6 ms·
It's kind of funny that Krebs doesn't mention the other obvious "one weird trick", which has been around for decades now: do not run your critical systems on Wi
by cure 5y ago
It's kind of funny that Krebs doesn't mention the other obvious "one weird trick", which has been around for decades now: do not run your critical systems on Windows.
- Someone1234 5y agoOr Linux: https://en.wikipedia.org/wiki/Linux.Encoder https://en.wikipedia.org/wiki/Linux.Encoder Or MacOS: https://en.wikipedia.org/wiki/MacOS_malware#Ransomware https://en.wikipedia.org/wiki/MacOS_malware#Ransomware The reality is that this problem is 90% systemic/organizational and 10% technological. You can definitely run only Linux, make the same mistakes as these Windows shops made, and get destroyed by ransomware. A lot of this problem is getting the fundamentals wrong (flat network layout/design, no/bad backup strategy, shared credentials across different classes of equipment, and too liberal inter-access). Much of which is wrong for organizational convenience and sometimes cost savings. I can look at an org without even knowing what OS they run and tell them if they're vulnerable or not, because the assumption you must make is that entry will occur at some point, and then evaluate how or to what extent it can propagate and what the costs/consequences will be. Ransomware will continue until organizations and their management are held accountable for their own incompetence/apathy/cost-cutting, that let the ransomware cripple the company. If I was on a company board I'd ask for the CEOs job if backups didn't exist or company operations shut down for multiple days/weeks, but that isn't happening.
- sodality2 5y agoI think the issue is that if you use linux you are usually smart enough to not get infected, windows users are the majority and thus get hit more. What is the term for this phenomenon? I know I read the wikipedia page for this phenomenon in the last year.
- tw04 5y ago>I think the issue is that if you use linux you are usually smart enough to not get infected I think that's an extremely poor assumption. How many people on HN run containers with "docker run"? How many of those users actually went and personally audited those containers before doing a docker run vs. just trusting someone else checked first? I can tell you first hand I've seen dozens of customers do a docker run with a public image on a system attached to an internal network without giving it a second thought.
- sodality2 5y ago> How many people on HN run containers with "docker run"? I'd hazard a guess that a far LESS percentage of linux users do so, than Windows users who would open an exe if their browser told them to and fall for other types of ransomware.
- robjan 5y agoI'd hazard a guess that more of us have done this than haven't: curl https://raw.github.com/innocent/script.sh https://raw.github.com/innocent/script.sh | sudo sh
- sodality2 5y agoI'd hazard a guess that a far LESS percentage of linux users do so, than Windows users who would open an exe if their browser told them to and fall for other types of ransomware.
- tablespoon 5y ago> I think the issue is that if you use linux you are usually smart enough to not get infected, windows users are the majority and thus get hit more. It's been a long time since "using linux" meant you're "smart enough to..." Probably around the time corporate IT departments everywhere realized Linux on x86 was cheaper than Solaris and could still get the job done.
- sodality2 5y agoFor sure, there are dumb linux users and smart windows users. But the percentage is skewed since you generally don't use linux unless you have a minimum amount of skill; especially on desktop there are WAY more non proficient windows users than non proficient linux users + windows is preinstalled on basically every consumer device.
- kelnos 5y agoAlso on the desktop the prevailing method of malware infection is probably from downloading .exe files from sketchy sites (or email attachments) and running them. Or from websites exploiting browser bugs to do OS-specific things (though I imagine these sorts of vulns are hard to come by these days). The vast majority of these are going to be Windows executables and Windows-specific things. Your random malicious website is much more likely to target Windows desktop users than Linux desktop users.
- tclancy 5y agoThat's what everyone else said up until they did.
- yjftsjthsd-h 5y agoThat malware exists for multiple platforms does not mean that it occurs with similar frequency across platforms. I strongly suspect that, all other things held equal, an org running all Linux would statistically fare better than one running all Windows. Even if that's true it doesn't justify ignoring other measures just because of your OS, but I seriously doubt that it doesn't help.
- mumblemumble 5y agoThis is one of those tricks you don't want to publicize if your goal is to increase your own security. Linux being less of an attack vector than Windows has little to do with its inherent security (I wouldn't be surprised if Windows has Linux solidly beat in this department nowadays) than it does with how many and what kinds of computers run Linux. If a company's Linux boxes mostly run production servers that are generally stateless and/or covered by a comprehensive disaster recovery policy, then there's a good chance that their response to your ransomware attack will be to laugh in your face and push the "recover" button. On the other hand, there's a decent chance that at least some of the company's Windows computers contain some critical spreadsheet that holds together some essential business process and isn't being regularly backed up. The thing is, that balance only works as long as there aren't a whole lot of organizations running all Linux. Because, if there were, then you'd start to see more of those critical irreplaceable files living on people's Linux desktops.
- yjftsjthsd-h 5y agoIt is not obvious to me how to compare the fundamental security of NT and Linux, although I give some credence to the traditional answer that >90% of servers are on Linux (i.e. there's no shortage of valuable targets) so if it were really that easy to attack people would do it. However, even assuming comparable inherent security of the OS, it is trivially true that more malware exists for NT than Linux, so for non-targeted attacks Linux is probably safer. And, of course, if you're worrying about targeted attacks (such that people knowing what you run is a problem), then OS is almost irrelevant because you need to do some serious hardening regardless.
- inetsee 5y agoSerious question: If you are really paranoid about getting hacked, or you're operating in an environment that requires hardcore security, wouldn't your first choice of operating system be OpenBSD? I have often read about how secure OpenBSD is, but I've also thought that you give up a lot of convenience in using it. I don't think my circumstances would justify switching to OpenBSD.
- WrtCdEvrydy 5y agoI'd honestly say Qubes now... just virtualize everything :D
- bluGill 5y agoUntil someone figures out how to attack virtual machine.
- ramraj07 5y agoOr the actual fix - real tested backups. Stop blaming a reasonable secure OS when almost no competitor is noticeably more secure and only happens to not be hacked much because of obscurity.
- breakfastduck 5y agoImpossible for most organisations
- miguelmota 5y agoIt might reduce attacks but no operating system is bulletproof and attackers devote more resources to the operating system with more market share. If all infrastructure running on windows changed to linux, then linux would be the new target.
- jascii 5y agoLinux has an over 90% market share on critical infrastructure like servers and cloud resources which I would consider prime targets for ransomware. Who cares about an infected workstation, reinstall and move on.