Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

361–370 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#361

Earlier quoted context omitted.

There are many steps in the chain between a phish message and a ransomware attack - the user opening a phish is just one of them. You might prevent lateral movement afterwards, you may detect the attack in time (there often are days or even weeks between the phish and the ransom) to protect it, you might prevent the payload from reaching the user, etc. So yes, you're right, the solution is not just better backups but…

>... however that takes will, money and quite some time. And the accounting folks will not be fans of anything that costs money. They will just say "But we haven't been attacked a second time, why should we pay for mitigation services and implementations??"

That's the "it takes will" part.

Organizations can and do take many decisions of which "the accounting folks" are not fans of, the accounting people can and do say such things about the costs, but they don't have a veto. Arguments about cost of mitigation are valid in general, but leaders and owners can choose the priorities, and the responsibility and blame for these choices is fully on them (for their will or lack of will), not on "the accounting folks" arguments.

Also, sometimes that accounting argument is entirely valid. For example, look at the recent case of First American Financial - https://krebsonsecurity.com/2021/06/first-american-financial... - if the consequence of leaking the sensitive financial documents of millions of customers is just 500k, then it definitely is cheaper to just accept the hacks and pay the compensation, because investing in proper security would be much more expensive than that.

Re: 80% of orgs that paid the ransom were hit again

#362
post #212

Earlier quoted context omitted.

But the rest of it was. The part in the first half of my message and the linked video is entirely free-market. Also, please do the work to expound on your claim.

> do the work to expound on your claim A free market system requires protection of property rights. Arson violates property rights, and so is not free market.

What type of market is it when there is no regulation to protect rights, whether property, natural, or civil?

Re: 80% of orgs that paid the ransom were hit again

#363

Earlier quoted context omitted.

Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that. And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.

> Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that. The effect would not come from the criminals being able to cash out, it would come from the company not being able to cash in. If cryptocurrency were to be banned and public exchanges were closed purchasing cryptocurrency to…

Crypto can work peer-to-peer even with fiat echanges shut down.

Sure, it would be more difficult if crypto is illegal, but I think because of the difficulty of getting it, crypto prices would skyrocket.

Everyone will also move to using the privacy coins too. So, banning crypto might actually be beneficial for it as it would incentivise crypto projects to improve privacy and decentralization even more.

A ban won't stop people from using it or developing it in their homes.

Re: 80% of orgs that paid the ransom were hit again

#364
If an insurance company would also offered IT security included in the premium, they should be able privide better security at a lower total cost. Actuaries could even asist in calculating how much risk is mitigated by each security measure, and optimize meausures to match costs to risk.

Re: 80% of orgs that paid the ransom were hit again

#365

Earlier quoted context omitted.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

(not saying I think this is a solution, but...) If the goal is to stop companies from paying ransom, then why not just make that illegal?

Better yet, add a 200% tax on top of ransom payments. That will tranfer the profits to the government. The attackers will know that the ability to pay is cut to 1/3.

Re: 80% of orgs that paid the ransom were hit again

#366

Earlier quoted context omitted.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

(not saying I think this is a solution, but...) If the goal is to stop companies from paying ransom, then why not just make that illegal?

It is already illegal to pay most ransomware gangs in the USA:

https://home.treasury.gov/policy-issues/financial-sanctions/...

Re: 80% of orgs that paid the ransom were hit again

#367

Earlier quoted context omitted.

> Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that. The effect would not come from the criminals being able to cash out, it would come from the company not being able to cash in. If cryptocurrency were to be banned and public exchanges were closed purchasing cryptocurrency to…

Crypto can work peer-to-peer even with fiat echanges shut down. Sure, it would be more difficult if crypto is illegal, but I think because of the difficulty of getting it, crypto prices would skyrocket. Everyone will also move to using the privacy coins too. So, banning crypto might actually be beneficial for it as it would incentivise crypto projects to improve privacy and decentralization even more. A ban won't sto…

> Crypto can work peer-to-peer even with fiat echanges shut down.

Sure, nowhere in my post do I deny that an underground market won't exist. In fact, I directly hint to the fact that it will exist. What matters for this problem is how easy it is to buy $X million worth of bitcoins for a company. Currently this is easy. If you have $X million in your bank account, you can go to one of these exchanges and buy $X million worth of bitcoin.

With the exchanges shut down, how would a company buy $X million worth of bitcoin? Where do they go? How do they not get scammed while doing so? It's not like companies can easily move $X million to another country where it would be legal to buy crypto either. After all, if they could move money in a bank that easily, crypto would not be required at all for the purpose of ransomware. They could just move the $X million directly! People use crypto for ransomware because it is not so easy to move money of this magnitude.

> Sure, it would be more difficult if crypto is illegal, but I think because of the difficulty of getting it, crypto prices would skyrocket.

That seems unlikely. A bank run seems the most likely scenario with a massive drop in price being the result, even if only a few high-impact regions would make it illegal (e.g. the US and EU). Regular people and large investors would cash out almost immediately upon hearing the news. Why would regular people want to own an illegal currency that they cannot trade for anything besides maybe drugs on the black market?

The reason the majority of people own crypto now is not because of the utility - it is because there are legal crypto exchanges that they can use to trade them back to the actual currency that they use (generally dollars or euros). If people have to go through illegal networks in order to perform these exchanges (and remember, exchanges for fiat money would be illegal and hence risky) the entire value proposition is lost.

> Everyone will also move to using the privacy coins too. So, banning crypto might actually be beneficial for it as it would incentivise crypto projects to improve privacy and decentralization even more.

I wouldn't even propose banning cryptocurrencies entirely. Shutting down the exchanges and banning the trade of cryptocurrency for fiat seems more than sufficient for this purpose. Cryptocurrencies can continue to exist on their own and perhaps find a use/purpose of their own. The back-and-forth exchange for fiat is what is problematic.

This might even be good for cryptocurrencies as a platform, as the focus would shift back to the underlying technology and its use cases rather than the investor crowd that doesn't give a shit about the technology and only cares about making a quick buck.

Re: 80% of orgs that paid the ransom were hit again

#368

Earlier quoted context omitted.

Preach! I have the same issues,but my last place had me as IT for the whole (small) shop, and when they outsouced IT ('we need you on important_thing') they had me install all of the Corp Spyware (because 'why would we ask them to send their own techs, then we would have to wait for them to schedule us in, you do it- it'll be faster!) and I watched with Despair as all resources went to AV (gotta love that Norton 360,…

> The owner refused to admit he made a bad decision and stayed with that 'IT' 'company' for over a year, and didn't get rid of them until I'd left and no one was available who could triage, and they saw just how little that 'company' did, and just how much I was made to cover for them That last part leaps out at me as particularly interesting: highlighting behind-the-scenes firefighting work is always tricky. Managem…

It sounds like they didn’t convey it all. As I read it, the boss only learned about the heroics after the employee had left and no one was around to put out the fires. And that sounds normal for the situation, because management did not want to hear about it.

Re: 80% of orgs that paid the ransom were hit again

#369
post #223

Ransomware is actually a net benefit. They force information security into the business agenda in a way that we haven’t really been able to accomplish before. You can now quantify the cost of getting pwned. It’s a bit like the immune system needing pathogens every once in a while.

This argument is reasonable-ish but wrong. Companies have long been subject to information security crises. Earlier, there were viruses; today, it is ransomware. Business practices will change in a way that makes these hacks less feasible, but not most businesses just aren't interested in it. The fantastic new security of the future won't be secure by design, it'll be known-ransomware-proof.

(Also, implicit in the claim is the argument that any activity is good activity. I don't think that holds: I think paying for security guards and spending disk space or CPU cycles on security measures are necessary, but not beneficial. Probably, the world would be better if there are no bad actors. But I can only assent to your claim if I believe that the world is better if we protect against bad actors than if we have no bad actors and no protection. This is probably the cause of you getting downvoted.)

Re: 80% of orgs that paid the ransom were hit again

#370

Earlier quoted context omitted.

Everyone knows that once you find a loose slots machine, you keeping playing it.

You might come back next week, but if it just jackpotted it's empty right now.

Not if the slot machine had an insurance company payout for them
Post reply on HN