Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

41–50 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#41
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

Did the business follow best security practices? Did it do its due diligence to harden against attacks? Why should insurers pay, when businesses have no incentive to do this?

If you follow security best practices, you have append-only backups that you can use to restore the encrypted data and don't need insurance at all...

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#42

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

You're completely right in thinking that. Insurance companies are only providing "insurance" from the perspective of the customers. They're actually just another investment vehicle and their managers (not so dissimilar to hedge and mutual funds) optimise for profits -- thus minimising risk. All the while being "risky" enough to allow for building some customer base (so cash inflow).

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#43
post #33
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

> This is why you need government intervention. Just make it illegal to pay such ransoms.

this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping.

I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be loopholes for shell / shelf companies to hide activities. The ransomware gangs themselves already today encourage you to reach out from private emails and promise smoother negotiation if you do.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#44
post #36
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Interesting argument, though forcefully selecting a donnor does not increase organ failure rates for others, whereas paying ransom does increase risks of future attacks.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#45
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

> This is why you need government intervention. Just make it illegal to pay such ransoms. this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping. I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be l…

a cybersecurity company to which you pay an annual retainer will just pay the attackers instead.

Communication will be done by lawyers and subject to strong confidentiality protection, no one will ever know.

Basically, exactly how it happens with kidnappings today.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#46
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

It will incentivize others paying the ransom if the consequences are dire enough. Remember the after-ambush interrogation in the film Inglorious Basterds.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#47
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

> Now, what do you do? You quit and go do something else. It's not like your life ends when a company ends. In a less sarcastic tone: this is where your DRP and BCP get involved, and if you don't have those at that scale, then you were doomed from the start anyway and your existence as a company was on a short lifespan to begin with.

For other readers : DRP is "Disaster Recovery Plan" and BCP is "Business Continuity Plan".

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#48
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

> This is why you need government intervention. Just make it illegal to pay such ransoms. this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping. I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be l…

There are several laws already on the books which address this – various international sanctions (https://www.reuters.com/article/us-treasury-cyber/companies-...), anti-terrorism laws (can't pay ransom to a known terrorist group), anti-money laundering laws and more. There is nothing stopping the government from enacting more.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#49
post #21

Earlier quoted context omitted.

Not this event alone, sure, but it is a step in the right direction. The attitude will need further adoption and it may drive pre-emptive actions actions ransomware instead of the "do nothing and cash out on insurance" approach

This hasn't really worked for real-life kidnap/ransom, which has probably been done since the dawn of civilisation. I don't see why it would change now.

Kidnap/ransom only really exists in countries with poor or corrupt governance.

It's a solved thing in the West for example, because the criminals know they will not get away with it. It's easier to get away with murder, because it doesn't create such social commotion, which in turn bring in the government focus.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#50
post #44
post #36

Earlier quoted context omitted.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Interesting argument, though forcefully selecting a donnor does not increase organ failure rates for others, whereas paying ransom does increase risks of future attacks.

It does modify behavior though: I am more likely to engage in risky activities like heavy drinking and overeating if I know a replacement organ (like a liver) is readily available thanks to the wisdom of the government.
Post reply on HN