Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

161–170 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#161
post #154

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…

This is not entirely useless as you still have a backup of the data, you just need to restore it without the "time bomb".

Re: 80% of orgs that paid the ransom were hit again

#162
post #67

Earlier quoted context omitted.

From the perspective of the individual, there is no greater good than defending one’s self.

Hardly. There are many philosophies that argue that the greatest good lies with how we interact with the other. And on a purely primal level it's common to prioritize one's offspring over one's self. I think most cultures recognize this intuitively.

I’m not arguing philosophy. I’m arguing how absurd the statement “it’s crazy hard to get people to sacrifice themselves for the better good” is, as if OP would sacrifice his or herself for anyone here they didn’t know.

What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality.

Maybe you watch a little bit too much television, but there are plenty of spouses out there who would, for example, not want their wife to die in childbirth if they had the option.

Re: 80% of orgs that paid the ransom were hit again

#163

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

> “Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. This has nothing to do with that idea. The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ran…

It has from a certain angle: For society/the internet as a whole it might be better for no one to pay the ransom at the cost of some of them perishing. The ransomware attacks would become unprofitable and would eventually stop. But to assume any organization wouldn't pay the ransom if its survival depends on it is obviously unrealistic.

Re: 80% of orgs that paid the ransom were hit again

#164
post #50

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

The privately owned fire brigades in NYC 100 years ago weren't much better. The free market at work:

https://www.youtube.com/watch?v=9zoXk1vnmcg

The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires.

https://en.wikipedia.org/wiki/Bowery_Boys

Re: 80% of orgs that paid the ransom were hit again

#165
post #154

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…

That assumes the backup couples the data and compute together, like a system image or something. If the backup is just data and is somewhere else, you can just rebuild the compute infrastructure from a known secure state (which arguably may require rebuilding the entire compute environment).

Even if your backup does couple the data and compute together, if it's simply time based (not sure what other event you could use really, perhaps some pure probabilistic function), then it seems like you can just trick the environment that the time is something else to get back in.

The real underpinning issue is that this stuff breaks the state of the infrastructure and the business can't afford the downtime to go around and repair these issues.

If you have your infrastructure build out mostly automated, that automation is backed up, and critical data is backed up, then you can reasonably sidestep these issues (I supposed a real thorough breach might integrate the ransomware in this very automation system but it should be reasonable to root out). The other issue is of course if the intruders threaten to release private data (empkoyee and customer PII, financials, so on). There's also business integrity but that doesn't really seem to matter anymore.

Re: 80% of orgs that paid the ransom were hit again

#166

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

Many people’s backup routines aren’t good enough. Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.

Maybe corporations should make it standard practice to have cold storage backups that are physically disconnected from the network (by humans) in a rotated fashion. Backup A is physically disconnected on B days and backup B is physically disconnected on A days.

Re: 80% of orgs that paid the ransom were hit again

#167
post #7

Looks like ransomware criminals are going for the subscription model.

Hardest part is to find subscribers, from then on the milking process is easy. Leaving the joke aside, does this mean that the systems remained unprotected after the initial ransom was paid or that they continued to threat leaking sensitive data? Paying the ransom a second time would guarantee nothing. Neither was paying the first time either.

If they were caught in the first place and paid up, the attacker presumably learned enough about the infra to find another way in? Or it was social engineering.

Like, is a company who runs its IT infra on Windows XP and pays the ransom likely to switch to the latest and greatest, no expenses spared, in a total and utter overhaul of all their systems? Or will they only try to patch the holes that were already revealed and gloss over the rest? Blame it on the intern, all that.

Re: 80% of orgs that paid the ransom were hit again

#168
post #149

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die? https://threatpost.com/ransomware-hits-hospitals-hardest/162...

They’re supposed to back up their data and set up proper contingencies. By failing to do so, they are already putting patients lives in the hands of the encryptors.

Re: 80% of orgs that paid the ransom were hit again

#170

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

How do you go about testing your personal backups? I find my own desktop is harder to verify than a server with automated tests
Post reply on HN