Live data from Hacker News

Confessions of a Ransomware Negotiator

theregister.com

11–20 of 56 posts

Re: Confessions of a Ransomware Negotiator

#11
post #10
post #8

I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?

Then the payment will be done by "underground payment processors" with a hefty extra fee. It wouldn't solve the problem I think, only shift the path an organization has to take.

No it wouldn't, no executive at any company would risk federal time and money laundering charges if it was made illegal.

Re: Confessions of a Ransomware Negotiator

#12
post #2

Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.

That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.

Re: Confessions of a Ransomware Negotiator

#13
post #4
post #2

Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.

ha! That is brilliant idea, how come nobody ever though of it before?

I don't know. Seems to be easier (read "cheaper") to run shitty software and not train people well, so this doesn't happen in the first place.

It's not like Ransomware is some god-given thing that just happens.

There's a case in Germany right now where the critical Confluence bug was simply not patched for two weeks after the notice that there's a critical bug/exploit. Now the systems are down and everybody's wondering how that could probably have happened...

"Won't happen here" is easier than taking care.

Re: Confessions of a Ransomware Negotiator

#15
post #2

Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.

That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.

“That’s victim blaming”

And?

In this case the victims are enabling a whole cottage industry of crime.

Re: Confessions of a Ransomware Negotiator

#16

Earlier quoted context omitted.

That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.

“That’s victim blaming” And? In this case the victims are enabling a whole cottage industry of crime.

Ransomware won't stop even if you don't pay up. Just destroying the target by data loss can be a sufficient reason for any attacker. No payment needed.

Re: Confessions of a Ransomware Negotiator

#17
post #4

Earlier quoted context omitted.

ha! That is brilliant idea, how come nobody ever though of it before?

I don't know. Seems to be easier (read "cheaper") to run shitty software and not train people well, so this doesn't happen in the first place. It's not like Ransomware is some god-given thing that just happens. There's a case in Germany right now where the critical Confluence bug was simply not patched for two weeks after the notice that there's a critical bug/exploit. Now the systems are down and everybody's wonderi…

'If you dont pay it will die off'

'If you have prepared staff and software you are not going to be affected'

All of it is true, no discussion here.

But that's not how real world works. Complex systems, large staff of various skills, temporary access for temporary fix that becomes an established feature because there is something else more important, people leaving and so on.

That's how a company ends up with their DB not backed up or backed up locally so that's encrypted in the attack too.

And you need info on orders, deliveries, and money etc RIGHT NOW!

What do you do?

Re: Confessions of a Ransomware Negotiator

#18
> unless you're critical to national security, the bottom line is: you're on your own here

Ransomware attacks are now pervasive. I'd argue that even though most individual victims are not critical to national security, society as a whole is under attack. This makes it a national security emergency in my view.

Re: Confessions of a Ransomware Negotiator

#19

Earlier quoted context omitted.

“That’s victim blaming” And? In this case the victims are enabling a whole cottage industry of crime.

Ransomware won't stop even if you don't pay up. Just destroying the target by data loss can be a sufficient reason for any attacker. No payment needed.

This is wildly incorrect. For criminal groups who intend on making money, that payment is needed on a certain subset of victims are they can’t stay in business.

Re: Confessions of a Ransomware Negotiator

#20

Earlier quoted context omitted.

Ransomware won't stop even if you don't pay up. Just destroying the target by data loss can be a sufficient reason for any attacker. No payment needed.

This is wildly incorrect. For criminal groups who intend on making money, that payment is needed on a certain subset of victims are they can’t stay in business.

I am a shady company who wants to take down a competitor. I can hire a hacker who'll do the dirty job for me and then get paid in cold hard cash. Or a nation state actor can decide to attack an enemy country's infrastructure.
Post reply on HN