It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…
US travel firm $4.5M ransom negotiation open chat
61–70 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#62It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.
Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations, I really don't have a problem with them going under. It's less burdensome than being compliant with the local tax code, which all businesses have to do already.
Re: US travel firm $4.5M ransom negotiation open chat
#63Re: US travel firm $4.5M ransom negotiation open chat
#64Re: US travel firm $4.5M ransom negotiation open chat
#65Earlier quoted context omitted.
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.
I think this is where insurance can come into play. Like get a smoke alarm and sprinklers, but also get fire insurance.
Re: US travel firm $4.5M ransom negotiation open chat
#66Earlier quoted context omitted.
Does that revenue include pass-through?
Good question, I was wondering the same thing. It seems it doesn't. The main article body puts total transaction volume at $23B.
Re: US travel firm $4.5M ransom negotiation open chat
#67Re: US travel firm $4.5M ransom negotiation open chat
#68Earlier quoted context omitted.
Aren’t there mixer services for that or just convert to monero? This is off an exchange so lots of shenanigans to make things less traceable. I am guessing these people know what they are doing.
I’d imagine the feds are involved at this point. They paid to get their data, but the feds have to be tracking the addresses from this juncture and examining the breach. I hope.
Re: US travel firm $4.5M ransom negotiation open chat
#69Earlier quoted context omitted.
Continuous append-only backups, where one can't rewrite them without physical access to the system, would - most likely - help with a data loss, malicious or accidental.
Maybe a dumb question but -- I'm not a sysadmin, why isn't this the case already? At least for a company doing $1.5 billion in revenue.
One may not recognize the real value of something (or costs of losing something) until it happens.
Re: US travel firm $4.5M ransom negotiation open chat
#70Earlier quoted context omitted.
In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.
Reading "Never Split The Difference" - sounds like the police will work with families pay off kidnappers is some countries, but get it down from millions to a token amount. I think he aims for zero though most of the time.