Live data from Hacker News

The ransomware surge

bbc.com

61–70 of 216 posts

Re: The ransomware surge

#61
post #3

This is going to be the rationale given for the heavy-handed cryptocurrency regulation they're going to bring down on all the exchanges that US persons can access. Pretty soon all you'll be able to legally access as a USian is "Bitcoin!(tm)"[1] (like what PayPal is doing), not the actual uncut blockchain bitcoin that you can send and receive at will. [1]: https://www.epsilontheory.com/in-praise-of-bitcoin/

Already happening with 'unhosted' wallets being blocked or heavily scrutinized. My personal experience is as follows: Sent over 20 transactions from US exchange -> US exchange and no problems. Sent a single transaction from my unhosted software wallet -> US exchange, and got my account locked. Questioned on everything including my employer's information, had do re-do advanced KYC, source of funds etc. (The unhosted w…

I wonder how exchanges know each other's addresses? Don't they tend to use a new address for every incoming and outgoing payment?

Do they have private API's to verify addresses?

Re: The ransomware surge

#62
post #8

Earlier quoted context omitted.

Absolutely this - most ransomware attacks are pretty unsophisticated. You don't need privilege escalation, or an exploit. You can carry out the attack using just basic user permissions. You are exploiting a basic "problem" of most modern OSs (that apps run "as" the user executing them) - the user/group permission model ceases to work in 2021 with non-expert users. Portal-based access to individual files via secure OS…

I would like to see rate-limiting built into OS's. Eg. an application is only allowed to touch 100 files per second or 1000 files per hour. When it reaches those limits, it gets paused and a popup asks the user if this application really should be doing X. Then at least ransomware can't run through stuff too quickly.

Indeed - I think Windows Defender dabbled in offering this as a feature. I at least recall seeing programs prevented from creating files in the Desktop or Documents folders.

A rate limit, with group-policy controllable "automatic response" would perhaps help - you need the GPO integration though so that an IT admin can say "never allow file system rate limit to be exceeded".

If you enforce a rate limit locally, and on the network, and move to copy-on-write filesystems, it would be a whole lot harder to cause straightforward harm (at least while migrating to a newer, safer OS architecture paradigm, where code doesn't run as the user).

In the post-Covid world, I think MS and others have a whole host of these kinds of issues to think about - Windows in an AD environment is still (as far as I know) not something really geared for working off-prem. It still relies heavily on LDAP and CIFS etc. A re-write to get a desktop OS ready for the "web first" world (where everything is sent to the AD domain TCP/443, using HTTPS, with client certificates rather than passwords, stored locally via hardware-backed secure storage, and trusted CAs used by the DC) would be a big first step towards this. Yes, I know you could use Direct Access or whatever MS has butchered into the system, but in a world moving to zero trust, MS needs to move to zero trust.

Rate limits would be a great starting point, as would some proper platform-level protections around preserving shadow copies, using copy-on-write, and locally preserving versioned user files as a priority. As soon as a ransomware attack touches the network, IT should be able to handle it, as their backup regime should take effect. At that point, if you don't have backups sufficiently separate from user-writable files (or you never validate them, and thus don't realise you're backing up transparently encrypted ransomware'd files for months), you're on your own!

Re: The ransomware surge

#63
post #10

Ransomware wouldn't be a problem if the software industry took quality assurance seriously (or was regulated to do so), like every other engineering industry. There's little difference to me between an insecure program that allows hackers to hold your data for ransom, and a defective home appliance that occasionally starts electric fires.

Well every home appliance could easily start a fire if random malicious actors got to fuck with it while it was plugged in. You'll note that other engineering disciplines would also fall apart if hostile actors were constantly throwing explosives at the things they make 24/7.

Things that are exposed to an adversarial environment are usually engineered with that in mind. Locks are (usually) designed to be hard to pick, for instance.

Re: The ransomware surge

#64

Exchanges are good at blacklisting BTC ,so this means it will be hard for hackers to cash out. Just converting BTC into XMR is not a trivial process, as it needs to go through an exchange. Trustless cross chain transactions are still in infancy .

Then why do the hackers keep asking for BTC?

Re: The ransomware surge

#65

The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…

I agree with what you are saying, but calling it a people problem makes it harder to solve. If you organization is large enough than your users will always click on phishing links and download sketchy malware toolbars. You should also expect to an lesser extent that your internet facing infrastructure will have vulnerabilities that will be exploited before you are aware of them.

These are facts of life and need to be expected. Not saying that security training is wasted money, but it is in no way a solution to for example phishing. Accept that you will have compromised clients and internet facing servers and start making a strategy with that scenario in mind.

Re: The ransomware surge

#66

Exchanges are good at blacklisting BTC ,so this means it will be hard for hackers to cash out. Just converting BTC into XMR is not a trivial process, as it needs to go through an exchange. Trustless cross chain transactions are still in infancy .

Then why do the hackers keep asking for BTC?

becase BTC is the most common and there are still ways to obscure the audit trail, but the efficacy of such methods is declining.

Re: The ransomware surge

#67

I think it is likely that there will be a real world kidnapping where the kidnappers demand a Bitcoin ransom. Once this happens, Bitcoin will get rapidly regulated out of existence by governments. Imagine if it follows the usual stereotypical news coverage. An attractive, photogenic American woman goes to a foreign country and gets kidnapped. Later the kidnappers send ransom demands with a Bitcoin address. This would…

You're at least four years too late. https://www.vice.com/en/article/zmvn44/kidnappers-around-the...

They've since moved to more anonymous platforms. https://www.reddit.com/r/Monero/comments/ae4keu/kidnappers_d...

Re: The ransomware surge

#68
post #16
post #7

Earlier quoted context omitted.

Personally, I don't see the problem. 1. Bitcoin drives up GPU costs. 2. Bitcoin makes it ridiculously easy to commit certain forms of crime. 3. And Bitcoin's energy footprint hurts the planet.

4. It snuffs those pesky troublemakers and brings them back in line through monetary inflation across generations.

Bitcoin has been around for less than twenty years. Since then it has seen massive deflationary periods (when the relative value rises, like up until a month ago), and massive inflationary periods (when the value drops) In 2018 bitcoin had an "inflation" rate of roughly 500% (meaning that at the beginning of 2018 you could buy a basket of goods with an equivalent value of $13.5k USD, at the end of the year you had to spend 500% more bitcoin to get the exact same basket of goods. Meanwhile you only had to spend 2-3% more USD to get those same goods)

The fact that there aren't bitcoin loans is proof that it is not a viable store of value.

Re: The ransomware surge

#69

Earlier quoted context omitted.

Then why do the hackers keep asking for BTC?

becase BTC is the most common and there are still ways to obscure the audit trail, but the efficacy of such methods is declining.

most recently the twitter hacker was arrested after failing to use a btc mixer

https://ciphertrace.com/twitter-hack-update-blockchain-analy...

https://www.theverge.com/2021/3/16/22334421/twitter-hacker-b...

Re: The ransomware surge

#70

I don't get why everybody cares so much about the ransomware/cryptominer part, but not the data being exfiltrated and sold/used for criminal activity part..

This attack is most effective against victims without backups who are desperate to get back their data. If you have backups, you basically shrug it off, restore your data, (re)train your users and use forensics to mitigate any obvious weaknesses. In most cases, it takes less effort for the attackers to move on to the next victim instead of trying to extract value from any data they may have exfiltrated (probably none in a lot of cases).
Post reply on HN