Ransomware gives free decryption keys to victims who infect their friends
bleepingcomputer.com
bleepingcomputer.com
I find this whole thing quite scary. We all know how difficult it is to protect yourself from a determined and skilled adversary. Now that there is clear business model and opportunity to make hundreds of millions[1] this thing will probably attract more and more people. Building botnets was a mass market operation. Ransomware could become more targeted, since the value of single infected machine can be much higher.
[1] http://thehackernews.com/2015/10/cryptowall-ransomware.html
Why doesn't Microsoft get held accountable when a 0-day in Windows is exploited that results in loss of user funds? Without that, there's no incentive to build secure software in the first place.
How do we get society to have more of a security-first approach when it comes to things connected to the internet? A lot of these vulnerabilities are scary in a systemic way. Cyber warfare would likely be as damaging as dropping napalm on cities, and it's all preventable by having more security oriented infrastructure.
There is nothing stopping you from entering into a contract with Microsoft that requires them to take on that liability. And there are some companies that have contracts like that with some software vendors -- presumably in aerospace and so on. And those companies pay $5000 or more for a piece of software that you would pay $10 for. If you asked a normal person to pay that much for every app in the store they would just laugh.
If you made developers liable for vulnerabilities, that's what would need to happen. Software would have to cost enough to cover the liability. If you sell ten million copies of some code and you have one vulnerability (down from 75 before this), that vulnerability may cost 1% of your customers $20,000 each and you're suddenly on the hook for billions of dollars. And you better hope none of your customers are large corporations that could potentially suffer even bigger losses, even though the software developer has no control over that at all.
A big part of the problem here is that we keep trying to shield the users from liability, but they're the ones who make the decisions. The user won't be willing to pay extra or suffer any inconvenience for better security if it's the credit card company or insurance company or software vendor that sustains the loss when they get hacked.
Security is terrible because the party who decides how much to prioritize security is the party we give half a dozen ways to get out of suffering from the consequences of poor security.
Very far away from Microsoft's "let's use consumers as beta testers" approach.
That's not competitive though. When the user is at minimal risk the user wants the cheapest software, not the most secure software. In that situation you can't spend money improving security or buying insurance, that would make your software cost more than the competition.
The winning competitive strategy would be to minimize the consequences of declaring bankruptcy. Take on debt financing instead of issuing stock, to minimize net assets. Develop the software as many pieces each owned by an independent business entity so there is no deep pocket to attract claims and there is a smaller loss when an owner has to write one off.
Though I suppose the best solution would be to get everyone on the upgrade treadmill
No. The best solution would be to require Apple, Google and MS to split up their OSes into individual packages, that can be upgraded at will, and to unlink functionality from optics in all parts of the OS.
The reason is simple: most people, especially corp environments, don't upgrade their software because they see on friends' machines (or phones) that the look and feel has changed too much for them / that retraining time for employees is too expensive. A good example is the clusterfuck MS committed with Win8 by replacing the taskbar, the unremovable phone-home/unstoppable auto updater in Win10 or the various "design improvements" / "performance improvements" Apple did on OS X/iOS.
Oh, and with Apple there's the high risk of critical bugs or other incompatibilities with their newest OS. Software like the Adobe suite, music/video editor programs, and even office mainstream apps Lotus f..ing Notes and Cisco's programs tend to have boatloads of bugs each major OS X release. With MS, you can at least assume that you can run any old software that doesn't require drivers...
I agree that it should be possible to upgrade the backend without having to upgrade the frontend (so to speak) of the OSes.
In my experience, though, even the backend for OS X is massively changing. Networking, in particular, seems to be changing every release.
So you're not going to improve software with this, you're going to make it incredibly expensive in the US. The only groups benefiting from this will be lawyers and insurance companies.
how does that work when most home connections have terrible upload? to make matters worse, if you upload at full speed, people will notice that their internet is getting sluggish and notice something is up.
Perhaps an Ethereum program could do it, but then it might be a good idea to set up a second Ethereum network for anonymous use over darknets.
You don't need an actual company to accept Bitcoins. You don't even need a PO box or a telephone number. Just a computer connected to the internet.
Note: the point of the affiliate marketing is to make your an affiliate of /spreading the infection/ not pumping some third party product.
Could you explain very slowly how this would work in your mind? Who is paying the money, and who is receiving the money?
a. publisher b. affiliate network c. person selling a product
You are saying that the affiliate network would block the publishers for distributing malware. Yes, that's true. But what is stopping someone from creating another affiliate network? That would replace the actors with the following:
a. malware distributor b. illicit affiliate network c. malware publisher selling key
In this case, the "product" is the key to decrypt the files. The network could be anyone. It could even be the same person who wrote the malware.
I imagine that anyone who is willing and skilled enough to be a malware distributor would rather just do the whole thing himself, ie code the malware himself and collect himself.
The benefits are that the creators get more people to hero then spread their blackmail.
Call it affiliate, call it MLM, call it resellers, call it a distributed crime syndicate. Same thing.
Suppose a kid gets their parents computer infected. There is a pretty good chance that they will panic and take the non-monetary route. It's not like infecting others is beyond most kids abilities. Just run the exe themselves on school computers, post it in video game chats, send it to friends, etc. Since they aren't sure how many people will pay before their parents notice there is a strong incentive to send it to a lot of people, not just two.
The other route I see is that an adult sees this and tries to infect some company computers, on the theory that the won't be caught and there is a good chance the company will pay up. Not many people will go for it of course, but if it manages to spread internally then they will be in a decent position to demand a lot of money.
Bitcoin addresses are anonymous, but all transactions are public, right? So while it's hard to find out who's behind an address, it's publicly visible if they spend money, and where it goes. Thus, they're only able to spend it on "trusted" peers to not jeopardize their own anonymosity.
For example, if they buy something from an online shop, this transaction will be visible for all Bitcoin users. And if that shop publicly shows its Bitcoin address, authorities might track down that shop and force it to give away their shipment address.
Or am I missing something?
It's easy to generate many temporary wallets that can not be linked back to your main wallet, shops can do this too and I think it's considered a good practice to use one address per sale.
You can also convert the Bitcoins to a more anonymous coin (Monero?) and back.
https://cyber.harvard.edu/cybersecurity/Economics_of_Malware
https://www.coursera.org/learn/malsoftware
At some point, it would make sense anonymized malware (i2p, tor only) may go open source similar to commercial open source but instead because of scene cred / blackmarket consulting.
Pretty interesting process to watch from the sidelines!
[1] https://www.google.com/search?q=does+paying+ransomware+work
I wonder if their English is poor, or if they're trying to be endearing to help their conversion rates. You could confirm the former by correlating it with what common errors people in different countries make.
It doesn't look like they expect people to infect their friends, but offering the false choice is a pretty common way of making people feel slightly more in control. It probably helps their conversion rates, even if nobody picks the blue option.
Like others have said, public/private key crypto can be used to achieve this, and fairly easy: The randomware is distributed with a public key, and after generating the AES key and encrypting the system, it then encrypts the AES key using the public key and removes all other copies of the AES key. Thus, nobody with access to the system can decrypt the system now unless they have the matching private key. If you pay to decrypt your system, the program sends off the encrypted AES key, and then they send back the decrypted AES key which they got by using the matching private key. And then from there you use the AES key to decrypt the rest of the system.
Perhaps the AES key is encrypted with RSA after encryption is complete and kept on the infected machine.
private_key, public_key = keygen_rsa();
send_home(computer_id, private_key);
wipe(private_key);
for file in files {
aes_iv = ivgen_aes()
aes_key = keygen_aes()
encrypted_file = aes_ccm_encrypt(file, aes_iv, aes_key);
encrypted_aes_key = rsa_encrypt(aes_key, public_key);
wipe(aes_key);
filepos(file, 0);
write(file, aes_iv);
write(file, encrypted_aes_key);
write(file, encrypted_file);
} aes_key = keygen_aes()
crypted_aes_key = rsa_encrypt(MALWARE_PUB_KEY, aes_key)
for file in files:
content = read(file)
encrypted = aes_encrypt(content, aes_key)
write(file, encrypted)
wipe(aes_key)
display(RANSOM_NOTE, crypted_aes_key)
I'd assume all the details needed to decrypt the files EXCEPT for a small key would be stored in the encrypted file headers. The AES key could be encrypted to a given public key and then directly displayed to the victim. This means that the software doesn't really need to know how to send infoto the ransomware writers. Instead the victim would be responsible for contacting them.I think this is how PKE is usually done, precisely for the reasons you mention.
The end result is you see a file encrypted with a symmetric key.
Hiding the key is unnecessary over engineering.
I think they encrypt the files with an AES key, which is then encrypted with a public key received from the botnet herder.
Pricebuilding exercise combined with social engineering.
God, they could go full ponzi scheming with this and get a billion people to get rich and accomplices..
It's basically a link to an EXE. You could probably only convince someone to run it if you have some acquaintance with them, so obviously they'd hate you afterwards. And you only get the key if they not only get infected, but pay up. And you have to do it twice.
A better method might be "get 5 people infected", regardless of payment.
If you don't require payment, anyone could just spin up five VMs and infect them, then request a decryption key. Not saying these guys are clever or anything and the scheme seems likely to fail for the reasons you mention, but I think something like a "get two other people infected and they pay up" scheme is the most workable version.
"why does the FBI, NSA, CIA, or any cyber security agency exist? They should not exist.
SECONDLY, why aren't they actively targeting those criminals?"
I think it's important to remember that those agencies shouldn't even exist, before asking why they're not doing something. Don't quietly justify them.
Now as for providing you the argument for why they should or shouldn't exist, I think it's political and I like HN's move away from political discussion so let's not have it. But I think it's not going too far to ask people to be explicit about some of the contradictions. If you look at the comment phrasing I "suggested", you'll see it's a contradiction. I don't mean to resolve that contradiction but we shouldn't ignore it - my point was to write the contradiction explicitly.
One possible way to address your question briefly would be with reference to some films and books. but we don't need to answer your question in order to acknowledge the contradiction and I wouldn't like to answer it (one way or another - why they should, why they shouldn't exist.) it's good for HN to step back from politics a bit so let's leave it at that.
Hiding this behind the 'no politics discussion' experiment was a bit odd though.
But my point wasn't any of this: just that most of HN strongly feels against surveillance and the capabilities mentioned.
I don't want to take a side I just want the contradiction to be put front and center in these cases. It will lead to everyone on HN having a better position, when they do eventually take one. I still think we don't need to have that argument here (or in most cases where it comes up).
I put in "backdoor found" as a search query here https://hn.algolia.com/ after modifying it to search the last year.
The first article I clicked had this thread: https://news.ycombinator.com/item?id=10889008
which says:
>myth_buster 333 days ago [-]
>Please don't give away ideas. You be surprised how well these things would resonate with layperson.
Isn't it clear that they don't want these agencies to be able to have the support of populations?
I don't think I overstate the case that most HN users are against surveillance and related capabilities by anyone.
I'm not sure if you're referring to attention paid to political discussions in general or the Political Detox Week. If the latter, the week-long experiment was terminated early. See https://news.ycombinator.com/item?id=13131251
However, how much software do you really have that rewrites even 1/10th of all your documents?
It is, in fact, recruitment into cyber crime. The title should read:
> Ransomware gives free decryption keys to victims who infect their "friends"
this sounds more like an attempt to taint the popcorn time name rather than real malware.
By the way I think that the ones held responsible and paying for the damages should be distributors, not malware developers especially if they did not know exactly how it would be used. Making malware is like making a gun, it is allowed in some countries. Maybe it will be used for good purposes.
2 - Collect decryption keys
3 - Laugh at the hackers
Of course not many people out of the general population know how to make a (primarily) windows VM, but I'm surprised that others aren't mentioning it in this thread.
We should require OS manufacturers to do the same. They should be on the hook for security until the last device using their technology is no longer in use.
The OS doesn't consider your browser downloading and running executable a problem, if it did we would all be complaining about wall gardens. If that executable wants to read and write files in your home directory it is allowed to (otherwise you couldn't download and run emacs). The fact that it happens to be encrypting them to ransom back to you isn't something the OS is really in a position to know, or do anything about.
I think the problem is in PC and OS design.
> There's not a whole lot the OS can do if the user is determined to open e.g. "kittenpic.jpg.exe" or "invoice.doc.exe".
I think there are many options:
1) do not download executable files or make them non-executable after download
2) do not run downloaded executable files
3) do not run executable files without valid signature from OS developers
4) run executable files inside a sandbox
For example, iOS uses approaches 1, 3 and 4, and Android uses 4. Only desktop operating systems (including some Linux distrbutions) allow to trick user into running a malware with full access to user's files by clicking a link and pressing Ok twice. That is why I consider this is OS fault, not user's.
In many environments users are not supposed to download and run executable files. For example, in a workplace an employee is supposed to use only software approved by the company. And still no operating system provides an easy way to enforce it.
Imagine if pressing a wrong button on a washing machine would cause installing malware. Would you like to buy such device?
Windows domains can do this with Group Policies, with the first large ransomware waves companies actually started using that feature ;)
Other than that, Windows shows a prompt asking for confirmation when running a downloaded executable, but it doesn't stick to files from ZIP files, doesn't apply to mail attachments (although I'd expect mail software to warn itself) and stuff like that.
If we had Linux on the desktop, we'd have Linux ransomware.
A washing machine isn't a Turing machine.
For instance: http://www.samsung.com/uk/consumer/home-appliances/laundry/w...