builders to invest in that: the number of peop…
Re: The No More Ransom Project
#229Earlier quoted context omitted.
They have to weigh in the risk of getting caught, especially if they piss off enough people. So one paying victim may not be enough for a criminal to go this route.
They are probably located in a country where it is easy to bribe the policemen, and factor that into their cashflow calculation.
If there's no police protection for the victims there's also little police protection for the criminal.
If I were a ransomware scammer I'd rather be caught and jailed than killed by irate victims or competing criminals.
Re: The No More Ransom Project
#230So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…