49 comments

[ 3.3 ms ] story [ 95.0 ms ] thread
That website seems to hijack back button history...
Nah, that's actually sane behavior for a SPA.

If you scroll into a different article, they push the last article's URL into history and pop that until different domain is reached when pressing back.

> Hackers are demanding a payment of $300 per machine, roughly equal to 300 Bitcoins currently worth around 510,000 euros.

EDIT: nvm. Apparently they mean to imply they have about ~1759 infected machines.

You misunderstood. The article claimed

300$ dollers per machine ≈ 300 Bitcoins ≈ 510,000€

(comment deleted)
(comment deleted)
IMO, it should be illegal to pay ransomware. Bad actors only deploy ransomware because enough people pay the ransom for it to be worthwhile. Raise the minimum risk-adjusted price (chance of getting caught paying * fine) by enough, and people will make the rational decision to not pay it.

Combine with an advertising campaign to make it common knowledge that paying ransomware gets you fined, and that you should have good backup-and-restore ability instead, and the problem should become much less intense.

(side note: paying ransomware has negative externalities, since it funds ransomware operations that hurt others. If criminalizing it offends your libertarian aesthetic, think of it as a Pigouvian tax instead.)

> Raise the minimum risk-adjusted price (chance of getting caught paying * fine) by enough, and people will make the rational decision to not pay it.

You don't need to make it illegal to pay ransomware to use this type of logic to stop ransomware. Here's an alternative version:

It should be illegal to deploy ransomware. Raise the minimum risk-adjusted price (chance of getting caught deploying * fine) by enough, and people will make the rational decision not to deploy it.

But it doesn't work. The chance of getting caught is (currently) so infinitesimal that it is ignored, and ransomware is rampant.

In your system, the chance of getting caught paying would be equally infinitesimal, with the added problem that anybody involved with prosecuting or convicting would fully understand that they are harming the victim rather than the perpetrator.

That definitely is not true. If a company has to pay $1m for ransomware, they would likely need to disclose it publicly, and at least privately to auditors. Making it illegal as in jail time would prevent any corporate employee from agreeing to do it so it would effectively stop it.
The ransomers are likely in another country which makes it harder to prosecute them.
(comment deleted)
We don't even know of all the attacks (because it makes the victim look bad), adding a fine would drive reporting down even more.

Legislate proper security more, enforce it, fund an electronic police to help combat it.

It has negative externalities? Don't make it illegal. Tax it to hell. $50k minimum plus 700% of the ransom paid ought to cover it. Dodging those taxes and trying to pay secretly, now that's illegal.

The taxes paid by the desperate and careless can be used for the expensive international cases against the scammers.

I'm sure this would work just as well as outlawing ransomware itself has worked.
There's a simple problem with your proposal.

Unless the entire world adopts this legislature in lock-step, there will still be incentives for ransomware authors to infect systems.

So what if French, Spanish, and American victims are legally prohibited from paying, if there's still money to be made in India, Australia, and Ireland?

Because the marginal cost of vulnerability exploitation is very low, what will end up happening is ransomware distributors will remain in business, and French, Spanish, and American companies will now not be able to recover any lost data. While their Irish counterparts pay the extorters, fix their systems, and move on with their lives.

There's opportunity costs for engaging in ransomware rather than doing other activities. If you're good enough with computers to do ransomware, you're also probably good enough with computers to do legitimate work. We don't need to completely starve out the ransomware actors, we just need to make it less lucrative than their other alternatives.

There's still a problem - nothing's stopping India, Australia, and Ireland in your example from benefitting from the reduction in ransomware without paying the costs for disincentivizing it. Free riders are a problem for public goods, such as low-crime environments.

Lets say I run any given hosting company.

Someone using a zero-day exploit gets in and encrypts everything that runs my company and demands a ransom in exchange for the key.

Using your logic, my government says I'm not allowed to take measures to get my company back in order.

Why should we further expand the power of the government to make an already shitty situation even more detrimental?

It's situations versus strategies. Making certain kinds of situations worse will make people choose better strategies. This is one solution to the Prisoner's Dilemma - if you defect, the mob boss puts a hit out on you, so nobody talks.
If something such as that were implemented, sure you'd stop a few, but it would just become an underreported metric. Making something illegal does not wholesale stop it from happening, it just pushes it out of view.
It'd at least put a significant dent in public corporation's spending on it. If they share it in their audits and reports to shareholders, they get nailed on paying ransomware. If they hide that they paid out significant amounts of money, that's accounting and/or securities fraud. The biggest sensible course of action is to put the IT infrastructure in place that mitigates ransomware attacks.
The natural response for the attacker is to discount the ransom amount to compensate for the expected cost of penalties (from breaking the law). This will deter attacks if the expected penalty is greater than than the ransom amount, but anywhere less than that, the government just becomes a co-conspirator in the ransom.
Kidnapping has been around for thousands of years, and yet so far no jurisdiction managed to criminalize paying the kidnapping ransom.
In Italy in the event of a kidnapping all the assets belonging to the kidnapped person and his/her family are immediately frozen by the law. As a consequence, paying the ransom effectively becomes a crime.
I stand corrected. Thank you for the correction.
Are there statistics on before/after this law was implemented? It seems that kidnapping would become massively underreported as a result.
That means that if I want to pay the ransomware, I also have to pay the (ongoing?) blackmail fee so the ransomware installer doesn't tell anyone I paid the ransom?
'Succumbs' makes it sound like they payed the ransom, which they haven't
Agreed. Mods, could we please change the title to something like "Telefonica Is Target of $600,000 Bitcoin Ransomware Attack"?

I know the current title is the actual title of the article, but it's misleading.

"Victim", as there's nothing to suggest it's targetted.
To me it sounds more like the company "died," i.e. went bankrupt or out of business. (Also not true.)
> “The origin of the infection is not confirmed at the moment, but sources close to the company point out that it is being treated as an attack originating in China,” El Mundo writes.

It's amazing how any organization can get away with poor security and backup practices by blaming either Russia or China, without showing any evidence to back their claim.

Well, we have always been at war with Eastasia...
To my mind, there's a difference between "blaming Russia or China" and saying the attacks originated in Russia or China. The former is a reference to the nation state itself (i.e. state sponsored cyber attacks), while the latter is broader and can also mean private individuals within those respective countries.
And, in fact, given that by now news reports are indicating that the greatest number of affected machines in this wave of attacks is in Russia itself, it's probably private criminal groups.
"The success of the attack is thought to be due to a vulnerability in Microsoft Windows" It's really 'good' day for Microsoft. Europe realizing that Microsoft is not that good and cheap: https://news.ycombinator.com/item?id=14314713 NHS in England is under attack due to Microsoft bug: https://news.ycombinator.com/item?id=14325213
The issue being exploited in the ransomware attack was patched months ago (MS17-010).

The reason that it's successful is a) people don't apply patches quickly b) people us unsupported versions of the operating system and c) the NSA dropped a reliable exploit for it.

All software has bugs, from all vendors. Security patching is a fact of life.

The NHS one was posted on Slashdot earlier. A bunch of companies and governments seem to be affected and it's spreading across much of Europe. Whoever started this is probably going to make a killing.

The trouble is, it's not unreasonable to open en e-mail attachment if it looks like it comes from someone on your work network. You may be expecting spreadsheets or PDFs every day, and the most recent MS issue was due to the scanning process itself; you didn't even have to open that attachment.

I feel like several things need to happen here. Non-tech jobs need solid white listing. A lot of white listing software is crap and at B-sides 2016, there was a talk on how to bypass a lot of them. Solid white-listing based on application hashes and complete paths of the binary needs to become the defacto standard.

Many PCs need to stop being PCs. If it's order entry for a doctor or nurse and the software already has a web interface, a Chromebook or Linux box that just boots straight to Firefox/Chromium or something else that's very simple/kiosk is a much better and cheaper solution. You don't need a full blown Mac/Win laptop for most of the applications we use them for. (Maybe Win 10 S could even be an option in this situation, if you can connect it to a domain and offer only company apps instead of store apps?)

Large organisations need solid backup strategies, snap-shoting storage systems for staff, backup verification (would suck of that storage rack had a ransomware timebomb waiting to encrypt your backups) so they're never out more than 24 hours of date.

Even though a lot of this is a "less is better" approach, it does increase costs, it is a learning curve, it does add some limitations and, for public organisations like the NHS, it will be a burden on already taxes IT departments.

It sucks, but I wonder if we'll start to see better practices due to this and if these types of ideas will become common practice in the next decade.

Absolutely we need to decrease the attack surface. We can't expect for each of those doctors to make sure they always have the latest version of Windows, etc. I'd also go so far as saying that we can't even trust IT to always update the systems because large corporates loose track of boxes all the time.
> The trouble is, it's not unreasonable to open en e-mail attachment if it looks like it comes from someone on your work network.

It's a worm, this isn't a targeted email virus.

I would like to read someone's educated guess on what is the % of bitcoin transactions that have a direct purpose of paying illegal activities (drugs, guns, black hat hacking, ransomware, etc).

I am not capable of giving such a guess. I would be happy to read even about the order of magnitude of said %.

Drugs are probably a big share of all btc value and maybe it's "gold standard" since it's one thing you can find people wanting to trade stuff for it anywhere in the world. The rest of the illegal activity would probably need to be calculated separatedly because I'm almost sure drugs would dwarf them.
This is, of course, actually good news for Bitcoin, because