5 ms·
The interesting part is the relatively low ransom amount. I understand it needs to be low enough to make payment an "attractive" option (at least compared to o
by tzmudzin 10y ago
The interesting part is the relatively low ransom amount.
I understand it needs to be low enough to make payment an "attractive" option (at least compared to other means of recovery, if any...). But 200 USD is significantly less than the 500 USD ransom extorted from private PC users.
Should we conclude the extortionists expect the database content to be worth less to a company owning it than a private person is willing to pay for his/her pictures, music files and documents?
- kukx 10y ago"Promises to restore the databases in return for a ransom payment are dubious, since there's no evidence the attackers copied the data before deleting it." I guess the high risk of getting nothing in return is affecting the pricing.
- matt4077 10y agoThey should do a tit-for-tat data release. Pay 1/10 of the ransom, get 1/10 of the data.
- 21 10y agoIf the data is valuable presumably it would have a backup. Many of these could be caches, or rebuildable from other sources. Many could be disposable. Since you can't really know which database is valuable and which not, you sort of average the price, since this is volume game. Or maybe he want's to give the impression that this is not very profitable, to keep others from doing the same.
- g00gler 10y agoI assume that's the case. Securing mongodb isn't rocket science, it's not all that different from any other database, so I can't imagine a business with any value has unsecured mongodb instances. What I mean is, it's pretty ignorant that just because authentication isn't on by default you don't turn it on at all. Even if you don't want to or don't think to configure mongodb itself setting up a firewall also seems to be common sense. Thus, the only reason they'd be unsecured is they're either for random tests or hobby.
- pjc50 10y agoHypotheses: - A/B testing of ransom prices will happen - the person paying the ransom is not the company but an employee afraid for their job - companies more likely to be able to restore from backup
- saycheese 10y agoIt would be really hard to run an A/B test of any meaning since the value asked and the data would both vary; to do a true A/B test there may only be one variable, the populous must be very similar, etc.
- matt4077 10y agoThe "data" (the unknown variables) always varies. That's why you need n >> 1 in A/B tests. And you are only testing one variable: the asking price.
- brianwawok 10y agoCorrect. Running a e-commerce store each buyer buys different items. You need a big n.
- saycheese 10y agoWhat is a "big n" mean? (Ask since I'm used to running valid A/B test on groups in the 1000s.)
- saycheese 10y agoThanks, though what does "n >> 1" mean? (Ask since to me it reads as gibberish and there's no way to Google it myself.)
- Karunamon 10y agoYou need more than one person to A/B test against, so n in this point is sample size.
- 88e282102ae2e5b 10y agoIt might just be as simple as $200 being a lot of money to the attacker.
- johnmcaddaman 10y agoMaybe, but the data in some of the mongo dbs listed on shodan didn't have anything good. Can't say all, but most of them were just random shit.
- emiliobumachar 10y agoFor the sake of exhausting all alternatives, it could be a not-entirely-evil criminal activist who's not trying to maximize their gains at all. The "tough love" approach to raising awareness about security.