So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…
This happens quite often at medical offices. Five and even six digit ransoms are not unheard of. On the plus side, it helps encourage Windows updates and IT responsibility.
The No More Ransom Project
81–90 of 241 posts
Re: The No More Ransom Project
#82Even in an issue about software, americans pull out guns. Have you noticed how noone else does this? It's shocking and abhorrent.
You do realise guns have other uses other than shooting people don't you. There's nothing remotely shocking or abhorrent about guns.
Only specially "firearms units" carry them.
While that's very unusual even in Europe, it goes to show that as long as not every idiot can buy a gun, things are just fine without such a deadly weapon.
That said, shooting at a range is immense fun. ;)
Re: The No More Ransom Project
#83Earlier quoted context omitted.
> For your particular case it could be the best solution to just pay - as even police departments have done before. It could be the best solution for you to pay - if you don't care that you'll finance the attacks on other people and cause more harm overall. So yes, from a purely egoistic perspective it makes sense. The question you should ask is not "is it worth paying xxx for my data?", it's "is it worth paying xxx…
But your individual case isn't going to affect their behavior. If you wanted to change the situation, not paying simply isn't going far enough. You'd need to coordinate with other potential victims or do something like this website and spread defenses. Without putting effort into organization, your thinking that you've helped others is pure egoism because these schemes only require a few people to pay to be profitabl…
In case of ransomware, criminals are exploiting the very difficulty of victims to coordinate their actions. They depend on you paying instead of solving it yourself, educating others, or even simply calling the police. In other words, they profit directly off people's short-term, selfish thinking. The advice of defaulting to not paying is sound because if enough people follow it, the whole ransom stops being viable, which makes ransomware attacks stop coming.
The same, by the way, is the tried and true way of dealing with regular, meatspace, "I kidnapped your daughter" ransom cases.
Re: The No More Ransom Project
#84This is a Windows phenomenon only right? I'd just restore from Time Machine and go along on my way.
And the "good" versions of these do things like encrypt or outright delete things like time machine before encrypting the rest.
Re: The No More Ransom Project
#85> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…
> For your particular case it could be the best solution to just pay - as even police departments have done before. It could be the best solution for you to pay - if you don't care that you'll finance the attacks on other people and cause more harm overall. So yes, from a purely egoistic perspective it makes sense. The question you should ask is not "is it worth paying xxx for my data?", it's "is it worth paying xxx…
Re: The No More Ransom Project
#86So this is what a ransom note looks like: https://d1b10bmlvqabco.cloudfront.net/attach/is23h8nx8ff3jw/... Short, blunt, helpful, clear. Pretty much what you'd like every memo you've ever gotten to be. Me, I'm a huge fan of ransom notes and Nigerian scam emails. We can learn a lot from them. I'm pretty sure that when you get one of these that you're dealing with a script. You pay .65880 BTC into its wallet, period. Th…
Sounds like an easy way to get rid of ransomware. Just spread rumors that you didn't get your files back even though you paid.
Somehow I have a feeling that wouldn't work, though. Many people would still pay.
Re: The No More Ransom Project
#87> When [you are infected with ransomware], you can’t get to the data unless you pay a ransom. However this is not guaranteed and you should never pay! What bothers me about their advice is that it is only correct macroeconomically. For your particular case it could be the best solution to just pay - as even police departments have done before. It also ignores that it is in cybercriminals' best interest to let you dec…
Sure the criminals will release your files. Just like with regular, "meatspace" ransom, only a stupid criminal would not release hostages after having their demands met. It's in their best interest to do so. But if people by default don't give in to ransom threats, the whole business model becomes unviable for criminals.
So yeah, this advice is kind of like with vaccination and quarantines - it's not just about you. It's about all of us.
Re: The No More Ransom Project
#88Earlier quoted context omitted.
Good comment. I've interacted with ransomware scammers on several occasions. Each time I couldn't help but be impressed by their operations. In one case, the scammers provided an email address for customer support once the victim paid the ransom. They were courteous, helpful and professional - more so than many customer response teams I've had to interact with in legitimate companies. To be clear, I also don't recomm…
To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...
Nope, doesn't check out.
Re: The No More Ransom Project
#89Earlier quoted context omitted.
To be fair, I think legitimate companies' customer support might be a bit more courteous and attentive if they personally stood to gain $500 from each dissatisfied person contacting them...
Hmmm, thinks back to some of the support contracts I've been involved with (or heard about from trusted friends) with "big 4 consulting firms" or "enterprise IT partners". Nope, doesn't check out.
Think of criminals doing ransomware as if it was a small startup, for which profits are strongly dependent on reputation, and where your "customer support" is actually handled by the founders themselves. They have every reason to help, because it literally keeps their business model alive.
Re: The No More Ransom Project
#90My mini Ask HN: Do you trust makers of security software?
I don't trust them to make good quality software which works quietly and efficiently in my interest.
They basically sell a security theatre product where their motivations are to popup "PROTECTED BY ____" at all times so I don't forget it exists, and to look busy - typically by scanning the same files over and over even though they haven't changed in months - and to hook into everything to add more sales buzzwords to their product.