13 ms·
The Worsening State of Ransomware
- riskable 6y agoRansomware only really works due to the lack of diversity of operating systems and software. If individuals and businesses were all running different stuff it would be nearly impossible to target them en mass. You could only target them one at a time.
- ssklash 6y agoWhile that is a solution, I don't think it is the solution. Another non-solution would be removing all Internet access. Ransomware problem solved, a whole bunch of other problems created.
- slt2021 6y agoand what if employee brings infected USB drive and plugs it into computer?
- bena 6y agoYes, a complete lack of interoperability would make it really hard for criminals to target them. However, a complete lack of interoperability would make it really hard to, you know, interact with other businesses and systems. This isn't throwing the baby out with the bathwater so much as drowning the baby in the bathwater.
- verandacoffee 6y agoProbably irrelevant. There would anyway be some number N of operating systems, and a number K of computers, and the number K will always be very much larger than N. So there would be a huge possible 'market' for these criminals, even if they targeted just one of the N operating systems, as long as the number of vulnerable computers is large enough. (edit: removed some meaningless words)
- bpodgursky 6y agoEveryone who downvoted you would upvote articles about the risks of monoculture farming, without considering that the two are one and the same.
- dgellow 6y ago> These "customers," who have zero coding skills or software expertise, take advantage of a ransomware-as-a-service (RaaS) model to gain sophisticated capabilities > Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets" What a crazy world we live in, where criminal organization have a quasi-normal corporate structure and even manage a "customer" support team
- MattGaiser 6y agoIs this any different from the mafia in many places?
- deleted 6y ago[deleted]
- lordnacho 6y agoI would think organised crime orgs would have a special money laundering department, but apart from that yeah, why would it not be a hierarchy structure like any other large org?
- novok 6y agoOnce you work in a large corp and see parallels with government, you start to realize it's just organizational theory all the way down, except some use physical violence, others don't.
- mikepurvis 6y agoWait, are we talking here about the state or organized crime?
- katbyte 6y agoBoth?
- 6y ago
- nicoburns 6y ago> Gangs also have begun encrypting backup systems, including cloud storage services such as Office 365 and Drop-box. Although 56% of the firms surveyed by Sophos regained control of their data through backups, that window appears to be closing. "[Cybergangs] have realized that the ransom demand becomes powerless if you have a full backup set in place and you can revert to it," This is why our backups at work write to a storage bucket with permissions such that they can create new files but not delete old ones. I'd definitely recommend this approach to everyone who can afford the storage space.
- tgb 6y agoI want this on a simpler scale: an external drive that has a physical switch. In normal operation the switch is in "append only" mode and the drive ensures that nothing can be erased. Only when the switch is temporarily hit to a "unsafe" mode would it allow deleting to make more space. I don't know how easy or difficult this would be (I assume external drives don't typically know about filesystem-level information like this), but it would be a nice product for people with simpler needs than yours. If the backup system can write only incremental changes then the storage requirements would likely be fine for many users.
- temp0826 6y agoYep, not a new concept- https://en.wikipedia.org/wiki/Write_once_read_many https://en.wikipedia.org/wiki/Write_once_read_many
- netflixandkill 6y agoThere are USB drives that do vaguely similar things but it's all in software. It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't. For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though. You can do something conceptually similar with any sort of NAS that provides immutable snapshots as long as the management and control is effectively out of band. The out of band part is the key. Our SAN data has snapshots. The backups are written to another storage device that only has an API key to write them to B2 storage. An attacker would effectively need to completely compromise multiple admins in the organization to get at all the stages of data duplication, and frankly there is no additional line of defense for total compromise if the attacker is willing to wait for physical tape or disk swaps. Fortunately for ransomware, time is money for them too.
- xen2xen1 6y agoFunny that nightly tape backups, a very old and established technology, would pretty much fix the problem.
- GnomeChomsky 6y agoExcept then you're losing hours and hours of data during a restore. CDP, on the other hands, results in data loss of seconds only. Particularly powerful when combined with archiving in, say, AWS with tiering and object locking for immutability.
- hsbauauvhabzb 6y agoFor now. If it becomes a common mitigation strategy, malware will start detecting and corrupting those backups.
- sodality2 6y agoWrite only setting perhaps
- hsbauauvhabzb 6y agoNo, because you’re reading the local file system using the local processor, which could corrupt reads or writes. Even DMA reads won’t solve it - malware could encrypt/decrypt transparently for a period undetected, then toss away the decryption key once it’s likely that backups are no longer viably usable..
- sodality2 6y agoI mean, if the malware is in the system before backups are even set up, sure it could be broken..
- hsbauauvhabzb 6y agoNot even before, it just has to exist long enough to trash backups for a while - reverting from a month old backup would be substantially damaging.
- rectang 6y ago> Not surprisingly, dozens of major ransomware gangs now exist worldwide, including in Russia, Eastern Europe, and North Korea. To what extent should ransomware activity be considered low-grade economic warfare by nation-states who can't or won't police cyber-criminals, and thus justification for robust national responses such as sanctions?
- vkou 6y agoTo the extent that you'd be willing to cut off your nose to spite your face[1] (Impose economic tariffs on the countries in question, thus hurting your own domestic consumers, and strengthening economic bonds between the nation in question, and their other trading partners), or be willing to kill people over money (Go to war with the nation in question.) [1] This point is debatable, some people feel that tariffs are not 'both-sides-lose' games. Depending on the tariff, and the situation, I too feel that way - but neither I, nor those people hold to an orthodox understanding of neo-liberal economics. [2] [2] Which as of 2021 are the primary drivers of trade policy in the Western world. This may, or may not change in the decades to come.
- BitwiseFool 6y agoThis reminds me of privateering during the age of sail.
- alert0 6y agoThere is actually some talk in the cyber policy space about this topic. [1] In a sense, all the spam, ransomware, and banking trojans that are thrown by other nation states (or their sanctioned criminal groups) raise the noise floor for what U.S. and allies need to address. This helps mask high-skill high-impact attacks (0days) since everyone is trying to figure out how to get their employees to not click spam emails. The U.S. is kinda missing out on creating this noise for our adversaries to deal with. 1. https://www.usni.org/magazines/proceedings/2019/october/grant-cyber-letters-marque-manage-hack-backs https://www.usni.org/magazines/proceedings/2019/october/gran...
- shahar2k 6y agoto the same extent that Hollywood movies function as cultural warfare / propaganda
- deleted 6y ago[deleted]
- 7786655 6y agoRansomware provides a useful service and should be legal. Businesses with poor security practices deserve to be punished for their negligence.
- detaro 6y agoKidnapping provides a useful service and should be legal. Schools, kindergardens and parents with poor security practices deserve to be punished for their negligence.
- bena 6y agoIt also ignores the perverse game being played. Defense has to work every time. Attackers just have to get through once. That's a game that favors the attackers.
- 7786655 6y agoGame 1: Every time offence scores, they get $100 of defense's money. Game 2: Every time offence scores, they get $100 of my money. Defense loses nothing. Neither is fair to defence, but game 2 is unfair to me, and that's what's important.
- deleted 6y ago[deleted]
- bena 6y agoBut what you are advocating for is a game in which if you aren't perfect, you are harshly punished. I just hope no one ever holds you up to the standards you demand of everyone else.
- djmips 6y agoIt's a wonder our own immune systems work as well as they do...
- 6y ago
- Isinlor 6y ago> Some, including the U.S. Treasury, have promoted the idea of making it illegal to pay a ransom, though the idea has not gained widespread support. That's probably the only solution, besides the obvious ones like actually protecting the systems.
- intrasight 6y agoI'm not sure how such a rule could be enforced. But let's assume that it could. I think this would cause a huge shift in IT. For example, companies would be more eager to switch from Windows to something more secure. Or if they continued to use Windows, it would be in the form of ephemeral VMs, perhaps on AWS, that lack an attach surface area. But I would hope that financial pressure - like insurance companies not insuring unprotected systems - would have the same result without the need for regulation.
- Sebb767 6y ago> For example, companies would be more eager to switch from Windows to something more secure Windows is not inherently insecure. Executing a malicious program would work just as well under Linux. (Presumed) technical superiority does not help when it's basically social engineering all the way. Ephemeral VMs don't help too much, either. So I highly doubt this would reduce windows market share in any significant way.
- Isinlor 6y agoIntroduce obligation to report successful cyber attacks under penalty for delay. EU is already doing it. Also make a fine of 10 times the ransom for paying the ransom. Additionally introduce criminal liability for intentionally hiding a ransomware attack in order to pay the ransom. The biggest reason is to starve the attackers of incentive and resources. If you get 10 million dollars from an attack you can hire 10 people for a year to work on more attacks. But it's unlikely that companies will change anything besides reporting in their practices. People are bad at evaluating tail risks of 0.001% chance happening in their lifetime.
- hollerith 6y ago>companies would be more eager to switch from Windows to something more secure That would be true if in 2021 the alternatives were more secure than Windows, which I doubt.
- hn_throwaway_99 6y agoThe article briefly touches on this, but my belief is the one thing that may eventually "take down" cryptocurrency is ransomware. That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments impossible. Honestly, if anything, I see ransomware as probably the primary use case today for crypto besides speculation.
- monocasa 6y agoBearer bonds aren't outlawed, they're just not explicitly tax exempt anymore.
- bradleyjg 6y agoCrypto, or at least bitcoin, is not anonymous. On the contrary the payment trail is there for the whole world to see. Governments could blacklist those coins such that no exchange or legitimate vendor would ever take them. They choose not for whatever reason but not because the technology offers anonymity.
- lucasmullens 6y agoIf there's a centralized government blacklist of certain bitcoins that everyone has to follow, doesn't that defeat the point of cryptocurrency? Also a hacker could just buy something with the coins between the time the victim sends the money and the time the government is notified.
- pinkybanana 6y agoThere are already blacklists and sanctioned bitcoin addresses. It might defeat your point of bitcoin, whatever that is, but not mine... There is no universally agreed "point of BTC".
- bradleyjg 6y agoDepends on what you think the point of cryptocurrency is. I’ve heard a lot of different explanations over the years. I believe the most popular one currently is an inflation resistant store of value, which should be compatible with blacklists. As for timing, either blocking spending or tracing the transaction back to a person is equally valuable as a deterrent.
- naringas 6y ago"These "investors," who have zero industry skills or expertise, take advantage of a [insert economic activity]-as-a-service (?aaS) model to gain sophisticated capabilities" The type of billionaire individuals who by virtue of inheriting billions upon billions, don't ever have any real skills (nor the need to develop any) and yet, they live in societies (subcultures) which expect that they keep having (and making) billions upon billions. Think of descendants of descendants of founders of what are now giant corporations. They fund VC-backed startups, which they then own (by proxy). They can barely use an iPhone; let alone understand how it works or is made. Except the business being funded is a criminal enterprise, maybe their riches originally come from "shadier" dealings? My point is that the underlying principle is the same, it's a very powerful principle. This is how the market enables societies to build super complex stuff. The marketplace abstracts away the complexities. This 'principle' is a technology, it's ethically neutral.
- mikewarot 6y agoHow is it that Operating Systems don't default to a configuration that can't ever be changed by a rogue application process? Why can't the OS be write protected? Why can't the configuration also be write protected?
- slang800 6y agoUsers need to be able to edit the same files that ransomware encrypts, and differentiating between a legitimate user and a ransomware program is difficult.
- mikewarot 6y agoIf the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible. No matter what the application does, it can't access the backups in such a system.
- chefkoch 6y ago> If the backups are made by the system, and the user can't access them, and the system protects itself (and the backups, obviously)... ransomware shouldn't be possible. And if the gang get's admin rights on the box your backups are gone.
- Ajedi32 6y agoThat's a much higher bar to clear, particularly if end-users don't have admin access to their workstations.
- kemotep 6y agoEspecially since the user is the one being tricked into executing the ransomware.
- mikewarot 6y ago
- trynton 6y agoIs it possible to disable the built-in encryption in Microsoft Windows?
- chefkoch 6y agoYes, but why would that help?
- trynton 6y ago@chefkoch: "Yes, but why would that help?" Most/all of these ransomware attacks use the built-in Windows encryption.
- jasdine817 6y agoNo they don't, they usually just use common encryption library and encrypt files directly.
- Thorentis 6y agoMy prediction: Ransomware will be the scapegoat that leads the way on making the use of encryption a criminal offence. This is exactly what many governments want. Up till now, the best argument against encryption is "we can't see what criminals are doing", but that isn't very tangible for many people. Just wait until a powergrid or water treatment plant in the US is down for weeks due to being "attacked with encryption" (yes, that will be the spin), and you'll have tons of people ready to vote for the outlawing of any and all encryption without a license/backdoor/etc.
- dgellow 6y agoLet's say you outlaw encryption, what would be the impact on ransomware criminals? They will continue not following the law and do their criminal things, using "illegal encryption" (aka non-backdoored encryption).
- tw04 6y agoI doubt it, my guess is it will (understandably) be used as the scapegoat to kill cryptocurrency and/or put it under a central authority controlled by governments. Ransomware was basically non-existent before criminals had a way of being paid anonymously.
- blackearl 6y agoSocial engineering scams manage to get millions wired (https://variety.com/2018/film/news/pathe-loses-more-than-21-million-internet-scam-1203027025/ https://variety.com/2018/film/news/pathe-loses-more-than-21-...). Crypto may be more convenient and less risky, but I don't see a crypto ban stopping ransomware completely. Plus there will always be someone wanting to do it for laughs or infamy.
- echelon 6y agoThis is one of the reasons crypto sucks. I'm building a list: - Attacks sovereign currencies and ability of countries to set fiscal and monetary policy. Instead, it rewards "crypto geniuses" that got in early. I'm not sure these are the people that should have power over our elected governments. - A waste of human and resource capital that could be spent solving more important problems - Hugely bad for the environment - Lack of KYC that enables money laundering, terrorism, and other illicit activities. Including randomware attacking hospitals - Rewards pump and dump and crazy schemes like NFTs that don't contribute to innovation or the economy - Relies on cryptography to remain post-quantum safe
- toss1 6y ago>>Not surprisingly, dozens of major ransomware gangs now exist worldwide, including in Russia, Eastern Europe, and North Korea. Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets," says Alexander Chaveriat, chief innovation officer at Tuik Security Group. "They buy server space all over the world using cryptocurrency, change servers as needed, and use virtual private networks and other tools to hide their location." It is getting to the point where the threat is beyond office functions and to manufacturing, infrastructure and IOT. With the threat escalating to that genuine national security level, and often under sponsorship or blind eye of criminal govts (NK, RUS...), we are not far from the point where the appropriate response is to deliver a kinetic response - as in a cruise missile through the window.