'We have your porn collection': The rise of extortionware
bbc.com
bbc.com
Then below the headline "The New Normal", a second group is introduced as "another ransomware group". I assume "another ransomware group" is the group subsequently referred to as "the relatively new gang". Also, relative to whom or what?
I am assuming the author of the piece originally named the groups or provided the detail you'd expect to have it make sense. Then editorial/legal spiked the names but did not copy-edit the rest of the piece to flow around the changes? I mention this because the article also weirdly edits around the nature or name of the firm targeted in the first story.
Weird.
That would be bizarre too. You can name Al-Qaeda and ISIS, but not ransomware groups?
Threatening to send fabricated evidence of your scandalous kink to people in your work or social circles should be enough. If "that isn't mine" actually works, it works against an actual hack too.
Society will experience a brief but painful moment in the near future when Zoom recordings deepfaked to show you into scandalous kinks are easier to create than the public thinks.
I have seen others sent to real email addresses with real (terrible, previous breached) passwords. But again there was no real access to anything, since those emails/passwords only belonged to the breached web sites (i.e. Adobe.com!)
Obviously these are different from some of the attacks in the article.
> It also posted a screen grab of the computer's file library which included more than a dozen folders catalogued...
I hope the ultimate outcome is the rise of shamelessness - such as Jeff Bezo's response a while back, "sure, you have a picture of me, go ahead, so what".
If your niche does not involve ID-verified videos from the big studios, I guess it would be useful to have backups.
There is also a relatively large community for torrents, just like with movies and music. Sure, you can be a total l33ch and "stream" a torrent, but most content is shared on private trackers that demand high seed ratios.
There is also mega, which has its own limitations.
One of the biggest reasons for someone having local copies of data is when actually paying for porn: Subscriptions are relatively expensive, but practically always allow downloading. It makes sense to get a subscription for a short period of time, and download as much content as you can before it runs out.
All of the same goes times 10 for VR. Good bitrate/resolution VR content tends to run 5-20gb per video. SLR has managed to find a good balance for streaming - very impressive IMHO - but it still runs into the same motivations that other subscription-based services do.
Looking at current trends, I suspect that all those questions will be asked about any porn stash that is revealed a d people with problematic porn stashes will be called out.
The overwhelming majority of sex-positive people understand that fantasy is not behavior, and that the interests of an individual are rarely diverse. The only sort of porn that is ubiquitously "problematic" features people who were either underage or did not consent.
I don't think we're a few generations away from high level managers having done nothing online that they're ashamed of.
Related: What topics do you freely talk about today which will get you fired in 20 years when society's expectations and sensitivity level changes? (Hint: It's impossible to know)
In an alternate world, labor would be strong enough that a worker could be comfortable knowing that their managers can't just fire them at-will for frivolous reasons. Labor is not at that point, in the US, at least.
If you're worried about this, vote for pro-labor politicians & judges when you can. Collectively bargain for protections or procedures for individual dismissals for this, etc.
Not many people know that here in the UK we got something like IR35 which innocently says that if someone works as an employee should be taxed as an employee (this was introduced by Labour to tackle employees registering a company on Friday, and going to work for the same company on Monday on b2b basis and paying less tax as a result). Now current government (Tories) added changes to this law so that now a client has to determine whether you are a genuine contractor or a disguised employee and then tax you at source. Still nothing sinister at the first glance, right? The problem is that because of that change employers will be able to construct their contracts in the way that contractor / employee will be always classed as a disguised employee, but only for tax purposes. This means workers hired this way will legally not have any employment rights - I mean their only recourse will be against their own company, that will not have any profits to care for employment benefits and so on. So for example if your de facto employer fires you when they learn you are pregnant, you only be able to take to court yourself (your own company). Anyway - I think much simpler explanation is here - https://norightsemployee.uk/step-by-step
What I want to say though - our Labour party and unions did absolutely nothing to stop this. This not only can render unions obsolete in the hands of crafty corporations, but essentially strips away decades of what Labour was fighting for.
So even if you vote Labour or pro-labour parties - there is no guarantee they will not sell you down the river.
And I don’t blame them, most of the time it works, even if they do it wrong.
Those hosts usually have fat internet pipes, allowing a bunch of people to download a copy over FTP at once, letting you claim credit for the first rip. There's also probably less of a paper trail; most of the hosts I'm aware of require some kind of ID, and would almost certainly hand that data over to law enforcement.
The template is to get a credentials dump, email the user's email, offer the password from the dump as proof (most people re-use the same password).
I know what you've been watching (no they don't), I recorded you on cam (doesn't matter if you have a camera or not).
It doesn't have to be bullet-proof. It only has to work once to pay off.
I'm pretty confident I didn't have anything personal on there, but just to be certain I wasn't leaking passwords, I did a quick
rm -rf ~ &; disown
Point being: employers have all the leverage over their hardware, and you never know how or when they will use it. Encryption is your friend.That said, I've heard of cases where an ex-employee was sued by their employer for deleting the drive, for example salespeople who maintain contact lists.
I essentially got lucky, but they were a bit concerned when they saw me hastily typing, even though they had already revoked all of my credentials.
I don't remember for certain, but I may have set my password store to be permanently open, which leaves a copy of the encryption key in the user directory.
Really, the practice should already be, "if you have data you care about, then always have offsite backups".
Privately, the management had forbade me from fixing the bug. Literally forbade me, and assigned me lots of support work (that didn't have tickets-- it would look like I wasn't working). Then a month later the project manager makes a show of coming over to yell at me in front of everyone for this bug not being fixed.
I zero'd my personal data, walked out of the building and never went back.
i took it to mean it was extreme trollcraft, rather than money motivation.
But if the kompromat is child porn-level illegal than you could be right.