22 ms·
New Mac ransomware spreading through piracy
- cpach 6y agoI don’t understand how people dare to run executables downloaded from a pirate site...
- ipsum2 6y agosome people like to live dangerously.
- earthscienceman 6y agoOr. Like the world we live in, there's massive inequality and some people just don't have "I comment on hackernews" levels of money
- WrtCdEvrydy 6y agoDepends on the site, some repacks are probably nicer than the average DRM dump from ubisoft.
- y2bd 6y agoSimilarly, a cracked version of Photoshop probably installs less junk than a legal version of Photoshop.
- qppo 6y agoIt's how kids get into multimedia content creation using real tools without paying real money
- lintroller 6y agoIt's how I did. Now I'm a professional frontend developer with adequate Adobe skills and a license paid for by the company that frequently come in handy on the job.
- bredren 6y agoMe too. I distinctly remember the warez group editing the startup image of PS 6, which had the code name Venus in Furs. Apparently that was 20 years ago! Anyhow, I know that much of my early software license transgressions resulted in actual software licenses.
- userbinator 6y agolicense paid for by the company that frequently come in handy on the job. ...and now you know why Adobe products are so easy to pirate. Young pirates turn into loyal product users and customers.
- dmix 6y agoMore like they eventually join mid-size plus companies which Adobe tracks down to make them pay for their photoshop (if they detect it on a company network they will reach out). Or they simply just pay for it because they can and/or are professional/law abiding people. Adobe doesn't spend copyright enforcement time on individuals much.
- the_af 6y agoDidn't this also use to be the case with MS Windows and MS Office? I always thought they were so easy to crack, and Microsoft was so prone to turn a blind eye to pirate copies at home, because this led to employees familiar with their products at the office. And they did go after pirated software at the office.
- phre4k 6y agoIt's almost as if pirating software for home users doesn't have the negative impact the big corporations would make you believe.
- user5994461 6y agoMicrosoft gives everything for free to students, except office. Check with your university. This shall includes hundreds of software, all editions of Windows both 32 bits and 64bits, as well as all editions of Visual Studio Ultimate, plus databases and other tools.
- dylan604 6y agoThe grandparents used alt.binary.* to get software
- ogre_codes 6y agoOuch... a little too close to the truth here.
- dnh44 6y agoThat’s still going strong actually and a really convenient way to download things.
- rimliu 6y agoIt was really true back in the day, not so now. You can get e.g. Davinci Resolve for free and it as real of a tool as it gets.
- 488643689 6y agoThis is a hidden downside of having proprietary defacto monopolies in tech. As long as the Adobe suite is the default in digital content creation, piracy is the default gateway to that profession. I don't care about Adobe's loss, as they pretty much encourage the status quo, I do however care about all the people risking their digital life's integrity for this. Since it's "this is how you do it", many non-tech people are not even aware of the potential fallout. It's the same for even more problematic scenarios, e.g. students using cracked Matlab, SPSS, ... executables to crunch real study data at home. Yes, digital responsibility is ignored by those using cracked software, but really you can't ignore factual constraints and the economic situation, when talking about who's to blame.
- eckza 6y agohttps://en.m.wikipedia.org/wiki/Child https://en.m.wikipedia.org/wiki/Child
- saagarjha 6y agoNot just children.
- imtringued 6y agoThey ought to be punishmed by forcing them to play Cataclysm DDA without the wiki.
- rvz 6y agoFrom the standpoint of malware writers, the users are one Office 20XX or Adobe CC 20XX away to installing the latest 'free trial' until they search for that fake keygen.exe or 'cracked full version' and it starts encrypting their work. Adobe and Microsoft are the most targeted by malware writers unsurprisingly.
- AnthonyMouse 6y ago> I don’t understand how people dare to run executables downloaded from a pirate site... Pirate sites have reputations the same as anybody. The more reputable ones actively remove spam and malware. So it's kind of like saying, I don't understand how people dare to run executables downloaded through the internet. Depends a lot on where on the internet you downloaded it.
- milesvp 6y agoVery much this. Decades ago, when I couldn’t justify the cost of software, I generally knew what places I could trust, and what places might be more sketchy, and what places were guaranteed to infect my system. The cracking scene was very competitive, and any place that messed with the final binary would get blacklisted, making it very hard to get zero day releases from various groups. I have no idea what the landscape looks like today, and I’d be reluctant to run anything outside a vm, since I no longer know where the reputable sources are, but I’m sure there are still private trackers and discord servers where you could trust every link.
- sneak 6y agoThere’s no such thing as a private Discord. It’s not end to end encrypted, and all Discord “servers” are actually just Discord hosting accounts (and hosted by Discord), so they can always read 100% of everything. They happily ban users for sharing the wrong links, and have banned entire instances for discussing anticheating technology.
- whitepoplar 6y agoWhich are the most reputable sites?
- AnthonyMouse 6y agoIf you're looking for free software the best site I know of is debian.org, though if you use Windows or Mac you might want to check out firefox.com, libreoffice.org and gimp.org.
- Karunamon 6y agoI'd trust the average pirate to not crap all over my computer a lot more than I'd trust the average corporate software release nowadays. The former actually has to care about their reputation...
- csydas 6y agoYou've never been a part of a trusted community before? rutracker isn't some fly-by-night random tracker, it's a well established site in Russia, and the admins have been extremely communicative with users throughout virtually every governmental upset. To add some context, try to imagine if the classic western trackers had prominent links like this, for example, what.cd. Looking at the thread, the early posts correctly identified it as malware before the malwarebytes report, and even noted that the link itself violated the application post rules. It's good for malwarebytes to report that this exists, but they're focusing on the wrong parts, imho. The hash files to identify the affected file should have been the first part, then the explanation. A bit of google translate would have shown that already, rutracker users are calling to delete the thread.
- userbinator 6y agobut they're focusing on the wrong parts, imho AV/anti-"malware" has always meant "pro-corporations/pro-copyright/pro-establishment", ever since they started detecting completely clean keygens and cracks as well as "hacking tools" and demoscene productions. There is sometimes truth, like this article, but there is also a lot of FUD --- IMHO to herd users into giving up personal discretion and instead adopting centralised trust.
- boomlinde 6y ago> they started detecting completely clean keygens and cracks as well as "hacking tools" and demoscene productions. AFAIK this is usually a side effect of self-unpacking compressed executables, as produced by EXE packers. They have a property that's been useful to malware authors: they obfuscate the code. To de-obfuscate, you have to unpack, which some anti-virus vendors actually do for executables produced by common compression tools like UPX. For certain types of demoscene productions, however, a popular tool like UPX won't do if you can shave another few bytes using a more obscure packer that AV software are unlikely to have unpackers for. Once malware authors start using those same packers you'll get false positives based on signatures that are likely common to all software using them.
- 6y ago
- baddox 6y agoI don't pirate much any more, but in high school and college I was very much a digital hoarder. I ran plenty of pirated software and from what I remember never had any problems whatsoever with malicious software (that I was aware of). Of course you need to know what you're doing, same as downloading software from anywhere else.
- Polylactic_acid 6y ago> Of course you need to know what you're doing No one knows what they are doing. Unless you are decompiling and reverse engineering the whole thing you are mostly just blindly trusting its safe. Even on trusted sites people share stuff from other sites not knowing its infected.
- boomlinde 6y agoThere's something to be said for the sites that only shared scene releases from groups with a reputation to protect. Maybe in the future, trusted groups can cryptographically sign their releases to avoid tampering and minimize the amount of trust necessary.
- mfjordvald 6y agoThey have been for decades! Most scene releases that are packed will include an SFV file that contains the checksums of each of the package files so that you can check the file integrity. Obviously those can be repacked and faked so you'd have to check multiple sources to ensure you get a genuine release, but yeah the scene groups are as usual way ahead of everyone else.
- boomlinde 6y agoI meant signatures, not checksums. A signature chain would avoid the repackaging problem if the signer's public key was distributed out-of-band. Groups and distributors alike could add their own signatures to create multiple possible trust boundaries. I think the scene groups are a traditional bunch that in some respects are years behind because of it. I remember in maybe 2005 I'd still download releases that were split into floppy sized RAR files. Possibly, this tradition carried on for so long because the scene was so keen to shame groups that didn't package like everyone else. I don't know how it is now but I'm hoping they got over splitting releases.
- bobbylarrybobby 6y agoIt's not just that it was an executable. The real issue is that Little Snitch is distributed as a pkg (not that that's the developers' fault, as there's no way to implement the app's functionality with just a simple app). But distributing it as a pkg that requires installation with an admin password is how the malware takes hold of a user's computer. AFAIK it is always safe to open an app you download from the web (although the app may not respect your privacy).
- saagarjha 6y ago> The real issue is that Little Snitch is distributed as a pkg (not that that's the developers' fault, as there's no way to implement the app's functionality with just a simple app). In Big Sur, it might be. > AFAIK it is always safe to open an app you download from the web (although the app may not respect your privacy). Apps can still encrypt your disk this way.
- bobbylarrybobby 6y agoDoes apple not throw up a permission dialog whenever an app tries to access just about any part of your filesystem? Like this: https://nektony.com/wp-content/uploads/2019/11/grant-acces-documents.png https://nektony.com/wp-content/uploads/2019/11/grant-acces-d... I could be wrong, maybe it's only for certain kinds of apps.
- comex 6y agoThat’s for all apps, but only for specific parts of the filesystem, so there’s still plenty of room for apps to cause havoc by messing with everything else. This is separate from the older sandboxing feature that’s designed to fully isolate apps from the rest of the system, which is mandatory for Mac App Store apps but opt-in for other apps.
- saagarjha 6y agoMandatory for new Mac App Store apps
- pacamara619 6y agoI don’t understand how people dare to run anything but free and open-source software. Proprietary software tends to have malicious features. The point is with a proprietary program, when the users don't have the source code, we can never tell. So you must consider every proprietary program as potential malware.
- yjftsjthsd-h 6y agoThere are backdoored binaries for FOSS projects (filezilla comes to mind), and well-behaved proprietary programs.
- LadyCailin 6y agoI don’t understand how people dare to run anything but software they have written themselves. Open source software sounds good, but I don’t review each line of code myself, so we can never tell. So you must consider every program you didn’t write or review line by line as potential malware.
- saagarjha 6y agoI don’t understand how people dare run software at all. Everyone knows software has bugs, and what if it does something you didn’t want it to do?
- piratearrrggg 6y agoI've been pirating since I was 11 years old. I have never once gotten a virus or malware. I have, however, gotten a virus from a random website that popped up on the front page of google.
- Topgamer7 6y agoI knew a dude who loved to click on ads. All of them. He thought it was fun to see all the garbage people try to peddle to you. Even after I explained to him that ads can be sketchy and lead to you collecting malware.
- spideymans 6y agoIf you're gonna pirate, at least do a checksum or something.
- saagarjha 6y agoAgainst what?
- jonathanstrange 6y agoAgainst the cracked copy, of course, to make sure the DRM really has been removed. You don't want to get nasty surprises and accidentally install PACE or another Sony rootkit...
- saagarjha 6y agoHow would you know if he cracked copy you’re comparing against didn’t already have something nasty in it?
- jonathanstrange 6y agoYou wouldn't, I was joking. Sorry, I shouldn't have done thas, I was in "Reddit mode" and forgot that discussions are more sincere on HN.
- saagarjha 6y agoHa, I didn't catch the joke. Guess it seemed too much like genuine advice…
- mratsim 6y agochecksum can tell you if there is a difference but not what caused it.
- foobiekr 6y agoIt's a wonder it isn't spreading through open source packages. There is a de-drm tool that I used to use which packages some other open source. For whatever reason, I always assume people who package up software are careful about what they're packaging up, but no, as it turned out this project is not careful at all. It shouldn't have been surprising but it was. (I ended up writing my own tool. I de-drm on principle; I don't mind buying stuff, I am deeply offended when that stuff vanishes out from under me because of deliberate obsolescence and/or shutdown. Buying DRM-free is not always an option.)
- harikb 6y agoNot only that, Little Snitch of all things. I can understand if people downloaded pirated a game or word or photoshop (before they went all cloud). Little snitch is literally for the ones who are paranoid about these things in the first place
- c-c-c-c-c 6y agoDownload the program from the developer and run the keygen in a VM and copy over the license.
- saagarjha 6y agoIf they give you the keygen…
- whywhywhywhy 6y agoVery few keygens these days, there used to be a 100% safe way of getting the full Adobe Suite back in the CS6 days. Now everything is subscription based fully you have to replace the license system within most major software. So I'm told.
- jbverschoor 6y agoWe simply need better sandboxing, and on by default. In a way it’s also usable for normal people. Mac has the sandbox runner, with a configuration file. However it’s deprecated, and difficult to create. Also, not even Facebook signs all their apps. It’s funny, bc everybody is kicking and yelling against the AppStore, and the process. But it’s the only thing protecting everybody from misuse
- skinnymuch 6y agoiOS App Store? Were there any [major] issues with jailbroken iPhones running cracked apps? Especially before when jailbreaking and pirating iOS apps was a bigger portion of users and culture. It was and is a small number of people regardless. I’m not sure if that’s going to be the “reason” nothing happened. If so, it doesn’t seem like that can conclude protection from misuse.
- coldtea 6y agoBeats paying for the software they can't afford, and it causes no issue 99% of the time... It's a cost/benefit analysis... Billions of people in the developing world rely on pirated software, for one... Heck, even in large parts of Europe, at some point there would be much fewer graphic designers today e.g. if they couldn't pirate Photoshop when they were young and non-pro (and no, Gimp wouldn't be of much use, they want to learn on the industry standard)...
- GekkePrutser 6y agoI agree Creative Suite is way too expensive (at one point it was 3000 euros!) But for students Adobe was basically giving it away :) I remember getting a CD for 15 guilders at the time at the university. Which was around 5 euros.
- jonathanstrange 6y agoBack in the days when I couldn't afford proprietary software and didn't use Linux yet, I often downloaded torrents even for free software because the download was 20 times faster and you didn't have to fill out web forms and give away one of your throw-away email addresses to get the content. The crackers also often fixed bugs the developers refused to fix and removed annoying nag screens. To be honest, when I had to upgrade my Windows machine last year, I really regretted the fact that I've gone fully legit with VST plugins. It took me more than a week to deregister and reregister all the horrible proprietary DRM schemes those companies are using. That would have taken less than a day if I had used cracked versions.
- usrusr 6y agoVST are particularly nasty for a reason though, because when they have a signature sound widespread usage by freeloaders will actively ruin that sound for those who paid. Exclusivity is a feature, the inverse of network effect. Is there something like a "steam for VST"? Maybe it should exist, to ease the DRM pain for legitimate customers.
- waheoo 6y agoYou mean like a batch file with a vlc shortcut icon. I accidentally run those all the time. My eyesight sucks and win10 accessibility is dogshit. Ive done similar on mac too.
- brnt 6y agoI don’t understand how people dare to run executables downloaded from app stores..
- GekkePrutser 6y agoIn particular, I don't understand how people use pirated security software (which Little Snitch basically is). If you're going to have to trust something, it's that.
- deleted 6y ago[deleted]
- nisten 6y agoYou could say the same thing about every business that has installed Zoom.
- lovelyviking 6y ago>I don’t understand how people dare to run executables downloaded from a pirate site... But do you understand people who dare to run executables from 'proper-company' site? It's closed source, you have no idea what you are running, isn't it? As long as it's not free software in terms of FSF there is not guarantee what so ever that it's not harmful or even worse intentionally harmful. How about this one from SONY, that didn't even ask user to run? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk... or this one Amazon remotely deletes book from kindle: https://www.nytimes.com/2009/07/18/technology/companies/18amazon.html https://www.nytimes.com/2009/07/18/technology/companies/18am...
- raesene9 6y agoThere's no guarantees what you're getting even if it's open source, unless you read and understand the source code :) The set of computer users who a) have the knowledge to do security code review and b) have the time to review the programs they run is, I would expect, fairly small.
- maayank 6y ago> There's no guarantees what you're getting even if it's open source, unless you read and understand the source code :) Obligatory reference to Reflections on trusting trust [1] [1] https://dl.acm.org/doi/10.1145/358198.358210 https://dl.acm.org/doi/10.1145/358198.358210
- lovelyviking 6y ago>The set of computer users who a) have the knowledge to do security code review and b) have the time to review the programs they run is, I would expect, fairly small. Even a small number of those who understands can make a huge noise, because if comment is well grounded, it spreads exponentially by people who do not need to understand all the details. And frankly how much those who understand you really need for each project? The thing is, if you are worried you can always look, which is not the case if you have nowhere to look. Also expert is not always required just to see there is no brutal obvious harm intent, which covers a lot of cases
- wolfgke 6y agoBecause they simply cannot afford the software, they often do not have an alternative.
- stOneskull 6y agoit is getting like that. it's been mostly good up til the present time. you know, there are 'scenes', trusted crackers and communities, users giving 'thumbs up' etc. but this ransomware trend is a bit scary.
- coronadisaster 6y agoProbably not much riskier then using the mobile app stores if you have a good source.
- sys_64738 6y agoCouldn't you run the Mac equivalent of a Windows Sandbox to restrict access if you had concerns about an app?
- saagarjha 6y agoYou can, but the API to do this is considered Apple-private ¯\_(ツ)_/¯
- Kejistan 6y agoYou can `sandbox-exec`. But that probably wouldn’t be useful for a program like little-snitch, which needs rather broad permissions normally.
- jldugger 6y agoThe sandbox-exec command is DEPRECATED. Developers who wish to sandbox an app should instead adopt the App Sandbox feature described in the App Sandbox Design Guide. The sandbox-exec command enters a sandbox
- Wowfunhappy 6y agoDoes it work though?
- comex 6y agoIt works, but you have to supply your own sandbox profile (list of allowed/denied operations) and it won’t create a virtual home directory for you like App Sandbox does. I’m not sure whether there’s an easy way to forcibly enable App Sandbox, but one possibility is to compile your own sandboxed app that simply execs the untrusted one. (Sandboxes are inherited by child processes, as they must be for security.)
- oefrha 6y agoIt works, and Homebrew is a high profile example of software that uses sandbox-exec extensively (bottling CI and brew install from source build formulae in sandboxes so that build scripts can’t read/write whatever they feel like; so do tests).
- peterburkimsher 6y agoHas anyone tested whether this can be detected with RansomWhere? https://objective-see.com/products/ransomwhere.html https://objective-see.com/products/ransomwhere.html It's a program that warns me whenever programs are locking files. In practice it's a minor annoyance when using brew or pip. Similarly, Oversight tells me when my camera and mic are being used. https://objective-see.com/products/oversight.html https://objective-see.com/products/oversight.html It's a minor annoyance whenever I have a video call and plug in a microphone. But it's "for my protection", and sometimes can be useful to know whether it's really my sound settings that are the problem, or that my headphones are unplugged. These two also seem more trustworthy than anti-virus for Mac, because they don't claim to keep me safe, just warn me when there's a problem.
- spsful 6y agoExactly this. Been wondering the same thing myself.
- _underfl0w_ 6y agoI'd be very curious to audit the codebase for the tools you mentioned.
- peterburkimsher 6y agoI'd be very curious to read your review!
- nneonneo 6y agoYes, RansomWhere detects it. The Objective-See folks did their own analysis of this ransomware: https://objective-see.com/blog/blog_0x59.html https://objective-see.com/blog/blog_0x59.html
- deleted 6y ago[deleted]
- fortran77 6y agoWhy are these people trying to steal "Little Snitch" software? That's not right, either. There are no clean hands here.
- lostgame 6y agoAs Little Snitch is a tool often used for the purpose of blocking cracked apps from calling home, it should come as absolutely no surprise that Little Snitch itself often ends up pirated. 14-15-year-old me whose parents would not allow me to use their credit cards, along with the thousands like me in that situation; either have the option to pirate Little Snitch alongside whatever else they are pirating; most likely to learn how to use; or not pirate and learn at all. Piracy is a non-option for a lot of people in this critical age group who still have a great drive and initiative to learn. Blocking people like this out, stopping them, or shaming them; is stomping on our future.
- sukilot 6y agoHuh? If an app depended on remote authorization, why wouldn't it simply disable itself after a grace period? Also, piracy of proprietary software hurts free software, which is means it is worse existential harm to computing than not having access to Photoshop.
- anyyw 6y agoMy first thought was that that flow could have the potential to produce false positives, such as from spotty internet connections. This might lead to a poorer user experience, similar to how some legitimate purchasers have had with certain DRM laden games.
- comex 6y ago> If an app depended on remote authorization, why wouldn't it simply disable itself after a grace period? Because some people still use computers without internet connections – especially users of “pro” applications (widely defined, e.g. anything made by Adobe), which are some of the most commonly pirated applications. I can confirm from experience that cracks telling you to prevent the program from connecting to the Internet are a thing.
- aronpye 6y agoYou tend to get what you pay for.
- Jerry2 6y agoPlay stupid games, win stupid prizes. If you cannot afford Little Snitch or don't want to pay for it or just prefer open source, install LuLu. It's a free and open source alternative to LS application firewall. [1] You can install it through Homebrew or download binaries manually [2]. [1] https://github.com/objective-see/LuLu https://github.com/objective-see/LuLu [2] https://objective-see.com/products/lulu.html https://objective-see.com/products/lulu.html
- pram 6y agoI never understood why objective-see releases all these useful things individually. Surely a comprehensive app that had all the functions would be better?
- Wowfunhappy 6y agoI vehemently disagree! Monolith apps are the worst; a single app should focus on doing one thing well. Let's say I already own and use Little Snitch for monitoring traffic, but I want to install RansomWhere to detect malware. Do I get rid of Little Snitch even though I prefer it, or do I deal with having duplicate software on my machine?
- imtringued 6y agoI've seen some programs that are excessively modular. You can always go too far in the other direction.
- deeblering4 6y agoI appreciate the foss alternative, but at the same time it seems downloading binaries manually is also part of the “problem”. It matters a lot what site binaries are downloaded from, and a lot of average users don’t really understand the difference. I suppose as long as a human decision is involved there is room for error. Wonder if this can be solved without going 100% down the app store path.
- 6y ago
- Wowfunhappy 6y agoThey only want $50 to decrypt the files? I wonder if they actually decrypt the files for that amount or if they demand more. I keep backups, but if I somehow got hit by this, I think I'd pay the $50 to avoid losing the few days of work. (I'd have a bit of an ethical quandary about it, but I'd still probably do it if I'm being quite honest.)
- Thorentis 6y agoAaannnd that's why they only ask for $50.
- Wowfunhappy 6y agoIt’s just that all the stories I’ve heard about Ransomware in the past ask for sums of at least $500, often much more. Even if only 10% as many people pay up, they come out ahead. At $50, do they get enough scale for the endeavor to be worthwhile? This malware doesn’t appear to be particularly smart, but it must have taken some effort to wrote and seed trackers with fakes, and it will all be for nothing once Apple updates the XProtect definitions.
- altfredd 6y ago> It’s just that all the stories I’ve heard about Ransomware in the past ask for sums of at least $500, often much more. That's when they target corporations and governments. Such small amounts are nothing when those are concerned.
- rovr138 6y agoThey’re releasing for the general audience. Not targeting larger companies/governments/hospitals. If people keep downloading and installing, the fact that it’s only $50 makes it easier to justify and pay. Most people don’t keep backups. Every time I had someone close call me about a phone they lost access to and if there was anything they could do for their pictures, the only thing you could say is, do you have backups? Then direct them to someone who could mess with their hardware (if they still had it) and see what they could do. If it was a screen, they’d pay to get it replace. If it was a sketchy soldering job, they’d risk it just to get their photos, same with transferring boards, etc. If it was just paying $50 bucks, I know a ton of people that would spend they money and probably like 80% of them would then keep using their phones without backing it up.
- Shared404 6y ago> However, Chrome will see that the files have been modified, and will replace the modified files with clean copies as soon as it runs, so it’s unclear what the purpose here is. The programs mentioned run in background almost continuously, right? If the malware modifies these, couldn't they execute it themselves so they could have a non-suspicious looking process?
- hedora 6y agoSomeone emailed me my password from two decades ago, and said they were going to ransomware my box, but that my porn habits were so uniquely interesting they just had to make a collage including screenshots and pics from my webcam (in the attached pdf, presumably). They’ll delete it for $1500 BTC, which is really a steal if you think about it. Is there a chatbot I can point at this chucklehead? > I really want to pay you BTC, but my computer says bit torrent was made by an unverified developer. I called my bank, and they said to ask what other ways you can accept payment. Do you know what a “Wire Transfer” is? We’re saving up for our first house, so I have the money and Ashley won’t miss it. Is $2000 OK? Please please please don’t out me!!! And then I want it to send a dozen more of these until the scammer gives up or sends it bank account info.
- the_af 6y agoThe scammer was trying on you a variation of the plot of a Black Mirror episode, "Shut up and dance". They were counting on you being alarmed about a secret so shameful you'd turn your skepticism off.
- jackson1442 6y agoGranted, at the risk of spoiling it, the blackmail had a little bit more of a hold on the character than you might think.
- vdfs 6y agoIf you have time to play: https://m.youtube.com/watch?v=_QdPW8JrYzQ https://m.youtube.com/watch?v=_QdPW8JrYzQ
- deeblering4 6y agoLike the chat bot version of dontevenreply.com, I love it. If this doesn't exist already it really should! Simply season a mail forwarding rule to taste and watch hilarity ensue.
- stordoff 6y agoI had someone try that on me about a year ago (shortened as it was a _long_ email): > You probably noticed your device is acting strangely lately. That's because you downloaded a nasty software I created while you were browsing the Ƿornographic website...[...] If you do not do what I ask you now, I will upload this ugly video file with you ... and the stuff you were watching to several video upload sites and I will send the links to all your friends, family members and associates.[...] I think 2,000 USD is a fair price for my silence. I know you can handle to send me this money - and it is enough for me to get lost. So how do you send the cash?? Bitcoin.[...] > Ok.. so what if you decide not to pay ? Well if you want to test my patience - go on. I will destroy your social life, you can count on that. You think that visiting Police is a good idea ? Nope. I don't live in your country and I know how to stay Anonymous. I will send the compromising video to everyone you know! Just send me the 2,000 USD and we forget about the whole thing. I have family to feed too.[...] > The time starts ticking after you open this letter (I included a pixel in this message and I will know when you read it). Oddly enough, nothing ever happened.
- jiux 6y agoRiddle me this: I wonder what ROI would look like in comparison if the schemers targeted $49.98.
- crobertsbmw 6y agoIt sounds like whoever wrote this malware is just as crappy as a programmer as I am. Reassuring, I guess.
- JaggerJo 6y agoThumbs up. Pay for your damn software.
- nisten 6y agoI really appreciate you reporting this, and understand that it's too late now but you should try to keep your source anonymous in a cases like this in case they get bad publicity where they live.
- dewey 6y agoWhy would they need to keep a source anonymous if they mentioned them in a public tweet? https://twitter.com/beatsballert/status/1277557875888533504 https://twitter.com/beatsballert/status/1277557875888533504 I'd assume they wouldn't post the full name if someone sends them a private email.
- nisten 6y agoIt's a psychological matter, the more increased publicity the higher the likely hood of an illogical backclash against the person, especially if they live in places where the rule of law doesn't protect them well.
- dewey 6y agoThe likelihood of a person getting in trouble for posting information about a badly written malware in some pirated copy of a software seems very slim. It’s not like they are exposing some nation state’s surveillance plan.
- nisten 6y agoThey could be screwing over a local company that developed the malware and, it's just good journalistic practice in general to protect your source.
- deleted 6y ago[deleted]
- b212 6y agoApple puts so much pressure on security, shouldn't it be possible to block ransomware somehow on the OS level, possibly on all platforms? I mean not many apps need to modify millions of files on all drives including network drives and dongles... It should be fairly easy to spot, something like: 1. If xxx wants to modify more than 50 files in 24 hours go to 2. 2. If some of the files were modified more than a week ago or if the files are in directories across multiple drives go to 3. 3. If some of the files are images/documents it's a no go, prompt user to accept and list the affected files. I'd love something like this for my Synology, it's connected to my Macbook as a network drive and I store my backups there, if anything modifies these files without my knowledge I'm doomed. I need to access some of my backups on daily basis so it's kinda hard to disconnect te drive all the time :/
- giancarlostoro 6y agoYou may want to consider archiving some of those backups to an external drive that is only hooked up to store new data maybe? Or maybe theres something you can do for the network drive
- cutemonster 6y agoAppend-only external disk, is there sth like that? And one flips a hardware switch to start overwriting from the beginning, if disk full
- giancarlostoro 6y agoI think a network based one in theory should be capable of doing so with the right OS / configuration, but not sure about a hardware based one https://en.wikipedia.org/wiki/Write_once_read_many https://en.wikipedia.org/wiki/Write_once_read_many This is the acronym I saw on HN somewhere though, WORM. Edit: Upon further research its kind of annoying that this isn't more common for NAS / cloud storage solutions. I think some like Dropbox do keep revisions on the other hand.
- 6y ago
- pgt 6y agoIt seems to me that the way to solve the encryption ransomware problem is to impose an immutable file system at the OS level + undo for X time and to ask for permission to write files outside a regular folder, just like microphone or screen share access.
- joshvm 6y agoThe problem is that people will often grant that kind of access, particularly to pirate software. For example modification of hosts files (to prevent phoning home) is generally something that lives in /etc which requires sudo to edit. OS X will refuse to run most unsigned software anwyay, unless you explicitly allow it. Though that could (should) be in parallel with some kind of sandboxing.
- aj3 6y agoThere are two problems with that approach: 1) while this might stop ransomware as we know it, it does not fix the underlying problem, e.g. usually all the important files are in the "regular folder" anyway, so even if adversaries wouldn't be able to delete them, they still can steal them 2) privescs are cheap and abundant, which makes all localhost-based protection mechanisms trivial to bypass
- qwerty456127 6y ago> Worse, the installer package was pointlessly distributed inside a disk image file. Pirate torrent tracker forum rules often demand every single Mac app uploaded must be encapsulated in a DMG disk image file.
- varelaz 6y agoViruses & malware is the price of software piracy. If you don't have money to pay for the soft, you need to be ready to be infected with all possible consequences. It was obvious decades ago when piracy become a business. I understood piracy 10-15 years ago when price of the soft was too high for Russia comparing to US. Right now most everything is subscription based and you pay only if you get enough from it, and usually regional prices are pretty sane.
- mratsim 6y agoEven if you pay, software are packed jammed with telemetry that reports on every single thing you do (Windows 10, Amazon Alexa, Siri ...) under the pretext of "convenience" and "improving experience".
- varelaz 6y agoI'm not talking about free soft at all, it's completelly separate universe. If you choose paid soft: as for me, if you steal it you are at risk. Also you can always setup firewall and block certain type of requests. Sometimes you can even disable telemetry if that's supported.
- margorp2019 6y agojust try
- deleted 6y ago[deleted]
- numbsafari 6y agoAdmins should fix the link title. It should read "New Mac ransomeware spreading through stupidity". Installing pirated software you find "on the internet" in 2020 is the equivalent of spending a few hours in a confined space full of other people, none of them wearing masks. Don't be surprised when you get sick.