Live data from Hacker News

Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

ciphercue.com

91–100 of 101 posts

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#91

Earlier quoted context omitted.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

That does not work. They just infect you and do not demand a ransom for a few months as they encrypt all your data going to the backup. Now your backups are also encrypted going back multiple months and you have to discard months of work.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#92
post #91

Earlier quoted context omitted.

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

That does not work. They just infect you and do not demand a ransom for a few months as they encrypt all your data going to the backup. Now your backups are also encrypted going back multiple months and you have to discard months of work.

I guess I should set up a monitor alerting me if the two backup diffs are larger than 80% of the data size.

But yes, these are the practical problems we need to address.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#93

Earlier quoted context omitted.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

> It does not.

Yes it does. A little bit of application control, network segmentation and credential hygiene (including phishing resistant MFA) go a long way.

> The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware,

Why are you letting employees execute arbitrary software in the first place? Application allowlisting, particularly on Windows is a well solved problem.

> not to mention AI agents.

Now this is possible only through criminal incompetence.

> And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets.

Relatively rare, likely to be caught by publisher rules in application control and even if not, if the compromise of a handful of endpoints can take down the entire business then you have some serious, systemic problems to solve.

> And no, backups aren't the solution either, they only limit the scope of lost data. In the end the flaw is fundamental to all major desktop OS'es - neither Windows, Linux nor macOS meaningfully limit the access scope of code running natively on the filesystem. Everything in the user's home directory and all mounted network shares where the user has write permissions bar a few specially protected files/folders is fair game for any malware achieving local code execution.

Why are you giving individual employees such broad access to so many file shares in the first place? We’re in basic hygiene territory again.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#94
post #88

Earlier quoted context omitted.

I don't think this helps anybody. There will always be some poor soul taking the blame for the crimes of the higher ups. And what exactly the crime would be? Using company money to pay an unspecified third party? Also pretty hard to enforce.

It should be a crime to knowingly transfer money to criminals for any reason. And it wouldn't not hard to enforce: offer bounties to whistleblowers who turn in their colleagues.

It likely is in many places, under laws relating to dealing with proceeds of crime, but I’m not aware of any prosecutions having ever been made on this basis.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#95
post #47

Earlier quoted context omitted.

I work in the state government space. Many targets/victims of ransomware are small/local government agencies and the ransom demands are greater than their annual budgets. Not every agency is big enough to have someone (bored) come in on Sunday, notice stuff getting encrypted and then run in to the server room and hit the big red button like Virginia's legislature in 2021[0]. Many ransoms are far more than the victim…

Most local governments lack the scale and budget to competently maintain their own IT infrastructure. It's not just security but everything. They should outsource the infrastructure layer to a large contractor, or possibly to the state government.

Contracting IT services at that level overpays by a whole number multiple for worse results because the government doesn’t have the in-house expertise to tell when the contractor is doing something wrong. (This is one reason why many construction projects go over budget: someone saved by laying off the engineers, so they pay 2-3x more for contractor A to oversee contractor B, guaranteeing 3+ party disputes for every problem)

What does work better is outsourcing an entire function: if you pay Gmail for email services, you know exactly how much it will cost per user and have an SLA for problems which they can’t blame on you.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#96
post #90

Earlier quoted context omitted.

Please don't. It's bad enough that companies running windows have all the data on win premises. Dumbing down what the users can do with their machines seems like the end of personal computing.

I don't think Android is "dumber" or less capable than Windows. In many ways the application sandbox actually gives owners a lot more control over their devices than a less locked down OS would, allowing them to restrict what information installed applications are allowed to access. But what I think you're concerned about (and I agree) is that the flip side of that is that giving device owners more control over their…

I see your point, I do. It seems like all external software is going in the SaaS direction, where the vendor is keeping all of the data, so they are available over an API. So there are genuinely solid cases for Chromebooks.

The issue is how much power this gives to the vendors. I think we should be able to survive a vendor going poof, taking all our data with them. Having a general computing platform capable of mixing files and privileges seems to me like the only way of keeping this capability.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#97
post #43

Earlier quoted context omitted.

OK I agree basic security hygiene removes ransomware as a threat. Now take limited time/budget and off you go making sure basic security hygiene is applied in a company with 500 employees or 100 employees. If you can do that let’s see how it goes with 1000 employees.

And just as dangerous: 50 employees. Because quite frequently these 50 employee companies have responsibilities that they can not begin to assume on the budgets that they have. Some business can really only be operated responsibly above a certain scale.

Depends on the organisation.

A law firm with 50 employees who use nothing but Microsoft Word, Outlook and a SaaS practice management application is really easy to button up tight, though they probably don’t have any inhouse IT and the quality of MSPs varies wildly.

A company of 50 software developers is an enormous headache.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#98

Earlier quoted context omitted.

Don't worry, ransomware already existed before BTC. The ransomware demanded Ukash and Paysafecard instead.

That seems disingenuous. Crypto made ransomware much easier.

That is true! The sums got bigger and the market for crypto is more liquid than for PSC.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#99
post #39
post #28

Stopping Ransomware is trivial if governments knew where the money goes. But cryptocurrencies and lax capital control pushed by the uber-rich makes it impossible. The technology is there and it is used to track the average citizens every move. But when it comes to rich people then the money goes and comes without control (and without taxation). Cryptocurrencies are a great solution to enable criminal activity. Their…

It is far from trivial. What are you going to do if the money goes to an enemy country? And while cryptocurrency are certainly popular with criminals, it is far from the only option for hiding transactions. As for the technology, if it exists, it is not very effective. The shadow economy is going strong even among average citizens, from drug trade to babysitting. If governments can't stop even the most trivial kind o…

> It is far from trivial. What are you going to do if the money goes to an enemy country?

Who send it?

> And while cryptocurrency are certainly popular with criminals, it is far from the only option for hiding transactions.

Start by removing the cryptocurrency option, that's an easy win. Go after other options afterwards. Removing cryptocurrencies is not going to stop all the crime but it will stop a lot of it and push criminals to more risky and easy to trace ways of getting money.

> how to you expect them to stop well organized international gangs, sometimes backed by nation states.

Removing their financing like cryptocurrencies. All that you say is that crime is impossible to stop. Bollocks. Start by banning Bitcoin and other crypto-crime-enablers and continue from there.

You gave zero arguments to why cryptocurrencies should not be banned.

Post reply on HN