Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

21–30 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#21
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

I don't think this will set any precedent. Unlike a standard kidnapping and ransom, where there is a huge amount at stake for the kidnapper - there is little consequence for ransomware authors and those who hold businesses hostage. They do it from the other side of the world, anonymously (assuming good opsec) and if someone doesn't pay up, they just move on.

Not this event alone, sure, but it is a step in the right direction. The attitude will need further adoption and it may drive pre-emptive actions actions ransomware instead of the "do nothing and cash out on insurance" approach

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#22

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

Not cynical at all. Insurance business is mostly predatory. If it doesn't make them money, they're not gonna cover it.

Regardless, in this specific instance I'm all for it. This will hopefully wake enterprises up so that they invest in good IT practices, which will have lasting effect on other parts of IT within firms.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#23
post #11
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

Businesses can't expect claims for theft insurance to be honored if they didn't take reasonable measures (install security cameras, alarms etc... and lock the valuables). How is this different?

Agree. Not arguing about not having insurance.

Just saying that paying the ransom may be the only way out of trouble.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#24
post #19
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

I read that certain ransomware distributors have been found to operate their own cleanup/“negotiation” service. Can’t be bothered to find a reference now, but this type of behavior is perfectly logical, and has been going on since forever in many traditional shady enterprises.

[deleted]

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#25
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

> You are aware that paying ransom may or may NOT work. The ransomware campaigns are pretty good on support. You will get a key for a sample of your data as a proof. You can sometimes pay progressively to get more trust. Getting your data back is just as important for the criminals as encrypting it in the first place - otherwise their business goes down.

Oh, good to know they provide support. I just remember some ransom (was it notpetya?) that had a broken "pay" thing or some invalid mail... anyway, you couldn't get the key.

And encryption your data doesn't help if you don't have backups.

Edit: Here is the story: https://www.theverge.com/2017/6/27/15881110/petya-notpetya-p...

So email provider blocked their email...

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#26

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

Not cynical at all. Insurance business is mostly predatory. If it doesn't make them money, they're not gonna cover it. Regardless, in this specific instance I'm all for it. This will hopefully wake enterprises up so that they invest in good IT practices, which will have lasting effect on other parts of IT within firms.

This isn’t predatory at all. This is a company creating a risk pool that is cheaper for organizations that believe they can self-manage ransomware risks. The ethical behaviour of an insurance company is completely orthogonal to what risks they choose to cover.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#27

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

I think of insurance as the only pyramid scheme allowed by the governments across the world. The only legal pyramid scheme.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#28
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

To play the devil's advocate, in an ideal world, you go out of business and another business that actually followed security best practices takes over.

Over time, companies start taking security more seriously. When it affects the users, they can just ignore, business as usual. But now, they can't just go on with their days, so that's the real accountability in my opinion.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#29

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

That's not cynical. That's just the lowbrow understanding of motivations. In that sense, any time you do something, you are only doing that because the utility to you is lowered. Sure, but that model provides no useful predictions about reality.

Everyone on the Internet always acts like this is some great revelation: "they're only stopping it because it doesn't provide enough utility to them"

Duh, that's what utility is. Honestly, it's so repetitive and each time it's presented as some insight when it's so trivial it provides no new value.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#30
post #15

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

Well insurance companies account for this by raising premiums. In fact it sounds counterintuitive but something which happens often is more profitable for insurance companies because otherwise few people bother to take out policies for it. In this specific case, I imagine the reason for the announcement wasn't moral or financial – the company likely decided it did not want the legal liability of potentially funding i…

Case in point companies unwillingness to buy pandemic insurance before Covid hit. Maybe lucky for insurers, and obviously they refused to sell after.
Post reply on HN