Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.
https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...
31–40 of 386 posts
Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.
https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...
One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway.
That’s a hard one to swallow, hard enough that govs also sometimes can’t follow the mantra and just pay the ransom.
It’s crazy hard to get people to sacrifice themselves for the better good, it’s yet a bigger ask for corporations who already screw the public day in day out.
The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Looks like ransomware criminals are going for the subscription model.
Somehow, that's a quite believable scenario.
Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
If the victim doesn't pay the first time, they suffer consequences and next time might decide to pay instead.
Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
Because second attacker might not be briefed by the first one.
I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.
Except that is a terrible analogy and has everything to do with a poor security culture on the firm's part because IT is treated as a liability rather than an asset.
If you pay the terrorists they just do it again. If you pay the ransomers they just do it again. And the payment increases their capabilities.
I think, except for rare conditions where a temporary need exists, it’s a net negative to pay.
But I think the security flaws that allow random ware typically are a sign of institutional incompetence so it makes sense they would also be incompetent to pay, and pay again, and pay again. Rather than to prevent the attack or to correct the flaw that allowed the attack.
Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.
I think we should actually legalize ransomware. By that I mean create a government-ran national bug bounty program. All companies of a certain size are automatically included in it. Bounties are awarded based off severity, and bounties are paid for by fines to the companies hit.