Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

51–60 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#51

Earlier quoted context omitted.

Did the business follow best security practices? Did it do its due diligence to harden against attacks? Why should insurers pay, when businesses have no incentive to do this?

If you follow security best practices, you have append-only backups that you can use to restore the encrypted data and don't need insurance at all...

If the ransomware operators follow best practices, their C2 is in those backups too. The data's not encrypted, but without good IT, not for long.

Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#52
post #36

Earlier quoted context omitted.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Somewhat interesting that you use an argument against utilitarianism to argue against deontological ethics.

Government intervention is government intervention no matter the context: it seems a good idea at first but it always backfires.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#53

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

I have things to say on (French) AXA. Worst insurer I ever had the displeasure to deal with. I will spare you the multi-year history, but if you're an expat: AXA will pretend that once you move out, suddenly all 'modern' financial infrastructure has evaporated and only French cheques exist (not cache-able anywhere in my next country, Netherlands) when refunding the fines and erroneously incurred 'costs'.

They'll will string you along for _years_ correcting their own mistakes and then you're stuck with a bunch of useless cheques. I think half a dozen former colleagues and friends tried to help me out too, including someones grandma, to no avail whatsoever.

Really, the worst.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#54
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

As others have pointed out.

For the business they do not care about the greater good, the greater good is not paying the ransom, for the business paying the ransom and then taking measures so it doesn't happen to them again personally is still likely to be the better option and that is the problem.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#55
post #36
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

It's more like banning the purchase of organs on the black market if you suffer organ failure.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#56
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

As others have pointed out. For the business they do not care about the greater good, the greater good is not paying the ransom, for the business paying the ransom and then taking measures so it doesn't happen to them again personally is still likely to be the better option and that is the problem.

Rome was not built in a day :-)

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#57
post #53

Call me cynical, but anytime an insurance company decides its in everyone's 'best interest', and by everyone I mean the policy holders, I cannot help but translate to mean - 'Its costing us more money that we expected, so we don't want to cover this'

I have things to say on (French) AXA. Worst insurer I ever had the displeasure to deal with. I will spare you the multi-year history, but if you're an expat: AXA will pretend that once you move out, suddenly all 'modern' financial infrastructure has evaporated and only French cheques exist (not cache-able anywhere in my next country, Netherlands) when refunding the fines and erroneously incurred 'costs'. They'll will…

I used to work for AXA Health insurance.

Up until about 2017(!), they were reimbursing people for treatment which was claimed back (as opposed to billed to the insurance company directly) by cheque exclusively, and there were rumours from the finance department that this was because lots of people never bothered to cash in their cheques because of the hassle compared to receiving a direct debit.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#58
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

As others have pointed out. For the business they do not care about the greater good, the greater good is not paying the ransom, for the business paying the ransom and then taking measures so it doesn't happen to them again personally is still likely to be the better option and that is the problem.

It's a mildly interesting game theoretic problem, where if you are attacked and you pay, that wins over not paying -- but if you are not attacked and others pay, that loses you money because now you need insurance. So the actual optimum is for nobody to pay, but good luck on that.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#59

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better.

So being cyber-insured:

- likely to have money to pay the ransom

- probably not really implementing strong security policies

- management more important than reality, so engineering buy-in unlikely which also means backups and redundancies unlikely to be effective at the target

This makes you wonder who ends up paying for all of this (with time, energy, money, mental health).

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#60
I think the best way to convice cybercriminals not to ransom companies would it, to just drop a small tactical nuke on the site of the criminals if they are ever discovered... that may not stop ALL, but the risk for any aspiring new cybercriminal would go steep uphill.

I think the best way to stop this "business" would be to make it as costly as possible for the "bad boys"... the course of AXA may be hard on some of their customers, but in the end it may be better for the net-society at whole.

Post reply on HN