Live data from Hacker News

Fujifilm becomes the latest victim of a network-crippling ransomware attack

techcrunch.com

1–10 of 17 posts

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#2
Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#3

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported".

The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless).

A more successful approach would be eliminating the ability for anyone in the world to extort money anonymously from companies. Because without the motivation, the blackmailers have no reason to blackmail you.

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#4
post #3

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…

> A more successful approach would be eliminating the ability for anyone in the world to extort money anonymously from companies. Because without the motivation, the blackmailers have no reason to blackmail you.

In other words: attempting to ban cryptocurrencies?

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#5

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

More likely, it will lead to a governmental crackdown on cryptocurrency. If it were illegal for people to hold digital assets and impossible to exchange them for fiat currency except on black markets, cryptocurrency would lose pretty much all value and make ransomware worthless.

For the record, I think this would be a bad idea, but it’s exactly the sort of governmental overreaction I’ve come to expect. I’ve sold off most of my cryptocurrency as a result of this latest spate of ransomware attacks, waiting for this shoe to drop.

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#6
post #3

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…

"A more successful approach would be eliminating the ability for anyone in the world to extort money anonymously from companies. Because without the motivation, the blackmailers have no reason to blackmail you. "

While I agree in principal, that is quite a lofty goal. What are some of the ways you would suggest eliminating that ability?

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#7

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

Would that actually law accomplish anything? Victims of these crimes already get punished in that they are paying ransoms. I doubt that increasing the penalty would provide additional disincentive, these are already awful situations.

But let's assume that this law would be effective. Would it do a net good to the world? Maybe, if ransomware attacks stop. But in the meantime, we'd probably see some innocent people's data being released, and the downstream societal effects from the destruction that occurs.

If a company that holds my private information is hit by a ransomware attack that threatens to release my data, I'd rather they pay it.

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#8
I feel like ransomware attacks will lead us down a road to most corporate computers acting as terminals and defense focused on internal systems general users have limited interfaces with. Email/browsing will be on your PC that can just be wiped if there is an issue and work will be done through VDI systems. I know there will still be attack vectors, but right now too many employees can compromise entire networks by clinking the wrong link.

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#9
post #3

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…

That's not apples to apples, necessarily.

Ransom requires a response to incentivize further crime. You don't get paid, it's not an option.

Unless you don't need the funds, and it's used to terrorize desirable targets. Then you have a much better case.

So the question is, which are we facing?

Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack

#10
post #3

Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.

It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…

Ship 2 pounds of gold to a county that will happily accept bribes to not care and then we'll email you the keys to decrypt your network, otherwise we'll sell the data.
Post reply on HN