Live data from Hacker News

University pays $20,000 to ransomware hackers

bbc.co.uk

71–80 of 80 posts

Re: University pays $20,000 to ransomware hackers

#71
post #45

Earlier quoted context omitted.

If you search online Mac forums many people ask how to disable such features. For average joe and jane security is a nuisance.

Most of the people I know still keep it on. It also makes the user think a bit before clicking through the scary warning.

Many people just click away at every dialog that disturbs their workflow, specially if they are made to look similar to the real ones.

That is how many of these exploits work, regardless of the OS.

Re: University pays $20,000 to ransomware hackers

#73

Earlier quoted context omitted.

The Mac makes this so easy with Time Machine. Is there something that's equally easy and effective in Windows?

Why couldn't the ransomware encrypt your Time Machine drive as well?

Don't keep the drive always connected and you're fine

Re: University pays $20,000 to ransomware hackers

#76

Easy solution - the government writes into law it's illegal to pay ransomware hackers. Sure hackers might get the occasional payee after this but the likelihood goes down dramatically removing much incentive, especially for larger organisations to be targeted.

The ransomware would still be about. Even if the US banned paying, there are other countries.

Re: University pays $20,000 to ransomware hackers

#78

Earlier quoted context omitted.

The Mac makes this so easy with Time Machine. Is there something that's equally easy and effective in Windows?

Why couldn't the ransomware encrypt your Time Machine drive as well?

It certainly could do this. I don't think Time Machine protects its data in any way.

Backups have to be coupled with some kind of way of noticing that something is wrong. If the ransomware encrypted your data slowly over the course of months and you didn't notice you might be out of luck regardless of your backup system.

Re: University pays $20,000 to ransomware hackers

#79
post #52

Ranked 151-200 in the QS rankings for CS. I bet if they handed this problem over to the CS people in the university they would have willingly helped them out to fix it. Information security is even listed as one of their main research areas. http://www.cpsc.ucalgary.ca/cpsc_research they even have some labs that does infosec http://icis.cpsc.ucalgary.ca/ http://ispia.cpsc.ucalgary.ca/ I bet the people at the CS dept…

You missed this quote under the picture: "University IT workers tried to crack the ransomware for more than a week before the payment". BTW, are you implying that a strong CS university can break asymmetric encryption? Why is everybody assuming that hackers are stupid all the time, and only they are smart...

RSA has some tools to assist with decryption from a few ransomware flavors. I would assume a few of the other big security firms do as well. We did this for a hospital that got hacked. It is not 100% successful and depends on the variant but is possible.

Re: University pays $20,000 to ransomware hackers

#80
post #17

The most interesting part of the article was that some ransomware sites have threatened to publish their files if they don't pay - no backup strategy will save you there.

But consider the University of Calgary's actions in response... they publicly announced the outcome of these events in the interest of transparency.

Wouldn't it be more transparent to just allow their files to be published?

Surely there are damages that could be caused, but as a public institution, I feel like this is the way they should operate by default.

Post reply on HN