Live data from Hacker News

Confessions of a Ransomware Negotiator

theregister.com

31–40 of 56 posts

Re: Confessions of a Ransomware Negotiator

#31
post #11
post #10

Earlier quoted context omitted.

Then the payment will be done by "underground payment processors" with a hefty extra fee. It wouldn't solve the problem I think, only shift the path an organization has to take.

No it wouldn't, no executive at any company would risk federal time and money laundering charges if it was made illegal.

That's what Michael Cohen is for.

Re: Confessions of a Ransomware Negotiator

#32
post #30

That if once you have paid him the Danegeld, you never get rid of the Dane. — Dane-Geld, Rudyard Kipling https://en.wikipedia.org/wiki/Dane-geld_(poem)

Quite literally if you are not careful: https://www.cbsnews.com/news/ransomware-victims-suffer-repea...

I expect the 80% figure to be rather inflated, unless they are talking about attempted attacks and not just successful second attacks, but paying the ransom in no way means you won't be attacked again.

Though thinking about it, if it were only attempted attacks I'd expect the figure to be 100% - criminal types are not known for leaving a potential easy mark alone! If they don't re-attack themselves then they could at least sell or swap to another group information about the potential target (or another group could just catch news on the grapevine).

Re: Confessions of a Ransomware Negotiator

#34
post #29

Earlier quoted context omitted.

That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.

He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.

Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.

Re: Confessions of a Ransomware Negotiator

#35
post #29

Earlier quoted context omitted.

He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.

Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.

> What else can they do?

They can take the hit and live without their data, thereby making the world safer for the rest of us. Focusing only on their own personal problem is the definition of selfishness.

Re: Confessions of a Ransomware Negotiator

#36
post #8

I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?

Partly already true. You can’t pay criminals in OFAC listed countries (https://sanctionssearch.ofac.treas.gov/) Now, the issue becomes how do you know? And what happens when it’s your businesses existence vs breaking the law?

Re: Confessions of a Ransomware Negotiator

#38
post #4

Earlier quoted context omitted.

ha! That is brilliant idea, how come nobody ever though of it before?

I don't know. Seems to be easier (read "cheaper") to run shitty software and not train people well, so this doesn't happen in the first place. It's not like Ransomware is some god-given thing that just happens. There's a case in Germany right now where the critical Confluence bug was simply not patched for two weeks after the notice that there's a critical bug/exploit. Now the systems are down and everybody's wonderi…

You can't protect against the 80 year old Marthas who IS GOING to click the link regarding her 10,000,000$ payment from the Nigerian prince. She IS GOING to download and install the bank transfer program, and she is going to compromise the entire network.

You can't get rid of the Marthas because the Marthas have been here 30 years and hangs out with everyone from the company on weekends, and probably knows more about the business than anyone even if you wanted to get rid of her.

Re: Confessions of a Ransomware Negotiator

#39
post #8

I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?

Partly already true. You can’t pay criminals in OFAC listed countries ( https://sanctionssearch.ofac.treas.gov/ ) Now, the issue becomes how do you know? And what happens when it’s your businesses existence vs breaking the law?

Break the law. Every time. The fines are minuscule, and you'll likely be able to settle with the government without actually admitting wrong doing. There's also no personal consequences for the decision makers.

Corporate accountability is laughable. So just break the law, get your small little fine, accept no wrong doing, and move on.

Re: Confessions of a Ransomware Negotiator

#40

> unless you're critical to national security, the bottom line is: you're on your own here Ransomware attacks are now pervasive. I'd argue that even though most individual victims are not critical to national security, society as a whole is under attack. This makes it a national security emergency in my view.

The same can be said for drugs, homelessness, corruption, social media, and literally anything. Society as a whole is under attack by these things, and the costs it pays for them are much higher than ransomeare.
Post reply on HN