Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

331–340 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#331
post #316

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

Backups might get you up and running again, but the new hotness is threatening to release trade secrets, competitive advantages, and embarrassing emails. Even with an ironclad recovery some people might be inclined to pay in such a situation.

True, but companies may be less likely to pay. I'm confident that our major competitors have enough ethics to not look at our trade secrets if released, and the minor ones that would don't have the ability to hide their tracks and so in court they will be shut down.

Re: 80% of orgs that paid the ransom were hit again

#332

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.

Well then, It’s starting to sound like backups aren’t what a business needs.

Re: 80% of orgs that paid the ransom were hit again

#333

Earlier quoted context omitted.

>> But it only takes one person and these huge companies employ so many people. No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site…

Notice the previous comment about developers not allowed to be admin of their own machines? On computers with a good security model developers don't need to be admin of their own machines, but that wasn't thought of.

I don’t get the point of not allowing administrator to the local machine to employees. The local machine is practically a throwaway in my opinion. Why should we care about it? The shared folder is much more vital to the business.

Re: 80% of orgs that paid the ransom were hit again

#334
post #333

Earlier quoted context omitted.

Notice the previous comment about developers not allowed to be admin of their own machines? On computers with a good security model developers don't need to be admin of their own machines, but that wasn't thought of.

I don’t get the point of not allowing administrator to the local machine to employees. The local machine is practically a throwaway in my opinion. Why should we care about it? The shared folder is much more vital to the business.

Yeah anytime a job locks admin access to a local machine I assume their network security is full of holes, and I'm usually right about that assumption.

Re: 80% of orgs that paid the ransom were hit again

#335

Earlier quoted context omitted.

I used to care for the security of my work machine. I was sole admin. No corporate crap- or spyware. I was responsible and I learned a lot. We got bought. Big corp enforced Endpoint Management and a whole barrage of corporate spyware. I am not an admin anymore. I can't even use an AdBlock solution anymore. And guess what. I don't give a damn anymore. If the device enforces an update, so he it. If I have to double app…

I have a direct A/B experiment on this: I have one work laptop which is centrally managed by big-corp IT (I'm not the admin), and one laptop which is a project machine which I manage and admin. Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machin…

Preach! I have the same issues,but my last place had me as IT for the whole (small) shop, and when they outsouced IT ('we need you on important_thing') they had me install all of the Corp Spyware (because 'why would we ask them to send their own techs, then we would have to wait for them to schedule us in, you do it- it'll be faster!) and I watched with Despair as all resources went to AV (gotta love that Norton 360, so secure), key-logging, sending everything out by the millisecond. It was like watching a dumpster fire.

I kept my machine as it was, explaining that if anything happened to those units (bad updates, blah blah), mine would be unaffected and mine was completely necessary.

Lo, and behold! That very day everyone was complaining how slow their computers were, how even basic websites now took ages to load, and they did.

The owner refused to admit he made a bad decision and stayed with that 'IT' 'company' for over a year, and didn't get rid of them until I'd left and no one was available who could triage, and they saw just how little that 'company' did, and just how much I was made to cover for them

Re: 80% of orgs that paid the ransom were hit again

#336

Earlier quoted context omitted.

And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees. Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but…

"I have seen unpstanding guys rub magnets over hard drives over pure apathy." Open up a spinning rust hard drive and you will find two very strong magnets inside, positioned opposite each other.

This isn't why it didn't work though: disks tolerate smooth magnetic field gradients just fine. To wipe them you want a chaotic, noisy electromagnet.

Re: 80% of orgs that paid the ransom were hit again

#337
> 80% of orgs that paid the ransom were hit again

This isn't true and I'm not sure why people think it is. This is not how the world works. Ransom crews are not cartoons, they are people like the rest of us running a business.

At a very high level, sure, ransom paid then they might be 'hit again' by a random hacker testing the defences next year. Is that 'hit again'? 'Hit again' is not 'ransom again'

If this is cookie cutter ransomware that's automated and you pay an automated system to un-encrypt. Sure the worm or what not will attack again is you don't fix that worms hole.

This has zero to do with REvil and all the famous ransom crews that the title implies. That should be pretty obvious.

Re: 80% of orgs that paid the ransom were hit again

#338
post #144

Earlier quoted context omitted.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

There are people who would.

Re: 80% of orgs that paid the ransom were hit again

#339

Earlier quoted context omitted.

I have a direct A/B experiment on this: I have one work laptop which is centrally managed by big-corp IT (I'm not the admin), and one laptop which is a project machine which I manage and admin. Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machin…

If a developer needs to be admin to do their work the os needs a better security model.

That's highly dependent on the type of development work. I'm a kernel developer and I need regular access to privileged components of the system for a wide variety of reasons. It could be argued that all standard *nix/windows/mac systems need a better security model to better isolate specific tasks, but for much of what I need to do (e.g., create, modify file systems/boot loaders/kernels, ptrace processes, etc...), if I'm allowed to do it at all, I can get anywhere else anyway, so I may as well just have full admin and save everyone some headaches.

And I'd argue this isn't only true for kernel development. In some cases, sure, but certainly not enough to make such a blanket statement.

Post reply on HN