Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My girlfriend's father had a hacker break into their network drive, encrypt all their files, and extort the company for $500 of Bitcoin in exchange for the password...


See http://en.wikipedia.org/wiki/Ransomware … or far more entertainingly, http://en.wikipedia.org/wiki/Reamde (read the novel, not the Wikipedia page)


Your girlfriend's father opened an email attachment he shouldn't have, you mean?

edit: C'mon, folks. Cryptolocker isn't a bunch of hackers targeting individual network drives. It's spread via email. http://en.wikipedia.org/wiki/CryptoLocker


Sure, and stupid people deserve to be taken advantage of, right?

Cos' that's what I see you saying.


No, I'm saying awareness of the actual causes of computer issues like Cryptolocker can be very helpful in preventing such infections.

No one in the general public is going to know how to protect against "hackers". "Don't open attachments if you aren't expecting them from someone" is actionable advice.


The problem is, before your edit, you just made a sarcastic response whose sole function, as far as I can tell, is to belittle the person you were responding to for their lack of awareness of issues like Cryptolocker without attempting to inform them.

This may not be a correct interpretation of your post but it is how it reads to me, above the edit.


Email attachments today, browser 0-days tomorrow.


Well, he had to tell his wife something...


I wonder if my disk is already encrypted (full disk encryption), can they put another encryption on top of that?


Yes... the malware replaces each file with an encrypted version. It works on an individual file level.


That's some cheap-ass pentesting. Here you go buddy! (j/k)

To explain the joke... companies spend tens of thousands doing "pentesting" to stave off vectors for concerted attacks. In this case, they would be spending tens of thousands to prevent the...$500 being extorted. My joke is that it is just as easy to pay the guy $500 for finding the errors. It's just a joke, though. You shouldn't pay extortionists a dime. (Even if that's all they ask for.)


There is some logic of burying wallet.dat files in various places in your systems and monitoring them. If/when they go missing, you know you have a problem.

Possibly set-up a periodic cycling system that drives the intruder to move them now, before they get cycled and might lose their bounty forever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: