7 ms·
I'm actually pretty happy cryptolocker's around. No, wait, don't hang me yet, stuff your pitchforks, let me explain. Let's face it, computer security has been
by pyalot2 13y ago
I'm actually pretty happy cryptolocker's around. No, wait, don't hang me yet, stuff your pitchforks, let me explain.
Let's face it, computer security has been pretty bad trough pretty much the entire personal computing era. I don't need to point any fingers, the guilty know who they are.
Now unlike some others, Apple and Linux do try to do a few things about that, in different ways, with varying degrees of success. But it's better, by far, than the teeming mess on that other platform we won't be mentioning.
I believe if we want to use IT in the future, that this stuff's got to get pretty much bullet and foolproof. And without a credible threat it won't get there. Now, one of the things that held the development of a credible threat back, was the limited ways in which security holes could be monetized. "Fortunately" that's no longer a problem.
And now that I think we have a credible threat. Will we now, please, with suggar on top, get computer security right? Isn't like, kinda time?
- NAFV_P 13y agoI'm surprised that the NSA hasn't looked into it yet (or have they?...), with what they've been up to over the past decade.
- dredwerker 13y agoI am more worried about cryptolocker than the Silk Road or its derivatives. These people must be getting the money out somehow via the visible blockchain.
- thrill 13y agoThe article talks about mixing services. Destroy those and what little anonymity that can be had in virtual currency ceases. As for getting money out, why bother, if you take the (perhaps not that) long view that BTC itself will be generally useful.
- saraid216 13y agoWouldn't it be the FBI's job?
- ams6110 13y agoI had a similar reaction to the Target credit card number situation. Not happy about it, but the thought did cross my mind "maybe this will finally make banks/card companies/retailers take security more seriously." Not really holding out much hope though.
- vkou 13y agoWhy would they? Most of the damage (time wasted by their customers dealing with the fallout) is an externality.
- lukifer 13y agoThere are situations in which "there is no bad publicity"; a massive security breach isn't one of them. Even if customers are protected by their credit card provider, it's still a massive inconvenience at best to have your card data stolen. I guarantee Target takes a non-trivial sales hit from the incident, particularly online.
- lifeisstillgood 13y agoYes and no. Well mainly no. Crime can leech too much, do too much damage that it actually holds back development (pretty much any dictatorship, many Mafias) It's pretty likely that the major reaction to crypto locker will not be "darn it, let's breakout a can of OpenBSD on our systems." It will be let's buy more norton, let's disconnect from the Internet except Wednesdays, let's print out our important emails. Anyway I still really really struggle with how anyone can get stolen / hot money off the block chain and into their hands, cleanly. There is a limited supply of fools who will accept 10M from a Nigerian in return for laundering it.
- pyalot2 13y agoWhile I would be glad if people would stop using that unnamed OS, what I meant isn't that everybody should just hop to some *nix. What I meant is that pretty much every OS out there does security completely wrong, for no discernible reason.
- ryanjshaw 13y agoComputer science solved this problem (the "Confused Deputy" [1]) decades ago [2] [3] with capability-based security [4]. I don't have the time to find the exact reference I'm thinking of right now, but consider taking a look at one of the papers that give a background to CapDesk [5]: > Which addresses, among other things: > "All Windows and Unix operating systems (referred to as “Winix” hereafter) utterly disregard the concept of POLA [Principle of Least Authority]. When you launch any application—be it a $5000 version of AutoCAD fresh from the box or the Elf Bowling game downloaded from an unknown site on the Web—that application is immediately and automatically endowed with all the authority you yourself hold. Such applications can plant Trojans as part of your startup profile, read all your email, transmit themselves to everyone in your address book using your name, and can connect via TCP/IP to their remote masters for further instruction. This is, candidly, madness." [6] Since then, things have changed slightly - UAC under Windows, for instance, means applications now only have the ability to steal and hold your highly valuable and personal documents for ransom, but hey at least these sneaky trojans don't have admin rights! Which is of course the exact scenario that Cryptolocker happily exploits. There's really no reason a piece of junk attached to your email application should execute any more authority than you explicitly grant it. (And no that doesn't require clicking a bunch of buttons to "Allow" access -- intelligent UI design can make much of this completely transparent, provided the host platform is capability-based.) It's not that companies like Microsoft aren't well aware of capability-based security [7], it just seems to be that the appetite isn't there to really solve user's problems (breaking stuff like the Start Menu appears to be more important), despite the valiant efforts of some really smart people [8]. To be fair, shifting to a capability-based system would be a significant engineering effort, but definitely well within the realms of Microsoft or Apple's capabilities. (Interestingly, some of the ideas on erights.org were influenced by Nick Szabo, who created "Bit gold" and who a few people think might be Nakamoto himself [though he denies it] [9]) [1a] http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html [1b] http://erights.org/elib/capability/deputy.html http://erights.org/elib/capability/deputy.html [2] http://www.cis.upenn.edu/~KeyKOS/Gnosis/Gnosis.html http://www.cis.upenn.edu/~KeyKOS/Gnosis/Gnosis.html [3] http://www.cis.upenn.edu/~KeyKOS/Key370/Key370.html http://www.cis.upenn.edu/~KeyKOS/Key370/Key370.html [4a] http://www.skyhunter.com/marcs/capabilityIntro/index.html http://www.skyhunter.com/marcs/capabilityIntro/index.html [4b] http://erights.org/elib/capability/3parts.html http://erights.org/elib/capability/3parts.html [5] http://www.combex.com/papers/index.html http://www.combex.com/papers/index.html [6] http://www.combex.com/tech/edesk.html http://www.combex.com/tech/edesk.html [7] http://research.microsoft.com/en-us/projects/singularity/ http://research.microsoft.com/en-us/projects/singularity/ [8] http://en.wikipedia.org/wiki/Capability-based_security http://en.wikipedia.org/wiki/Capability-based_security [9a] http://erights.org/related.html http://erights.org/related.html [9b] http://unenumerated.blogspot.com/2011/05/bitcoin-what-took-ye-so-long.html http://unenumerated.blogspot.com/2011/05/bitcoin-what-took-y...
- wrongc0ntinent 13y agoYes, lets. In the meantime, if your data is not in at least two places, it doesn't exist. I'm a fan of three.
- willvarfar 13y agoEh, cryptolocker will get those duplicates too.
- Bootvis 13y agoHe meant physical locations. Of course keeping your data on external backups has been a good practice since forever but many lack the discipline.
- EvanAnderson 13y agoReal backup is both offsite and offline. If your backup doesn't have both attributes then it isn't backup.
- ufmace 13y agoThat's one of the real headaches of Cryptolocker, apparently. If you have automatic backups set up, the encrypted files will most likely be backed up there and overwrite the clean ones. To really be safe, you need either secure versioned backups - default Windows and MacOS backups may not work, since the drive is connected and fully accessible to the computer - or to do backups manually to media not normally connected to the computer, and notice that something has gone wrong sometime between when the infection starts and when you connect the drive. Did I mention yuck?
- wrongc0ntinent 13y ago>do backups manually to media not normally connected to the computer Yup. This is really the only 100% way to have control over your stuff, local, physically separated storage. > notice that something has gone wrong sometime between when the infection starts and when you connect the drive. This assumes a chronological/incremental order for complete backups, which in practice is lazy and not related to the value of your data. Your only enemy should be the hardware. Dealing with the ugliest virus/worm/trojan turns into a mere nuisance when you have that kind of headroom.
- PhasmaFelis 13y agoSo getting fucked by criminals now is good, because it prevents us from getting fucked by criminals in the future? I fail to see how either of those options is better than the other. Reminds me of the database crackers who claimed that publishing a bunch of innocent people's passwords was actually helping those people out by letting them know their passwords were vulnerable. Look, if I think I'm safe from being punched in the face, and someone says "we'll see about that!" and punches me in the face, they haven't done me a favor.
- dasil003 13y agoYes, because more will be at stake in the future. If we didn't have immune systems the species would have long been extinct in the primordial soup. Strong systems are built from living in a hostile and competitive environment, not from living in a utopia like the first academic computer systems lived in. We have to go through these growing pains at some point.