Live data from Hacker News

Negotiating ransoms: when to play and when to fold

zetter.substack.com

21–30 of 35 posts

Re: Negotiating ransoms: when to play and when to fold

#21
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

Ransomware really is the best possible kind of data loss, at least there’s a recovery path built into it.

On three occasions in my career I’ve been involved in events which led to large scale data loss. The first time the backups failed, and there was no recovering from it, ever since then I’m religious about testing backups. If you’re in a position to just restore from offsite backups not only can you just flip the bird to people trying to ransom your data, you’re also in a good position to deal with anything else, up to and including the data centre containing all your servers being burnt to the ground.

Re: Negotiating ransoms: when to play and when to fold

#22
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

That multiply $ x time is the same argument why the Ford Pinto was shipped with an exploding gas tank - cheaper to pay the settlements.

I don’t think we’ll break this cycle until paying Bitcoin to a Russian Hacking group = Jail.

Re: Negotiating ransoms: when to play and when to fold

#23
post #15
post #3

Before it gets mentioned here is a good post why ransomware gangs love (traceable) Bitcoin. Most of ransomware gangs are more or less well known, not really anonymous. http://jpkoning.blogspot.com/2021/06/why-do-ransomware-gangs...

The FBI could set up a website where you can check whether your Bitcoins were involved in some crime. This would set up an interesting experiment. Would you accept a $20 dollar bill in the supermarket if you knew it was used in some ransom case? And what if suddenly you knew you owned such a $20 dollar bill? Would you try to get rid of it as quickly as possible?

Does the bill’s involvement in a ransom reduce the value of the bill or implicate me in any way? I’ve never considered someone morally responsible for the provenance of their money outside their control. Maybe I’m missing the point.

Re: Negotiating ransoms: when to play and when to fold

#25
post #19

Earlier quoted context omitted.

Actually — even better point from the post: > If you discover that the data was corrupted during the encryption process, is it game over? > Most of the time, yeah. If it’s database files, typically they’re gone. I hadn't even considered what happens when ransomware tries to encrypt a database while it is in use. That's not gonna end well...

The ransomware I've come across has lots of special heuristics to try and not destroy your data... Things like taking a copy and then doing an atomic replace...

Admittedly I've only had to deal with ransomware once, trying to help a friend. That one was way too shoddily written for anything like atomic replace or DB identification heuristics…

Re: Negotiating ransoms: when to play and when to fold

#26
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

That multiply $ x time is the same argument why the Ford Pinto was shipped with an exploding gas tank - cheaper to pay the settlements. I don’t think we’ll break this cycle until paying Bitcoin to a Russian Hacking group = Jail.

Yeah, I hate the $×t argument because generally it only factors in your $ and t. The impact to others and other secondary costs are frequently not included.

Re: Negotiating ransoms: when to play and when to fold

#27
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

I think this is wrong. It’s Bitcoin alone that is the problem. Ransom demands will exist as long as it’s viable money making enterprise. Asking humans to not to be human isn’t usually an effective strategy for anything. The only solution to remove the incentive, the value of crypto. Bonus for the planet since crypto also incentivizes coal burning and other pollution.

Re: Negotiating ransoms: when to play and when to fold

#28
First off, I remember reading that it was not control of their infrastructure that the hackers had, it was control of the accounting systems. They are separated functions and the pipeline could not bill folks that’s why they shut it down... think about that... these folks shut it down cause they were worried about counter-party risk in payments...

Re: Negotiating ransoms: when to play and when to fold

#29

> So you’re like, “Oh great. We have backups, the data is there, but the application to actually do the restoration is encrypted.” From my experience dealing with ransomware, most encrypted applications are not recoverable, even with the key. Those app servers need to be rebuilt or restored. File servers and individual files can be decrypted using the key, but applications get scrambled.

They need to be rebuilt. There’s no ifs or buts about that, once a server has been compromised by a malicious actor it can no longer be trusted. Even if you could just restore functionality you have no guarantees that there’s not a time bomb ticking away to hit you again at some later date now they’ve established you’ll pay out.

Rebuilt? Replaced! All of them are now suspect.

Re: Negotiating ransoms: when to play and when to fold

#30
post #15

Earlier quoted context omitted.

The FBI could set up a website where you can check whether your Bitcoins were involved in some crime. This would set up an interesting experiment. Would you accept a $20 dollar bill in the supermarket if you knew it was used in some ransom case? And what if suddenly you knew you owned such a $20 dollar bill? Would you try to get rid of it as quickly as possible?

Does the bill’s involvement in a ransom reduce the value of the bill or implicate me in any way? I’ve never considered someone morally responsible for the provenance of their money outside their control. Maybe I’m missing the point.

Well, the FBI could make it illegal to own Bitcoins that can be traced to criminal activity.
Post reply on HN