Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

421–430 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#421
post #284

Earlier quoted context omitted.

http://www.rsync.net/products/zfsintro.html

Wow, nice! How did you find that page? http://www.rsync.net/products/platform.html doesn't link to it

It was in my browsing history, somehow. No idea how I got there initially.

Re: Another Ransomware Outbreak Is Going Global

#422

Earlier quoted context omitted.

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

Is it not cryptographically possible to create a transparent provably-operational decryptor on top of something like ethereum?

Since you can't store the private key needed to decrypt the files in ethereum, I can't think of how to do this.

All blockchain state is public, since it needs to be calculated by and verified by all nodes, so there's nowhere to stash a private key without revealing it.

Re: Another Ransomware Outbreak Is Going Global

#423
post #410

Earlier quoted context omitted.

>If it gets big enough then people just hear from each other if paying unlocks the data or not. The idea would be to create "fake" ransomware that looks exactly like the real one >The best way to end ransomware is to get serious about security No matter how serious you get there always gonna be bugs, there isn't a single piece of mass distributed software in human history without bugs. That said, we should try to imp…

If forging digital signature is not that hard, then you can release some great scientific paper moving crypto decades ahead, or alternatively you can make billions.

I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/private keys; otherwise its a chicken and egg problem; how do you know what signature its the "real"; you google it and hope nobody added its own search results? Go to the official website of the ransomware developer?

Re: Another Ransomware Outbreak Is Going Global

#424

Earlier quoted context omitted.

[citation needed]

Seriously ? The whole idea is so fundamentally stupid. 1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so. 2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious choice and some…

> 1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so.

Its irrelevant, this has nothing to do with the fake ransomwares.

>2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious choice and something the ransomware author can just tell you to do.

The search results of any onion address are just as fake-able.

> 3) 3) Most people will need someone more technical to arrange the bitcoin payment anyway, these people will verify if the ransomware seems to be legit or not.

Sure, with their ransomware-detecting powers

>4) People don't magically get smarter, phishing still works if you pass the spam filters.

What has to do with anything

I got bored to keep answering, in general your points seem week which make you sound a bit too much like a ransomware creator. Probably not because you have 3 years here but otherwise you do.

Re: Another Ransomware Outbreak Is Going Global

#425

Earlier quoted context omitted.

Seriously ? The whole idea is so fundamentally stupid. 1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so. 2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious choice and some…

> 1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so. Its irrelevant, this has nothing to do with the fake ransomwares. >2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious c…

>I got bored to keep answering, in general your points seem week which make you sound a bit too much like a ransomware creator. Probably not because you have 3 years here but otherwise you do. 

Not a ransomware creator but I understand the economics at play. Ransomware is more profitable than sending spam, unless you're spamming to spread malware.

The value of individual installs has historically averaged at significantly less than a dollar each, ransomware is bringing that way up.

You aren't going to stop ransomware unless you figure out a solution to all other malware, or invent a more profitable scheme. People need to do something with their bots and ransomware is always going to make more money than spamming from bots that haven't been able to inbox anything for 5 years.

There's simply no way you'll stop enough people from paying to make viagra spam beat ransomware.

Re: Another Ransomware Outbreak Is Going Global

#426

i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…

Depends on where you live. I doubt you'd have faced any repercussions for buying that VPN subscription with your credit card, but the governments of other countries might not be so understanding. Bitcoin should exist for the same reasons Tor exists. Just because Tor is used by child predators and of little practical use to the average Western citizen doesn't negate its positive value.

I heard that the guy who invented TV thought it was going to be this amazing thing that would transit knowledge and learning like never before. After he saw all the junk they put on it, he regretted ever inventing it. The same could be said for the internet. A genius that invention that allows so much good in the world, yet the amount of mind-destroying, family-killing pornography on it makes one wonder how much better the world is with it.

I think at the end of the day, it comes down to the fact that with every new tool comes the opportunity to use it for good or evil. So I wouldn't blame the tool, but rather the person who uses it for good purposes or for ill.

Re: Another Ransomware Outbreak Is Going Global

#427

Earlier quoted context omitted.

Just because YOU cant figure out how it works, does not mean its not possible my friend. But I will say, that when you have a backdoor, and suddenly that backdoor stop providing intel/data/whatever, its usually a good indicator.

I do not know what you mean by this. Again, my point was that any backdoor is highly unlikely to stay hidden.

I point out yet again, to the Yahoo Email debacle. Google it please.

Re: Another Ransomware Outbreak Is Going Global

#428
post #410

Earlier quoted context omitted.

If forging digital signature is not that hard, then you can release some great scientific paper moving crypto decades ahead, or alternatively you can make billions.

I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/private keys; otherwise its a chicken and egg problem; how do you know what signature its the "real"; you google it and hope nobody added its own search results? Go to the official website of the ransomware developer?

The ransomware can present the key fingerprint for example.

But even without it, there are so many options, e.g. timestamp signed message on the blockchain before the release. After just one confirmed message you don't care about pretenders because people can check if the signature matches with the previous message.

Re: Another Ransomware Outbreak Is Going Global

#429
post #428

Earlier quoted context omitted.

I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/private keys; otherwise its a chicken and egg problem; how do you know what signature its the "real"; you google it and hope nobody added its own search results? Go to the official website of the ransomware developer?

The ransomware can present the key fingerprint for example. But even without it, there are so many options, e.g. timestamp signed message on the blockchain before the release. After just one confirmed message you don't care about pretenders because people can check if the signature matches with the previous message.

I think you are overestimating the technical capacities of the average randomware victim.

Re: Another Ransomware Outbreak Is Going Global

#430

Earlier quoted context omitted.

> 1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so. Its irrelevant, this has nothing to do with the fake ransomwares. >2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious c…

>I got bored to keep answering, in general your points seem week which make you sound a bit too much like a ransomware creator. Probably not because you have 3 years here but otherwise you do.  Not a ransomware creator but I understand the economics at play. Ransomware is more profitable than sending spam, unless you're spamming to spread malware. The value of individual installs has historically averaged at signifi…

Not really, ransomware is way more dangerous than selling viagra; I may want to kill you if you encrypt my data, not so much if you sell me a couple of viagra pills that don't work. When you scam someone (e.g nigerian scam) you take money from one (or a few) person only, here you are taking data from a lot of people and hoping some very few will pay; making a lot more enemies in the process, likely including state actors; which may make it a federal crime to pay such ransomwares.
Post reply on HN