This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.
Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…
Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
71–80 of 105 posts
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#72Earlier quoted context omitted.
Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…
The one company that I know personally that was hit by ransomware, and paid off the attackers, managed their own backups Which were encrypted as well. IMO, it's not just the importance of backups, but of having third party, redundant, off-site backups.
If your backups do not already include the above, then it is not a viable backup strategy.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#73Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#74Earlier quoted context omitted.
Interesting argument, though forcefully selecting a donnor does not increase organ failure rates for others, whereas paying ransom does increase risks of future attacks.
It does modify behavior though: I am more likely to engage in risky activities like heavy drinking and overeating if I know a replacement organ (like a liver) is readily available thanks to the wisdom of the government.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#75This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.
Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#76> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.
Not surprising. Having insurance just means you're a more attractive target now.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#77Can’t we just disallow email messages from anyone that is not either in the organisation or messaged by a user before? No more ransomware, or at least not as easily.
It wouldn't work well for many employees though. For example, try signing up for a legitimate service and guessing what email address the confirmation link will be sent from.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#78Earlier quoted context omitted.
Not surprising. Having insurance just means you're a more attractive target now.
And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…
In that interview, the hacker also talks about liking working with insurance companies because they understand how this situation works. They don't try to negotiate down to 10%; there's an understood negotiation window. They know how to get the bitcoins and send them, and probably know how to do bookkeeping for all of that.
I think it's closer to ransom insurance. The insurance company paying the ransom is a benefit, but not the primary reason to pay them. You pay them because they know what to do in that situation, and paying for ransom insurance looks slightly less ridiculous than paying a retainer to a Hostage Rescue Team. Most of the ransoms for hacks I've seen seemed well within the ability of the victim to pay. It's more about the negotiator that comes along with it, the bookkeeping, ensuring you get proof, ensuring they actually follow through, etc, etc.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#79> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.
Not surprising. Having insurance just means you're a more attractive target now.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#80Earlier quoted context omitted.
This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.
Sure, just like when you have 5 sick people, each needing a different organ to survive. We need the government to select a healthy person, take his organs and save the other 5. Sucks for that person in particular, but the public overall is better for it.