5 ms·
There is a theory floating about that some ransomware attacks were done purely to damage a country's infra and making money was a bonus, but not the main aim. S
by ______- 5y ago
There is a theory floating about that some ransomware attacks were done purely to damage a country's infra and making money was a bonus, but not the main aim. So the perpetrators used ransomware as a front and the real goal is to destroy and disrupt a country's computer infra.
But then we could argue ransomware is just going to bolster and make our systems antifragile and resilient against such attacks in the future, so the ransomware attacks could backfire since in the future it would be much harder to attack the US for example with other types of malware.
It also means people are going to be storing mission critical and crown-jewels type data in airgapped systems and making filesystems read-only. The data would also be encrypted and compartmented into separate containers so attacks can't affect the whole filesystem if the airgap was breached.
Thank you ransomware authors for forcing people to have better security!
- anigbrowl 5y agoFunny, I've been hearing that argument since the 1990s yet here we are. This concept isn't new, military aircraft were been hardened against electronic attack for years by limiting them to very simple software loaded from tape. There's a kind of product life cycle where people build tough robust systems with state-of-the-art technology, then those become dominant to the point where it seems superfluous, and people see opportunity in reducing inefficiency, overengineering etc., and adding new and genuinely beneficial features instead.
- petra 5y ago>> then those become dominant to the point where it seems superfluous Interesting. Can you give an example that happening over the large scale in some non-military field?
- Spooky23 5y agoApropos to ransomware, network filers. As the network gets more dangerous, old mechanisms aren’t safe to operate, so you transition to a cloud file solition.
- pdkl95 5y agoIt's just a variation of the Normalization of Deviance. See this[1] short talk by Richard Cook for a very good explanation of the mechanism that causes the transition from "robust" to "superfluous". [1] https://www.youtube.com/watch?v=PGLYEDpNu60 https://www.youtube.com/watch?v=PGLYEDpNu60
- enkid 5y agoI mean, notPetya claimed to be ransomware, but you couldn't pay the ransom, so yes, at least some ransomware is politically motivated instead of financially motivated.
- meowface 5y agoThis isn't considered ransomware, though, and I think it doesn't count and doesn't apply for this argument. It was just a disk wiping and infrastructure disruption operation by the Russian state against Ukraine that happened to appropriate aspects of some known ransomware family for deception/confusion/misdirection/misattribution/plausible deniability purposes.
- enkid 5y agoYes, that's exactly what I'm saying. It's not ransomware, but it pretended to be for misattribution. How are you contradicting what I said?
- meowface 5y agoBecause it's not an instance of politically-motivated ransomware. It's an instance of politically-motivated disk wiping. The parent poster said that it's possible the goal is not just to make money, but in this case no money could even be made. So it's just not relevant to their point. The question is if actual ransomware may be politically-motivated, e.g. if the big ransomware gangs are being encouraged by the Russian security services to generally disrupt other countries' businesses and infrastructure for geopolitical reasons. NotPetya doesn't help answer that question; it just shows the Russian government does sometimes disrupt other countries' infrastructure.
- deleted 5y ago[deleted]
- suifbwish 5y agoThe problem with recent ransomware is that they get ahold of sensitive data then threaten to leak it if you don’t pay. This is problematic because you can’t be rid of it. Depending on the gravity of the data, if you pay them it’s perfectly plausible for them to show up later and demand another payment or even force you into a perpetual payment system.
- meowface 5y ago>Depending on the gravity of the data, if you pay them it’s perfectly plausible for them to show up later and demand another payment or even force you into a perpetual payment system. Game theory-wise, though, a ransomware operator knows that a victim won't pay in the first place if they have credible reason to believe the ransomer won't stay true to their word. My understanding is that most of them genuinely want to maintain a reputation of honesty (like old-school pirates who would hold ships/items/people for ransom), despite the obvious immorality of what they're doing. In some cases this is partly due to a code of ethics/honor (like old pirate codes), but in general it's because their goal is profit, and total profit can be impacted if many victims don't believe there's any point to paying the ransom. You can see an interesting interview with a ransomware operator here: https://news.ycombinator.com/item?id=27097061 https://news.ycombinator.com/item?id=27097061