She was somebody I’d met once at an event. I couldn’t tell you which event or when, and I don’t remember much about the evening. Somewhere in it she must have learned what I did for a living, because months later, at 2:47 in the morning, she called me.
She had no idea what had happened. She only knew her computer was unusable and that her things were gone, and she was in complete and utter panic. No vocabulary for any of it. Just please help. I drove over with every recovery tool I owned.
How did Richard Lowe realize the ransomware attack was hopeless?
It was obvious from the moment I sat down. The ransom note was on the screen. This was early enough that the tools which exist now didn’t exist, and I knew within a few seconds that there was nothing I was going to be able to do. I worked until dawn anyway. Partly because I’m not one to give up, and partly because those photographs mattered to her. Wedding pictures. A baby’s first steps. Her mother’s last Christmas before the cancer. If there had been a millionth of a chance, I was going to give it the old college try.
There wasn’t. When the light came up I told her they were gone and that there was nothing she could do. I advised her not to pay the ransom. I learned later that she paid anyway. Five hundred dollars. She didn’t get the photographs back, and she called me again in a panic to ask what to do, and by then there was nothing left to try.
What’s the second half of a ransomware attack?
Everybody understands the loss. Your files are locked and you can’t get to them. That’s the version in the news and it’s the smaller half of the problem. The other half is that somebody was inside the machine. Whoever put the malware there had a look around first. Anything of value can be sold to other people. Anything with blackmail potential gets used for exactly that. Anything scandalous gets posted. The real downside of ransomware is that they have your things, and they can do whatever they want with them, and you’ll never find out which of those they chose.
That uncertainty is what I hate most about ransomware. A burglar takes the television and at least you know it’s gone. With ransomware you can spend years wondering where your family’s pictures ended up and who’s looking at them.
What obvious risk had Richard Lowe missed at home?
I’d spent decades protecting corporate networks and million-dollar systems, and I’d aimed my entire career at the wrong population. People don’t worry about bank security, and they aren’t entirely wrong not to. It’s FDIC insured. If a bank loses a million dollars, the general reaction is that this is somebody else’s problem, and in a narrow sense that’s true. Corporate security is a corporate issue.
Households are where the losses land on a person.
They lose files because they have no adequate backup. Exactly what happened that night.
If she had been keeping copies, I could have ignored the ransomware entirely and rebuilt the machine from scratch, and the incident would have been an irritating Tuesday. In those days almost nobody had backups, because backing up was a nuisance and the good tools hadn’t arrived yet. I strongly suspected before I drove over that there would be nothing to restore from. It would have been enough if she had been copying the important files to a floppy disk now and then. She wasn’t doing anything wrong. She simply didn’t know, and nobody had told her.
They lose bandwidth to a neighbor helping himself, and in the metered days that cost real money. They lose data to somebody who got onto an unsecured network and went looking.
And the theft is the part that horrifies people, more than the loss.
They keep their lives on these machines. Now they keep them on their phones, and almost nobody treats a phone as a computer. Every photograph. Banking. Everything precious, carried in a pocket, and plenty of people won’t even put a PIN on it. They leave a tablet on the table while they go and collect their food. A minute is enough, and with no security on the front of the device it’s wide open.
What do you do in the first hour of a ransomware attack?
Get off the internet. That’s the first thing, before anything else, and most people do the opposite because their instinct is to start looking things up on the infected machine.
I understand the instinct. You’re scared, and the machine in front of you is the only place you know how to look for help. Every minute it stays connected is another minute the attacker keeps working, so cut the connection first and do your research on a different device.
Simplest version: turn off your router. The reason is that plenty of malware isn’t finished when it arrives. It pulls down more of itself from the internet, so a nuisance can become a catastrophe while you sit there deciding what to do. Worse, an attacker can take control of the system directly. Cutting the connection stops both. Second, run a virus scanner.
Bitdefender is a good first line of defense. Hitman Pro makes an excellent secondary scanner, and it’s the one that will give you the clearest picture of the damage.
Plenty of people run Microsoft Defender, the one that comes with Windows, and it’s fine. It works reasonably well and it’s better than nothing by an enormous margin.
Whichever you use, the scan is diagnosis before it’s treatment. You could find a hundred separate infections and learn that the machine is hopeless. You could find something minor. You could find nothing at all. Until you know what you have, there’s very little you can sensibly do, and the guessing turns a bad morning into a bad month.
Hitman Pro will clean up most of it and sometimes all of it. Bitdefender will clean up a great deal. Defender will clean up a fair amount.
And there’s one more piece of information hiding in that step: a scan that won’t run at all. A large amount of malware disables the antivirus as its first act, because a program that can see it’s a program that can remove it. A scanner that won’t start has told you the answer, and that’s where you stop and call somebody who does this for a living.
How do you secure a family phone?
Treat the phone as seriously as the computer, because it’s one, and almost nobody does.
Everything precious is on it. Photographs. Banking. Messages. Accounts that reset every other password you own. And plenty of people won’t put a PIN on the thing, or will leave a tablet on a restaurant table while they go and collect their food. A minute is enough. With nothing on the front of the device it’s simply open. The list is short and unglamorous. Run a scanner. Take the updates and install them instead of dismissing the notification for the fourth time. Lock the screen. And back it up.
Backup is the one that matters most, for the same reason it mattered at that kitchen table at 2:47 in the morning.
Mine goes to Google’s cloud, the path of least resistance on Android, and Apple has its own version that works the same way. The platform hardly matters. What matters is that it’s running, and that you’ve verified it at some point, because a backup nobody has verified is a belief instead of a backup.
What was Family Cybersecurity called in its first edition?
I wrote it. It was called Safe Computing Is Like Safe Sex, and at the time I thought that title was extremely clever. The title was stupid. It welds together two things that have nothing to do with each other, and people couldn’t work out what the book was about from looking at it.
Everything else about that book was done properly. It was the first real book I published, and I put everything I had into it. I hired an artist for the illustrations. I had it edited twice. I read through it over and over. I had it beta read by Steve Levenson, a security expert who ran PCI audits for me at Trader Joe’s, and by Jimmy James, who was our network man there. It was complete and it was correct.
It sold about twelve or fifteen copies.
Two reasons. The first is that nobody cares about home security. That’s the problem the book exists to address and is also why it’s difficult to sell a book about it. The second is that I had no idea how to promote anything. I ran straight into what I call the wall of marketing. That’s a subject I had to learn the hard way and eventually wrote its own book about.
What changed in the Family Cybersecurity rewrite?
About a year ago I decided to redo all of my books, bringing them up to modern publishing standards and my own current standards. Larger, more complete, better made. Every book I’ve written is now redone and republished, and this was one of them.
Family Cybersecurity is a complete rewrite instead of a new cover on old material.
The aim narrowed. The original was about cybersecurity in general, written for anybody with a computer. This one is written for families: the home computers, the phones, the laptops, the tablets, whatever computing lives in the house and whoever lives there with it. That includes the parts of the problem that aren’t technical at all. Talking to children about it without frightening them. Teenagers and where the privacy line sits. Helping parents who didn’t grow up with any of this and are the ones being targeted deliberately.
The parents are the part that makes me angriest. Scammers go after older people on purpose because they’re trusting and polite on the phone, and the industry has done almost nothing to explain the threat to them in words they can use. The people who know better have left them to learn it from the scammers.
What was hardest to get right in Family Cybersecurity?
Keeping it out of my own language.
This book had every opportunity to become deeply technical, because I’m capable of writing it that way and it’s more comfortable for me. That would have made it useless. The people who need it aren’t technical, and a book they can’t read protects nobody.
So I kept the technical language down, wrote in plain English, and held the reading level to somewhere around high school. That lesson applies well outside security. Understand your audience and write to that audience. Write past them and you lose them, and it doesn’t matter how correct you were.
Cybersecurity has been near the center of my working life for a long time. I was doing security work on VAX/VMS at the start of my career, and PCI compliance at Trader Joe’s toward the end of it. I still keep a toe in the field, because it matters and because I enjoy it. I also run what I recommend: layers of backup, layers of protection, audited and monitored, checked regularly instead of assumed.
The argument comes down to one line. The people getting hurt are the ones at a kitchen table at 2:47 in the morning with no idea what just happened to them, and nobody has ever written for them.
