Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

71–80 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#71
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

The one company that I know personally that was hit by ransomware, and paid off the attackers, managed their own backups Which were encrypted as well. IMO, it's not just the importance of backups, but of having third party, redundant, off-site backups.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#72
post #71
post #7

Earlier quoted context omitted.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

The one company that I know personally that was hit by ransomware, and paid off the attackers, managed their own backups Which were encrypted as well. IMO, it's not just the importance of backups, but of having third party, redundant, off-site backups.

> IMO, it's not just the importance of backups, but of having third party, redundant, off-site backups.

If your backups do not already include the above, then it is not a viable backup strategy.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#74
post #50
post #44

Earlier quoted context omitted.

Interesting argument, though forcefully selecting a donnor does not increase organ failure rates for others, whereas paying ransom does increase risks of future attacks.

It does modify behavior though: I am more likely to engage in risky activities like heavy drinking and overeating if I know a replacement organ (like a liver) is readily available thanks to the wisdom of the government.

Now swing it the other way. Only harvest organs from those guilty of crimes. Would that make you less likely to commit crimes, knowing that your organs will be harvested?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#75
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

The chance of actually getting the data back are not that good https://www.msspalert.com/cybersecurity-research/71-ransomwa...

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#76

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

[deleted]

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#77
post #73

Can’t we just disallow email messages from anyone that is not either in the organisation or messaged by a user before? No more ransomware, or at least not as easily.

There are often classes of employees where external email is completely unnecessary. I know of one financial institution who has implemented this.

It wouldn't work well for many employees though. For example, try signing up for a legitimate service and guessing what email address the confirmation link will be sent from.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#78

Earlier quoted context omitted.

Not surprising. Having insurance just means you're a more attractive target now.

And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…

I think there's a net benefit to both sides here. The insurers probably charge a lot, in part because the risk is so hard to estimate and changes constantly with changes as well as new CVEs. I doubt they're losing money. The insured company gets benefits in terms of opex instead of capex, but more importantly, gets the expertise of the insurer in dealing with the situation.

In that interview, the hacker also talks about liking working with insurance companies because they understand how this situation works. They don't try to negotiate down to 10%; there's an understood negotiation window. They know how to get the bitcoins and send them, and probably know how to do bookkeeping for all of that.

I think it's closer to ransom insurance. The insurance company paying the ransom is a benefit, but not the primary reason to pay them. You pay them because they know what to do in that situation, and paying for ransom insurance looks slightly less ridiculous than paying a retainer to a Hostage Rescue Team. Most of the ransoms for hacks I've seen seemed well within the ability of the victim to pay. It's more about the negotiator that comes along with it, the bookkeeping, ensuring you get proof, ensuring they actually follow through, etc, etc.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#79

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

How would one go about finding out if a company has cyber insurance?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#80
post #36
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.

Except in this analogy we don't have a healthy person, but one that already was in a motorcycle accident.
Post reply on HN