Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

311–320 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#312
post #300
post #273

Earlier quoted context omitted.

There was ransomware before crypto currencies. There will be ransomware after crypto currencies.

There was? How did it work? Bank transfers?

Yes, actually, people overestimate the reversibility of wire transfers. And before cryptocurrency, there were still shady money services such as Liberty Reserve or Perfect Money with little qualms about their habitual clientele.

Re: 80% of orgs that paid the ransom were hit again

#313
post #306

This may be an impossible question to ask: does anybody know of organizations running entirely dark copies of infrastructure possibly using an entirely different stack up to the application layer? Rather than redundancy, which is an announced component of your infrastructure available for failover and thus known to attackers, this dark infrastructure exists unknown to all but a select few employees and can be engaged…

Keeping two infras in sync means that you gotta have some kind of formalized management process. If you do have that, then there isn't much value in having the fail over up and running at all time, you can just build/launch it if needed.

This is easy in a containerized env, if you don't have that luxury having batch scripts that can provision all the critical servers quickly does the trick. This combined with reliable database backups should be enough to make the impact of such an attack trivial.

Re: 80% of orgs that paid the ransom were hit again

#314
post #149

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die? https://threatpost.com/ransomware-hits-hospitals-hardest/162...

I am sure an IRL hostage situation alrrady happened at an hospital, so we could have the answer in a variety of cases.

My opinion would be the hospital should open up to the police and accept their fate whatever the outcome. The gov./police makes the calculation of the impact of X people dying a very public way, the Y amount that is requested, and the ton of other wildcards (e.g. can we catch the gang now ? after the ransom is paid ? void the ransom some way afterwards ? limit the number of death in other ways ? what will the other victims take away fom this case ?).

At the end of it there should be a custom approach to that specific situation and not some blanklet policy application.

This also assumes a cooperative and somewhat decent police force, which might not be the case everywhere (but then I think we're screwed anyway)

Re: 80% of orgs that paid the ransom were hit again

#316

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

Backups might get you up and running again, but the new hotness is threatening to release trade secrets, competitive advantages, and embarrassing emails. Even with an ironclad recovery some people might be inclined to pay in such a situation.

Re: 80% of orgs that paid the ransom were hit again

#318

I simply can't fathom why any organisation can't go offline for an hour or so to rebuild their systems from backups, rather than go offline for days or more while ransom is being paid.

Supposing they have backups and that the backups werent compromised.

Re: 80% of orgs that paid the ransom were hit again

#320

I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

Agree. There is much confusion and many bad analogies surrounding this issue. Some claim - without evidence - that nation states are behind it. Which, with a moments reflection, is absurd; nation states may have an interest in disabling certain systems for military purposes (at the appropriate time), but no nation state needs ransom money. Easier ways for a government to get money; namely, just print some. Others lik…

> Easier ways for a government to get money; namely, just print some.

What is money? If a government wants more domestic resources, it can get it by printing money. If a state is so limited in domestic resources that it fundamentally needs resources from outside, printing money doesn't help. Printing money can help a state devote more of its country's resources to trade, but if no one wants to trade with you at any cost, it doesn't matter what parts of the local economy the state controls.

North Korea has incentives compatible with these kinds of acts, and relatively few interesting ways of deploying software engineers locally.

Post reply on HN