Live data from Hacker News

The No More Ransom Project

nomoreransom.org

41–50 of 241 posts

Re: The No More Ransom Project

#41
Is using a VM to surf the web a reasonable answer? Are there any VMs (for my MBP for example) that are reasonably fast, don't take a lot of battery, and not clumsy?

Can't this be built into the OS so I don't actually have to do it?

Re: The No More Ransom Project

#42
post #34

Even in an issue about software, americans pull out guns. Have you noticed how noone else does this? It's shocking and abhorrent.

Hmm, well to be honest, I wouldn't use my .45. I would probably use my Mossberg 590A Police edition 12 gauge.

Re: The No More Ransom Project

#44
post #23

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

Or better yet, only unlocks after you _haven't_ paid the bitcoin ransom in the allotted time period. If you just decrypt now it's Pascal's wager and the buy-in is $500, so most people buy and worst case scenario the guy who hit you was a dick trying to prove a larger point, but if the cultural narrative is "don't help the criminals / don't negotiate with terrorists!" then it would be rational and societally acceptable not to pay the ransom.

Re: The No More Ransom Project

#46
post #34

Even in an issue about software, americans pull out guns. Have you noticed how noone else does this? It's shocking and abhorrent.

You do realise guns have other uses other than shooting people don't you. There's nothing remotely shocking or abhorrent about guns.

Re: The No More Ransom Project

#47

Earlier quoted context omitted.

JS is not the only attack surface in a browser. There have been exploitable bugs in image parsers, font renderers, etc. Tracking is possible without JS as well. Maybe try lynx?

> Maybe try lynx? Or just use VPS when surfing the web.

Or surf from a VM on your machine.

I used to do this on linux, as I had copies of my windows VM and I would just browse from the windows box on another screen and then work from the linux one on the main screen

Re: The No More Ransom Project

#48
For protection, I put all my files I care about on Dropbox. Is that enough? It's enough for backup for most things, but I worry attackers would be smart enough to kill it and also the old revisions that Dropbox stores.

Re: The No More Ransom Project

#50
post #23

> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…

In a twisted sort of way, a person could destroy trust that paying the ransom will actually get your data back. Someone could create ransomware that will never decrypt, even after the ransom is paid. Once the victims know the dishonest ransomware is out there, that may ruin the revenue towards the "honest" ransomware.

Couldn't you do the same thing with less of a human cost by merely telling people about cases where the ransomware was unreliable, and refusing to spread the information that it was reliable?
Post reply on HN