6 ms·
Every article on security ends with: * Update your anti-virus software * Apply all software updates * Pick a hard password Rarely do these matter: ransomware
by CharlesMerriam2 13y ago
Every article on security ends with:
* Update your anti-virus software
* Apply all software updates
* Pick a hard password
Rarely do these matter: ransomware, Target, etc., are exploits unrelated to these defenses. Why do we push them so hard? Does anyone feel safer and more righteous from advocating this security theatre?
- itchitawa 13y agoIndeed. Or even "don't click on suspicious emails or visit suspicious websites" which are actually always harmless. How about simply "don't run a program you don't trust" and we wouldn't need virus scanners at all.
- TrainedMonkey 13y agoThat would exclude me from using dominant majority of the software I use daily.
- itchitawa 13y agoOr at least cause you to consider the risk of loss compared to the value of using the software while not panicking when you receive a spam email with a suspicious looking xls file attached.
- lurkinggrue 13y agoDon't run unsolicited software.
- bloaf 13y agoMost people are pretty bad at deciding which programs are trustworthy.
- garrettgrimsley 13y agoAre drive-by-downloads no longer a legitimate threat?
- graylights 13y agoDepends if you have java plugin enabled
- garrettgrimsley 13y agoWell, I just checked and found information about Java being disabled by default in Firefox and Chrome. The only resources I found on IE were about how it is difficult to disable. Because of this, I am going to assume that it is enabled by default on IE. Correct me if I'm wrong. IE has about an 18-20% share of the browser market [1]. A significant amount of targets by any measure! So as long as it is true that a large percentage of the target market could benefit from "Don't visit/view!" security advice then it makes sense to include such advice. [1] http://gs.statcounter.com/#desktop-browser-ww-monthly-200807-201401 http://gs.statcounter.com/#desktop-browser-ww-monthly-200807...
- meowface 13y agoJava's sandbox is no more secure than it was before, but because of Firefox and Chrome adding in a ton of mitigating features like requiring "click to play" by default, disabling it as soon as it goes out of date, and Oracle adding the same features internally, it's definitely way less of a threat right now. Drive bys are still of course possible via Adobe Flash and Reader exploits, the occasional IE exploit, and the rare Firefox exploit.
- theandrewbailey 13y agoDepends on who's measuring. IE has over/about half of the browser market. Corporate cubicle farms are dominated by IE, as are aunt's, uncle's, and grandma's computers. http://netmarketshare.com/ http://netmarketshare.com/
- muyuu 13y agoAnd if you are a cybercriminal, learn the difference between 128 base-10 digits and 128 bytes.
- spoiler 13y agoNot to nitpick, but a string of 128 digits is technically still 128 bytes long, assuming ASCII/Latin digits! I guess, the parent of this comment meant that the "address space" of 1e128 is much smaller than that of >702e300. I just wanted to clarify, because it made me pause and wtf for a second.
- vizzah 13y agoI was wondering where "RSA-464" in the article came from.. and found calculation formula, which makes this number to seem incorrect? bmax - a maximum number of bits required for a decimal number is calculated by this formula: bmax = ceil(d(log(10)/log(2))) (where d - number of digits). log(10)/log(2) = 3.3219280948873623 approximately: bmax = ceil(d3.3219) comes to 425 bits key.
- muyuu 13y agoYep, namely <54 bytes. Just for ease of comparison. ~54 bytes vs 128 bytes. Considering it's a logarithmic measure (every bit adds x2 difficulty for cracking) and 128 bytes is rather tight... gives an idea of the weakness of this key.
- muyuu 13y agoWhen one talks about an n-byte key in cryptography one typically means an n-bytes combinatorial space, not a string of length n representing n decimal digits. That's what the cybercriminal needs to learn to distinguish :-)
- meowface 13y ago"The name "digit" comes from the fact that the 10 digits (ancient Latin digiti meaning fingers) of the hands correspond to the 10 symbols of the common base 10 number system, i.e. the decimal (ancient Latin adjective dec. meaning ten) digits." Digit means base 10 numerals. It would have to be a string of 128 characters, not 128 digits.
- vinkelhake 13y agoAnti-virus programs detect many kinds of trojans and malware. Why could ransomware not be detected by anti-virus? Those points are there because they make sense. While having an up-to-date system and anti-virus software isn't a silvet bullet, it's certainly better than nothing.
- graylights 13y agoStatic signatures are increasingly pointless as malware is rebuilt often. Heuristics don't work against ransomware because they act like a well behaved program. Search for files, open file, overwrite file. All could be done as non-privileged user. Ransomware is truly scary but the proper advice is: 1. Don't run untrusted software 2. Proper backups (e.g. not just a mirror) 3. Proper permissions on network drives that are mapped. Ransomware is devastating to small offices.
- meowface 13y agoAVs will detect ransomware approximately as easily as any other malware family. Ransomware shares plenty of traits with regular malware. The problem is that there are so many cheap services out there for malware distributors to automatically "crypt" (pack) their payloads, that the chances of getting a completely fresh sample are pretty high. AVs are also less effective against ransomware because they have to catch it before it first runs on the system, otherwise there's nothing it can do.
- stusmall 13y agoJust because it is not 100% accurate doesn't mean it is security theory. Security is about taking many measures to help mitigate threat. There is never a pragmatic, completely effective safe guard. That being said, keep everything up to date and don't reuse passwords or use guessable ones :)
- zAy0LfpBZLC8mAC 13y agoThat is somewhat of an unfortunate myth. Computer security is not a matter of withstanding force (where "adding an additional wall" might help) but one of correct logic. One of the best ways to achieve the latter is to get rid of unnecessary logic altogether. AV software does the opposite: It adds tons of more logic that gets into contact with untrusted data, and thus adds exploitation risk to the system (aka "attack surface"). Also, there is a very specific reason why AV really is more an annoyance filter than a security measure: It's a blacklist. For some practical examples for why AV is risky, see also: https://lock.cmpxchg8b.com/sophail.pdf https://lock.cmpxchg8b.com/sophail.pdf https://lock.cmpxchg8b.com/sophailv2.pdf https://lock.cmpxchg8b.com/sophailv2.pdf
- al2o3cr 13y agoDepends: does "apply all software updates" include installing something besides Windows? /snark :)