“I was told to buy a software or lose my computer: I ignored it”
blog.acolyer.org
blog.acolyer.org
The U.S. population is actually ~327M, but since we're talking ballpark figures, let's just say that ~200M represents the adult computer-using population. It strikes that ransomware is both much bigger and much smaller than I thought. The 160,000 ransom payments is much bigger than I would have guessed. It's not like being struck by lightning; it's more like a serious car accident. But the actual revenue generated, $32M as he's estimated, is pitiful. There are all sorts of illegal, quasi-legal, and legal ripoffs that generates billions per year. For the amount of attention ransomware gets, it's just noise.
https://en.wikipedia.org/wiki/2018_Atlanta_cyberattack https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_atta...
The other part of it appears to be some slightly funny calculations. If ransomware shuts down Target's online store for a day, Target might compute the loss based on 24 hours of no revenue, but purchases that go to Amazon, or to Target a day later, shouldn't be added into total "damage". The dollar value being computed there is something more like disruption.
This is marketing for CIO/CISO's to read so they make sure to add in various security features to their BoM for purchase.
You can't trust everything coming from companies at face value. That doesn't mean you shouldn't trust anything.
That's what makes extortion work. If the cost to avoid damage is on par with the potential damage, few if any victims would actually pay the criminal. The extorted amount being a fraction of the potential damage makes victims more willing to pay.
The report is from 2017, and relies on a 300% increase in the rate of ransomware to get that 2019 cost. That sounds high, but apparently the 2016 rate did triple in that much time (although the WannaCry spike drove a bunch of that).
On the other hand, it appears to be assuming 300% growth in attacks with a a constant rate of victimization. This doesn't make much sense alongside stats like "In 2016, an average of 40 percent of spam emails contained malware links to ransomware, an increase of 6,000 percent over 2015, when less than one percent contained ransomware." That's a qualitative change from "not a threat" to "threat", and presumably 40% -> 80% would not double attack success rates.
Further, the damage stat attempts to include subjective costs like employee training and reputational harm, as well as a naive calculation of revenue costs which assumes no revenue lost to donwtime will be recovered post-attack. That's a fairly reasonable corporate estimate, but summing it across all victims this way isn't valid at all. Only a fraction of that balance-sheet loss is actual GDP-shrinking damage, while the rest becomes either loss to competitors or value-creating OpEx like security and training investment.
Hilariously, one of the linked Cybersecurity Ventures writeups also claims[1] that "cybercrime will cost the world in excess of $6 trillion annually by 2021, making it more profitable than the global trade of all major illegal drugs combined". It's amazing what kind of numbers you can invent when you compare the societal cost of one crime to the net profit of another. As much as I love William Gibson, I don't think the cartels will be swapping their chemists for programmers within the next two years.
[1] https://blogs.cisco.com/financialservices/ransomware-lessons...
¯\_(ツ)_/¯
http://drivers.razersupport.com//index.php?_m=downloads&_a=v...
For example, there if someone mails you an attachment that you open, there is a program that can find your dropbox and encrypt all your files....including on your local machine (whatever filesystem elements are linked to dropbox) and drop new virus vectors on your dropbox directories. Windows Defender didn't notice when it happened in our office.
Of course you just revert your file folders in Dropbox (machines that are also linked to that dropbox that aren't the original vector, which should be quarantined) and lose all the work since the last synchronization, but you aren't dead in the water.
Also note that Windows is pretty slow on such operations, opening and reading of lots of files (eg a build). It may actually be quicker to set up a virtual machine running Linux for such a thing.
I have long wondered why precisely this isn't built into all the major OS's.
Edit: Although, reading more, I'm not sure I love how the logic works. For instance, it ignores all Apple apps. I understand the logic behind that, but there should be different thresholds: If any process on my machine, Apple or not, rewrites 10GB or more (to choose a somewhat arbitrary amount), I want to know about it ASAP. Otherwise, what if the ransomware finds a way to leverage Apple processes?
See here: https://support.apple.com/en-us/HT204899
A ransomware can technically encrypt all drives, steal password from cloud backup software, and destroy it too. Or they can be destroyed by uploading encrypted files. No software can destroy data on a hard drive that's disconnected and unpowered. Only I can.
it is not 'a' software. not here, not there, never. the construct <category-of-material>-ware is plural. period. therefore there can never be 'a' of them.
it is 'software' or 'a <noun describing unit> of software', e.g. 'a piece of software' or perhaps '<quantifier> software' as in 'some software' 'this software', 'malware removing software', etc. 'a software program', which can be shortened to 'a program', etc, is fine, because the 'a' refers to 'program', which is implicitly in the singular.
Ger ware is singular by the way.
Frequency of 'a software' arrived with the growth of non-native speakers on the internet, and is irrelevant to its 'correctness'. Plenty of bad non-native speach patterns are 'frequent', one can often tell the country of origin of a person from speech irregularities and even adapt a pseudo-dialect which may even improve the ability to communicate with them.
Don't have stats to back it up, but I have been involved in computers from the mid 80s and literally never heard this term until ~99 or so, initially typically in the context of text clearly written by non-native speakers, and then gradually gaining some traction among younger users who think it's 'cool' or 'normative'. I have no doubt that a more formal investigation would line up with this, give or take.
2) It's 'discourse' not 'discurs'. It's also 'nonsense' and not 'non-sense', and also 'full stop'. All of which would imply that the anser to #1 is 'no' - which proves a further point - that idioms and patterns of speech matter to correctness and are quickly seen by native speakers, but are not usually obvious to those who learned the language second hand.
Based on these mistakes, the bizarre 'this is both' introductory phrasing, parenthetical '(sorry)' and the general dry, dismissive tone with a petite je-ne-seis-pas of anti-authoritarian mockery that is just begging for a leading 'pfft', my guess is that you are French. Not really germane to the conversation, but, if correct, it underlines my point about the obviousness of idioms and cultural undertones to native speakers (of any language really).
3) To support 1 and 2: If I am incorrect, which, weighing my thoughts against North American vs British idioms, I'd happy to be incorrect but am fairly certain am not, please show me a single usage of 'bakeware', 'cookware', 'hardware' or any other 'ware' where people say 'a <x>' existent in any piece of literature prior to the existence of computers:
I took a bakeware and baked a lasagna: no.
A pan is a bakeware: no.
I washed a cookware and made a salad in it: no.
A bowl is a cookware: no.
Can you hand me a silverware? I need to cut my steak.: no.
A knife is a silverware: no.
I bought a hardware from the hardware store to fix the fence: no.
A hammer is a hardware: no.
And, even in computers, the (incorrect) 'a software' use is inconsistent w/r/t hardware: I bought a new hardware to run my application: no.
The new iPad is a great new hardware: no.
4) 'A ware' is singular, but also non specific. X-ware is plural. Whatever this meant in pseudo-proto-germanic is irrelevant to a discussion of English.Actually it's an uncountable noun. You use a singular verb form - "the software is" not "the software are." But you can't pluralize it or use an indefinite article.
Same with "code," unless it means "cipher" or "regulation."
I used to use this software called Clean Slate that would watch all the changes you made to your computer and undo them when you restarted. Maybe it's time for Grandma to get her own Docker instance.... :-)
I've never heard of something like that happening, and I've been using Steam since day 1.
Trying to find something on Google about that only turns up the usual "Hijacked accounts spreading malware to friends" scheme [0] and vulnerabilities in the client itself [1], but nothing about Steam distributing malware hidden in games.
Which is kinda unexpected, I probably just didn't dig deep enough?
[0] https://www.hackread.com/hacked-steam-accounts-spreading-mal...
[1] https://thenextweb.com/apps/2019/03/21/valve-steam-vulnerabi...
Conversely, putting a huge financial and certification burden on developers hurts power users and enthusiasts-- how do you bootstrap a new programmer if he has to spend a week generating (and paying for) certificates and learning signing tools before he can emit his first "Hello World?"
From the paper:
> Given the results above, we now present and discuss a proof-of-concept approach to risk assessment to estimate futureransomware infection that is based only on self-reported se-curity habits and past exposure to online scams. The methoddemonstrates that assessments can, in theory, be made with relatively little information, enabling consumers to estimatetheir own risk. We stress from the outset, however, that wemerely intend to illustrate the general approach; in particular, the strategy we present would need to undergo more rigor-ous evaluation before it could be responsibly used for riskassessment in the broader population.
Seems tenuous, that disclaimer notwithstanding.
That's what regression does! And maybe they should've used regression, indeed. Instead, this looks more like an "improper linear model" http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.188.... -- something we see less and less of now that regression models are at our fingertips.