Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

391–400 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#391

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

"Maersk is down."

They made themselves fragile to this attack. It was completely gratuitous.

They are large enough to chart their own destiny and critical enough to care deeply about it ... and they built on top of cutesy new versions of Windows that everyone knows are garbage.

How does that old saying go ?

"Fool me once, shame on you. Fool me a multitude of times, in varying circumstances, over and over and over again for two fucking decades, shame on me."

Something like that ...

Re: Another Ransomware Outbreak Is Going Global

#392

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

They should sue the pants off whoever shut down that email address. For many companies it would have been cheaper to pay than to suffer the damage that has already been done. And it would be easier to catch the culprits if people give them lots of cash because in spending the loot, they will make mistakes and make themselves visible to the police.

Now there is nothing to track until they rewrite their code and try the attack again with randomized email addrs

Re: Another Ransomware Outbreak Is Going Global

#393
Note that having a good multi-generational backup system in place for all machines, servers and laptops, would render this kind of ransomware harmless.

But the state of IT has deteriorated so badly these days because management doesn't care any more. After all why care when you can just take your severance pay and get an increase in salary and more responsibility at another company. Rinse and repeat.

It used to be that the primary job of system admins was to keep the data safe from loss. That was more important than keeping the systems running. How did we lose this?

Re: Another Ransomware Outbreak Is Going Global

#395
post #368

Earlier quoted context omitted.

The article says the ransomware affects even patched Windows boxes. Perhaps what you mean to say is, "Great. Maybe we can finally put a price on using Windows."

Patched machines are affected, but they probably weren't the initial entry point. We still rely too much on having a single line of defense.

Yes, a zero-day is no excuse for a lack of defense in depth.

Re: Another Ransomware Outbreak Is Going Global

#396
So.. ransomware authors want payments in Bitcoins. The obvious counter-attack from the governments would be to target and shut-down all services exchanging bitcoins (or other digital money) to real money. Heck, they can hack them and delete all data, so they shut down on their own.

Re: Another Ransomware Outbreak Is Going Global

#397

Earlier quoted context omitted.

This is indeed a heavily debated topic. It will cause a major headache for those who pay and will hopefully make people learn to distrust ransomware, in turn making it less lucrative. On the other hand, that requires a fair number of "acceptable casualties" so to speak. I personally think both sides of this are valid and don't know what the best option really is. It will be interesting to watch how things evolve at l…

>will hopefully make people learn to distrust ransomware, in turn making it less lucrative. Ransomware will never ever not be lucrative. Preventing people from getting their data back doesn't discourage future campaigns and primarily hurts the victims of the ransomware.

[citation needed]

Re: Another Ransomware Outbreak Is Going Global

#398
post #199

Earlier quoted context omitted.

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

If it gets big enough then people just hear from each other if paying unlocks the data or not. The best way to end ransomware is to get serious about security. In many cases, being attacked by a ransomware, is paying a low price compared to if it was a targeted attack. edit: Also, I imagine it gets easier after you wrote one i.e. many ransomewares come from the same author. So he could gain a reputation by signing me…

>If it gets big enough then people just hear from each other if paying unlocks the data or not.

The idea would be to create "fake" ransomware that looks exactly like the real one

>The best way to end ransomware is to get serious about security

No matter how serious you get there always gonna be bugs, there isn't a single piece of mass distributed software in human history without bugs. That said, we should try to improve security of software but expecting it to be THE solution is wrong.

>Also, I imagine it gets easier after you wrote one i.e. many ransomewares come from the same author. So he could gain a reputation by signing messages saying that yes, this is our ransomware, we always unlock after receiving the payment.

Forging a signature is not that hard.

Re: Another Ransomware Outbreak Is Going Global

#399

Earlier quoted context omitted.

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

It's like saying best way to fight heroin addicts is to supply market with poisoned heroin. No heroin users - no problems!

A non-strawman analogy would be to sell fake heroin that looks exactly like heroin but does nothing at all. This analogy is more exact because the resource you are wasting its the same: money (not lives as in yours)

Re: Another Ransomware Outbreak Is Going Global

#400

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

[deleted]
Post reply on HN