Earlier quoted context omitted.
When a lot of culprits are state actors, stepping up enforcement is a naive and useless endeavour
I don’t think so. Hack the hackers. In a war if someone is shooting at you, you shoot back. Until you do, they keep shooting. I’m not saying it’s easy , just that this is the thing to do when you’re attacked.
Governments turn tables on ransomware gang REvil by pushing it offline
51–60 of 94 posts
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#52Earlier quoted context omitted.
No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.
No. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least. What such an idiotic, short sighted policy would do is to encour…
[1] https://www.aamc.org/news-insights/growing-threat-ransomware...
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#53TLDR: "We failed to arrest, or even identify anybody, Team US OPSEC FUCK YEAH!!!" FBI, Cyber Command, Secret Service, Russian run Group-IB, DoD and spokesperson for the White House National Security Council seen in the background doing high fives and congratulating themselves on "Mission Accomplished".
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#54Earlier quoted context omitted.
Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.
> gross negligence by the user Not having tested, well scoped, and reasonably frequent backups for business critical corporate operations is gross negligence.
But by all means, let's limit the minimum liability for software vendors for such scenarios to "costs of downtime and effort for reinstalling backups and getting everything up again": That should provide an incentive to make backup procedures effortless and have the systems make some noise if they aren't backed up (with regular recovery testing etc).
As it stands, software vendors say "users are to blame" as if their shitty software isn't enabling ransomware, users say "can't do anything about it, we're down for the next 6 months" as if ransomware is some force of nature (or act of God or whatever), when both positions, while not entirely untrue, are mostly lazy.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#55Earlier quoted context omitted.
Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.
> gross negligence by the user Not having tested, well scoped, and reasonably frequent backups for business critical corporate operations is gross negligence.
Make high-quality, audited backups a legal requirement, or offer strong incentives for it, and much of the problem goes away. Companies may be able to outsource it, which arguably just shifts the attack vector elsewhere, but you would hope people who specialise in backups are better at it than their amateur clients.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#56Earlier quoted context omitted.
The prospective of spending 30 years in jail is a disincentive.
This is only a disincentive to people who normally don't commit crimes. If you're part of a crime ring, this ins't something you are concerned with on a daily basis.
For the same reason they don't go after local business in Russia, because of the 'cost'.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#57I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.
Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#58Earlier quoted context omitted.
The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.
Make hiding ransomware attacks a criminal offense mandatory and offer whistleblower programs to companies that try to conceal it. This is an issue of national security. Individual alcohol problems are irrelevant and not comparable to large corporations.
Forcing people to be whistle blowers is not a scalable enforcement plan. Very few people are willing to be one.
We need to legislate with the goal of corporate transparency not for more hidden behavior.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#59Earlier quoted context omitted.
No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.
No. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least. What such an idiotic, short sighted policy would do is to encour…
Right now it's apparently cheaper to pay a ransom than it is to implement sane security and backup procedures. That needs to end.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#60I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.
When a lot of culprits are state actors, stepping up enforcement is a naive and useless endeavour