Earlier quoted context omitted.
It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…
"A more successful approach would be eliminating the ability for anyone in the world to extort money anonymously from companies. Because without the motivation, the blackmailers have no reason to blackmail you. " While I agree in principal, that is quite a lofty goal. What are some of the ways you would suggest eliminating that ability?
Fujifilm becomes the latest victim of a network-crippling ransomware attack
11–17 of 17 posts
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#12Unauthorized Access to Fujifilm Servers - https://news.ycombinator.com/item?id=27384084 - June 2021 (26 comments)
Ransomware – Unauthorized access to Fujifilm servers - https://news.ycombinator.com/item?id=27375401 - June 2021 (46 comments)
Fujifilm shuts down network after suspected ransomware attack - https://news.ycombinator.com/item?id=27373455 - June 2021 (52 comments)
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#13Earlier quoted context omitted.
It's like a law that makes it illegal to get raped. Many countries exist where that's actually how they deal with it. Reported rape does indeed drop. Emphasis on "reported". The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless). A more successful…
Ship 2 pounds of gold to a county that will happily accept bribes to not care and then we'll email you the keys to decrypt your network, otherwise we'll sell the data.
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#14Does anyone have any thoughts about the prospect of a law that makes it illegal to pay ransomware ransoms in general, across government and private industry? I wonder if such a law could be written without loopholes or ambiguity about data recovery.
More likely, it will lead to a governmental crackdown on cryptocurrency. If it were illegal for people to hold digital assets and impossible to exchange them for fiat currency except on black markets, cryptocurrency would lose pretty much all value and make ransomware worthless. For the record, I think this would be a bad idea, but it’s exactly the sort of governmental overreaction I’ve come to expect. I’ve sold off…
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#15Earlier quoted context omitted.
Ship 2 pounds of gold to a county that will happily accept bribes to not care and then we'll email you the keys to decrypt your network, otherwise we'll sell the data.
If that were the outcome of said legislation, it would make the barrier to entry for executing a ransomware attack much, much higher than it is today. Wouldn’t that be a successful outcome?
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#16Earlier quoted context omitted.
If that were the outcome of said legislation, it would make the barrier to entry for executing a ransomware attack much, much higher than it is today. Wouldn’t that be a successful outcome?
I don't think the barrier to entry is higher. You're just asking for them to send something physical, you don't have to do any extra work. I'm making an assumption that a lot of the current problems with ransomware originate from criminal gangs in countries that already look the other way. Maybe that is a poor assumption. A company could be less likely to mail cash instead of clicking a button though.
Re: Fujifilm becomes the latest victim of a network-crippling ransomware attack
#17With more and more folks wanting to work from home, this further complicates the extant balancing act of how to securely give systems access to remote employees.