Newly evolved ransomware is bad news for everyone
arstechnica.com
arstechnica.com
If you know what a filesystem begins with and other common filesystem signatures (NTFS FILE records, for example), then you can derive the XOR key used and reconstruct everything without paying the 0.99 bitoins they demand.
Even then, if it just affected the MFT, you can do file carving and recover most of the files (there are always those pesky important files that will rebel and be fragmented or disappear completely). This last part is speculation of mine, I haven't been able to work on a Petya-infected system yet.
Or change the key if it's already encrypted.
Then again, I'm a bit sloppy on BitLocker mechanisms.
And it's not like solving a $1K ransom is a high priority case for LE, so you are partially right.
Like the saying goes, there is a lot of bike stealing because LE doesn't really care about stolen bikes.
If a municipality decided to take bike theft seriously, by paying increased OT or expanding the police department employment rolls, law enforcement would be all over it.
A similar problem exists for ransomware. Ransomware attacks are less frequent and more targeted, but drastically harder to investigate. We could spend many billions more to build an infosec investigative capability in state governments, and that would help, but we would rather spend those billions on other things.
Similarly, getting serious about tracking Bitcoin movements would probably involve a lot of new regulations around the use of Bitcoin, and somehow enforcing them worldwide.
I suppose the point was more that the police are likely to be very interested if you rip off one company for $50k, but it's harder to get them interested when you rip off $1k from 50 people spread around dozens of jurisdictions.
FWIW: Around here bike registration exists but is voluntary.
But if a municipality devotes even a small amount of resources -- an officer or two, full-time, I guess -- to prosecuting bike theft, that can raise the odds of getting caught for a single theft, I don't know, maybe three orders of magnitude -- from 10^-6 to 10^-3, let's say. Someone who steals hundreds of bikes a year is then looking at a real chance of getting caught for one of them.
What I've seen argued, and I seem to recall there's even experimental evidence to support this, is that that's enough to reduce the reward/risk ratio to the point where bike theft as a career, at least, is uneconomic. You might still get occasional opportunistic thefts -- leaving a bike unlocked would still not be recommended -- but the bulk of the problem would go away.
Coming back to the topic, the same principle probably applies here. You don't have to even try to solve all the ransomware crimes; you just have to solve enough of them, and come down hard enough on the perpetrators, to change the reward/risk calculation. That will probably be a lot harder to do, though, since they're unlikely to even be in the same country as the victims.
2 years in run the stats and see if there's been an effect.
Where I live, they hide beside hedges, or in blind spots, and ticket Soccer moms for California Stops at odd hours. Hours when no one is even out.
Oh, and let's not forget, the real work. Pulling over 200 vechicles on Friday, Saturday nights, and Sunday afternoons(we all get rip roaring drunk after the big game?); and look for that guy who's just over .08.
I don't know how to respond to the weird point about drunk driving. If you have any uncertainty at all about whether you might be close to the limit, just don't drive. No excuses.
If we could spend "many billions" to build this "infosec investigative capability," would it not be more efficient to implement at the federal level? Rather than training (and funding) N specialists at X different locations, why not train XN specialists at one single location?
Edit: Except for the obvious use case where you are using more than one compound in a row (e.g., high- and low-level).
Anyone want to write some Black ICE? :)
When they were using webmoney and western union no one cared to track that either. Cross border electronic crime has never had significant attention put at it, short of attacks on government systems.
Of course now that it's being done at scale that may change.
Maybe the OS could put a dialog up, along the line "Excuse me, I've noticed that a large number of files are being modified/deleted. This could be an active attack going on. Do you know about this, is this something that you are trying to do?"
Of course, malware will fight back by maybe encrypting only the file-system index (like some recent one does), or by slowly encrypting files over a period.
But still, changing large number of user files should be noticeable.
I'm not saying that the answer is to use an existing versioned os; I'm saying that filesystems/oses need to keep up with the demands users are making on this. Ransomware is a newer problem than viruses, users deleting files by mistake and power failure during writes; it's going to need a bit of thought and development to solve, but it seems obvious to me that this is solvable, and it should be easier to solve than, say, spam or ddos because it's somewhere where the OS should have complete control over what's being stored. At some point, the ransomware is attempting to remove the current version of something, and it's not beyond the wit of man to detect and prevent this.
It will, but AFAIK Dropbox keeps data for 30 days (or can get a yearly thing). I don't know if it's possible to rollback the entire stash though, nor do I know if there's a limit in the number of updates.
> Unless your provider gives you incremental backups.
I would really hope most cloud services either do that or only push verified files (for software-specific clouds) in which case the encrypted files would fault the application and not be uploaded or downloaded.
In most of the large scale damage it is not necessarily that the ransomware was spread to all the machines, but that it accessed shared network resources.
https://offensivetechblog.wordpress.com/2016/03/29/systems-a...
You are aware that there are server editions of Windows right? And that they don't exist for the fun of it?
But why is Windows still used anywhere that security is important? Shouldn't "best practices" imply that anything Windows-related be shunned? In 2002 Chairman Bill said "Security is top priority".[1] It's 2016 and the problems seem as bad as ever.
Okay, maybe Linux, OpenBSD, et al. would have as bad or worse problems if they were in such widespread use. But, after so many years, isn't it time to give those other OSes a chance? They might actually be better, not worse.
[1] http://www.cnet.com/news/gates-security-is-top-priority/
So the initial infection had nothing to do with Windows.
Microsoft historically hasn't done a good job of making it easy (and the default) to set things up this way though they take it a lot more seriously now.
NTFS supports permission execute on ACLs and the system enforces them. I wish they had made a policy decision to default that to off and require you re-auth with admin credentials to set the bit. It would work more like +x/chmod/sudo does and prevent a decent number of such things.