Telefonica Is Target of $600,000 Bitcoin Ransomware Attack
cointelegraph.com
cointelegraph.com
Combine with an advertising campaign to make it common knowledge that paying ransomware gets you fined, and that you should have good backup-and-restore ability instead, and the problem should become much less intense.
(side note: paying ransomware has negative externalities, since it funds ransomware operations that hurt others. If criminalizing it offends your libertarian aesthetic, think of it as a Pigouvian tax instead.)
You don't need to make it illegal to pay ransomware to use this type of logic to stop ransomware. Here's an alternative version:
It should be illegal to deploy ransomware. Raise the minimum risk-adjusted price (chance of getting caught deploying * fine) by enough, and people will make the rational decision not to deploy it.
But it doesn't work. The chance of getting caught is (currently) so infinitesimal that it is ignored, and ransomware is rampant.
In your system, the chance of getting caught paying would be equally infinitesimal, with the added problem that anybody involved with prosecuting or convicting would fully understand that they are harming the victim rather than the perpetrator.
Legislate proper security more, enforce it, fund an electronic police to help combat it.
The taxes paid by the desperate and careless can be used for the expensive international cases against the scammers.
Unless the entire world adopts this legislature in lock-step, there will still be incentives for ransomware authors to infect systems.
So what if French, Spanish, and American victims are legally prohibited from paying, if there's still money to be made in India, Australia, and Ireland?
Because the marginal cost of vulnerability exploitation is very low, what will end up happening is ransomware distributors will remain in business, and French, Spanish, and American companies will now not be able to recover any lost data. While their Irish counterparts pay the extorters, fix their systems, and move on with their lives.
There's still a problem - nothing's stopping India, Australia, and Ireland in your example from benefitting from the reduction in ransomware without paying the costs for disincentivizing it. Free riders are a problem for public goods, such as low-crime environments.
Someone using a zero-day exploit gets in and encrypts everything that runs my company and demands a ransom in exchange for the key.
Using your logic, my government says I'm not allowed to take measures to get my company back in order.
Why should we further expand the power of the government to make an already shitty situation even more detrimental?
The reason that it's successful is a) people don't apply patches quickly b) people us unsupported versions of the operating system and c) the NSA dropped a reliable exploit for it.
All software has bugs, from all vendors. Security patching is a fact of life.
The trouble is, it's not unreasonable to open en e-mail attachment if it looks like it comes from someone on your work network. You may be expecting spreadsheets or PDFs every day, and the most recent MS issue was due to the scanning process itself; you didn't even have to open that attachment.
I feel like several things need to happen here. Non-tech jobs need solid white listing. A lot of white listing software is crap and at B-sides 2016, there was a talk on how to bypass a lot of them. Solid white-listing based on application hashes and complete paths of the binary needs to become the defacto standard.
Many PCs need to stop being PCs. If it's order entry for a doctor or nurse and the software already has a web interface, a Chromebook or Linux box that just boots straight to Firefox/Chromium or something else that's very simple/kiosk is a much better and cheaper solution. You don't need a full blown Mac/Win laptop for most of the applications we use them for. (Maybe Win 10 S could even be an option in this situation, if you can connect it to a domain and offer only company apps instead of store apps?)
Large organisations need solid backup strategies, snap-shoting storage systems for staff, backup verification (would suck of that storage rack had a ransomware timebomb waiting to encrypt your backups) so they're never out more than 24 hours of date.
Even though a lot of this is a "less is better" approach, it does increase costs, it is a learning curve, it does add some limitations and, for public organisations like the NHS, it will be a burden on already taxes IT departments.
It sucks, but I wonder if we'll start to see better practices due to this and if these types of ideas will become common practice in the next decade.
It's a worm, this isn't a targeted email virus.
On Telefonica: https://www.bleepingcomputer.com/news/security/telefonica-te...
Globally: https://www.bleepingcomputer.com/news/security/wana-decrypt0...
I am not capable of giving such a guess. I would be happy to read even about the order of magnitude of said %.
It's amazing how any organization can get away with poor security and backup practices by blaming either Russia or China, without showing any evidence to back their claim.
I know the current title is the actual title of the article, but it's misleading.
If you scroll into a different article, they push the last article's URL into history and pop that until different domain is reached when pressing back.
EDIT: nvm. Apparently they mean to imply they have about ~1759 infected machines.
300$ dollers per machine ≈ 300 Bitcoins ≈ 510,000€