Live data from Hacker News

Confessions of a Ransomware Negotiator

theregister.com

51–56 of 56 posts

Re: Confessions of a Ransomware Negotiator

#51
post #23

I’m adding this to my business card. “Ransomware Negotiator”

------------------------------------------- | | | Winston Wolf | | | | Fixer, Cleaner, Ransomware Negotiator | | | -------------------------------------------

What a perfect reference hahahaha

Re: Confessions of a Ransomware Negotiator

#52
post #48

Earlier quoted context omitted.

Would you let your company that earns millions for a ransomware that is asking tens of thousands of dollars?

If your company that owns millions doesn't have a backup of the mission-critical data somewhere, you have a bigger problem.

No. In that moment your biggest problem is that all your data is inaccessible. That you don’t have backups reduces options since it precludes that solution, but another one exists: pay the ransom.

Re: Confessions of a Ransomware Negotiator

#53
> Shah's experience is different to most others this writer has talked to in that he doesn't see repeat attacks

The idea of repeated attacks and leaked data when the ransom is paid is delusional.

Yet somehow this idea persists.

I'm not sure if the average person believes it or just the ones who speak loudest. But it's seems an example of the masses believing something both illogical and not true. A bit like torture not working, the ability to mess with peoples brains is scary.

Re: Confessions of a Ransomware Negotiator

#54
post #2

Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.

I don't get why they don't just restore from backup. S3 has been around for more than a decade at this point.

Re: Confessions of a Ransomware Negotiator

#55
post #29

Earlier quoted context omitted.

He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.

Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.

Continuity is part of regulation in some industries, yes

Re: Confessions of a Ransomware Negotiator

#56
post #29

Earlier quoted context omitted.

He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.

Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.

> Maybe government can enact laws asking to maintain backups regularly in critical industries.

That's a step in the right direction, but we need more.

If you're critial industry and get ransomwared there should be hefty fines for everyone involved from the top down.

Also there should be hefty fines for any data leaks that are a result of ransomware attacks.

Companies will start moving when getting ransomwared due to low security standards is a major impact on your financials and not like some "put 50k aside for data hostage situations".

Post reply on HN