Ransomware attack puts KQED public media in low-tech mode
sfchronicle.com
sfchronicle.com
Meanwhile, there are countless lawyers, accountants, doctors, architects, engineers, landlords, and other small and medium businesses that suffer similar attacks and don't talk about it publicly. If you have an important relationship with a business like that, the time to ask them hard questions about security and reliability is now, before the court date, tax audit, surgery, construction commencement, etc.
A few years ago I went to a local doctor as a once off and the computers were "down" that day. A week later I walked past and they were shut, they never reopened. A few months later it made the news that local doctors offices were being specifically targeted.
But if the relationship is important, they will be open to the conversation and it may be worthwhile. For some of us, it may also present a business opportunity.
The NAS (which used to be writable to the victim) took a few days to restore from Amazon Glacier. To me this is key: always have an offsite backup which can't be erased by a non-admin. Use BackBlaze, CrashPlan, S3, Glacier, B2, Arq or whatever. Backups forgive a lot of stupid user sins.
I suppose there's not much else to be done, but scans aren't enough to prevent pivots.
A business that transacts with protected data should never try to remove malware - these systems need to be wiped and reinstalled.
I agree the other products are indeed backups as they provide immediate recovery.
So I totally agree that before picking a backup system, one needs to evaluate what the recovery is going to be like, and whether it will be good enough. For example, when recovering from the cloud, how long will it take to transfer all the data through your Internet connection? BackBlaze's overnight restore via FedEx could be a critical feature in your recovery speed.
I've been wondering if we're simply too over-connected at the moment and if there will be a regression back to using different networks that are literally physically disconnected with one other for certain kinds of professional work.
Meaning, the wonder of the internet is that there are now billions of people who have access to your office door. If a guy in Romania decides he wants to jimmy your lock and steal your filing cabinets, there's little stopping him from trying.
Will some offices simply disconnect entirely?
We need to actually write (and purchase) better software.
Ransomware is not a software problem, this is a human problem.
We keep putting up barriers to make it harder for malicious software, but so long as you put a prompt infront of users saying "Whoa, this looks dodgy, are you sure?" they're going to click yes. Even if you make clicking yes more difficult and the warnings more obvious, they'll blame the software for being difficult and run it anyway.
The only long term 'solution' to this from a computing perspective is to run only signed applications from trusted publishers on a restricted list which are sandboxed to such a high degree. No scripting beyond very basic building blocks. Effectively an end to general-purpose computing.
Every time something like this comes along though, everyone loses their minds.
They don't. As the parent said, the problem with the internet is that billions of people have access to your office door. Cut the external cable, and it's right back down to the number of people who literally have access to your office door. It's not a good fix, but it absolutely does make random or semi-targeted attacks far less likely, which leaves only someone with a specific bone to pick who is targeting you--and even they'll have more barriers to jump to get there.
Is that really right? That seems much higher that other ransomware attacks I've heard of - usually it's per computer.
I find the word "hackers" quite a misnomer. Not just because of the unix roots, but because it makes it seem like one's dealing with a couple of up-to-no-good punks. "Russian hackers" come off as random people in Russia deciding they feel like doing whatever recent news worthy thing's going on in "the cyber"
Good advice.