Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

31–40 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#31

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

Not cynical at all. Insurance business is mostly predatory. If it doesn't make them money, they're not gonna cover it. Regardless, in this specific instance I'm all for it. This will hopefully wake enterprises up so that they invest in good IT practices, which will have lasting effect on other parts of IT within firms.

Predatory in the same sense that most businesses are predatory. I.e exist to make a profit.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#32

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising.

Having insurance just means you're a more attractive target now.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#33
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#34

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

I think of insurance as the only pyramid scheme allowed by the governments across the world. The only legal pyramid scheme.

You already so many MLM companies, why would you think that it is the only one? Also, insurance edge risks. Πhat's why you take it. A better way is a mutual (is that the english word?), but it is too much communism for America!

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#35
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

Have the government bail them out by buying them out, then collectivize the company.

If your company is too big to fail, maybe it shouldn't be controlled by profit-optimizing external shareholders and reckless directors. If it isn't too big to fail and can't get a loan the usual way to pay for the ransom (or better: data recovery), just let it go bankrupt like any other company making a costly mistake.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#36
post #33
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#37
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

> Now, what do you do?

You quit and go do something else. It's not like your life ends when a company ends.

In a less sarcastic tone: this is where your DRP and BCP get involved, and if you don't have those at that scale, then you were doomed from the start anyway and your existence as a company was on a short lifespan to begin with.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#38
post #21

Earlier quoted context omitted.

I don't think this will set any precedent. Unlike a standard kidnapping and ransom, where there is a huge amount at stake for the kidnapper - there is little consequence for ransomware authors and those who hold businesses hostage. They do it from the other side of the world, anonymously (assuming good opsec) and if someone doesn't pay up, they just move on.

Not this event alone, sure, but it is a step in the right direction. The attitude will need further adoption and it may drive pre-emptive actions actions ransomware instead of the "do nothing and cash out on insurance" approach

This hasn't really worked for real-life kidnap/ransom, which has probably been done since the dawn of civilisation. I don't see why it would change now.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#39
post #36
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Somewhat interesting that you use an argument against utilitarianism to argue against deontological ethics.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#40
Note that this change in policy is probably ahead of a potential legislation by the government. Some industries do not like being regulated, and insurers are painfully aware of the impact of legislation. So this is more of a reaction than an initiative, but still kudos to them; it won't solve anything in the short term, but if it makes businesses invest more in clean security pratices, why not.
Post reply on HN