Live data from Hacker News

You’re infected—if you want to see your data again, pay us $300 in Bitcoins

arstechnica.com

41–50 of 295 posts

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#41

While I'd like to think I'm sophisticated enough about security to avoid this, it makes me concerned about the vast majority of people (e.g. my parents, my girlfriend) that are clueless about such dangers. Are there any recommendations of a simple way to at least enable automated backups of local documents to the cloud on a windows box?

I think that you could use Box for this pretty effectively. With their $15/month business plan, you get 1TB of storage and can apparently set any directory as a "workspace", which presumably includes the home directory. For most users, that would be more sufficient to keep everything backed up and the syncing process is supposed to be the same kind of transparent deal as Dropbox (which would also be a good solution,…

until it encrypts the workspace and that gets synced. Although, I suppose you might have a previous revision as I know dropbox supports versioning for some (all?) kinds of files.

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#42
post #15
post #9

Earlier quoted context omitted.

That i know, only MS

But note that's only due to popularity. Socially engineering your way into a user running an executable means that executable will simply run with user privs. No trickery or hacking required, no OS holes. And that will mean that the executable will have full access to do everything a user could do, which will effectively certainly include sending a new encryption key over the network, and encrypting every file that u…

OS X defaults to only running applications that have been signed with a valid developer ID. It’s not difficult to get such an ID, but Apple can also blacklist them, which would prevent the malware from running once Apple notices it. So I think the Mac has a good defense against this kind of attack.

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#44
post #40

Earlier quoted context omitted.

Look into one of the many cloud based backup providers. I don't have any specific recommendations but here's a list off the top of my head: 1. http://www.carbonite.com/ 2. http://www.crashplan.com/ 3. http://www.backblaze.com/

From the Reddit article linked above [1]: "Backup solutions like Carbonite are no good against this as they will commit the encrypted files to the cloud." You need "cold" backups to get around this without paying. [1] http://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care...

I'm assuming that Carbonite doesn't have a Dropbox-like version retention system? Or does this virus get around that?

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#45
post #40

Earlier quoted context omitted.

Look into one of the many cloud based backup providers. I don't have any specific recommendations but here's a list off the top of my head: 1. http://www.carbonite.com/ 2. http://www.crashplan.com/ 3. http://www.backblaze.com/

From the Reddit article linked above [1]: "Backup solutions like Carbonite are no good against this as they will commit the encrypted files to the cloud." You need "cold" backups to get around this without paying. [1] http://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care...

I was under the impression that Crashplan's backups included limited versioning?

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#48
post #6

I'm sorry, but if a firm doesn't compartimentalise access and a single infected workstation can bring down everything, then they deserve what they get. Hadn't been ransomware it could have very well been a disgruntled employee, to the same effect.

While you're technically right - we are responsible for our security, and we should lock down our networks just like we lock our front doors - this is basically blaming the victim.

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#49
Central to the plot in the book Reamde but these guys don't offer a 'pay in WoW gold' choice.

Given the cost of computers these days, at least in business a separate 'browsing' machine and 'business' machine seems to be the best solution. I wonder if you could provide wireless for employees to bring their own laptops which had no 'office' connectivity (but internet connectivity) and machines that were hard wired and MAC filtered to the 'business' network.

Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins

#50
post #29
post #13

The only new thing about this ransomware is that the payment method is through Bitcoin, right?

yup. But the fact they're using bitcoin shows a clever way for ransomware to collect payment with virtually zero-risk; since it's not possible(that I know of) to really trace exactly who, in real life, got those bitcoins. Which means, ransomware might make a strong comeback since the risk is now basically zero, this program isn't that difficult to write and there's real money to be made. Even if you only charged 50 U…

> Educating users to stop running random programs in zip files attached to emails, is apparently impossible.

Imagine something just like the malware we're discussing, but instead of a 72 hour timer, it's a 4 hour timer - and at the end, it pops up a "gotcha! just kidding. but if this were real malware, you would have either lost hundreds of dollars, or all your documents. Don't open attachments like me."

Post reply on HN