Live data from Hacker News

Governments turn tables on ransomware gang REvil by pushing it offline

reuters.com

51–60 of 94 posts

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#51

Earlier quoted context omitted.

When a lot of culprits are state actors, stepping up enforcement is a naive and useless endeavour

I don’t think so. Hack the hackers. In a war if someone is shooting at you, you shoot back. Until you do, they keep shooting. I’m not saying it’s easy , just that this is the thing to do when you’re attacked.

Look up the lazarus group, state hackers from North Korea. The way you seem to be thinking about war doesn't apply at all to the current situation.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#52
post #40

Earlier quoted context omitted.

No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.

No. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least. What such an idiotic, short sighted policy would do is to encour…

Additionally, ransomware attackers frequently target hospitals because they know the issue can literally be a matter of life and death [1].

[1] https://www.aamc.org/news-insights/growing-threat-ransomware...

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#53
post #41

TLDR: "We failed to arrest, or even identify anybody, Team US OPSEC FUCK YEAH!!!" FBI, Cyber Command, Secret Service, Russian run Group-IB, DoD and spokesperson for the White House National Security Council seen in the background doing high fives and congratulating themselves on "Mission Accomplished".

Did they fail to arrest anyone? Or are you just making up stuff to be snarky?

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#54
post #50
post #13

Earlier quoted context omitted.

Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.

> gross negligence by the user Not having tested, well scoped, and reasonably frequent backups for business critical corporate operations is gross negligence.

Not having updated the system (within reason: it _can_ take a week, but it should _not_ take a year) is gross negligence as far as vendor liability would be concerned.

But by all means, let's limit the minimum liability for software vendors for such scenarios to "costs of downtime and effort for reinstalling backups and getting everything up again": That should provide an incentive to make backup procedures effortless and have the systems make some noise if they aren't backed up (with regular recovery testing etc).

As it stands, software vendors say "users are to blame" as if their shitty software isn't enabling ransomware, users say "can't do anything about it, we're down for the next 6 months" as if ransomware is some force of nature (or act of God or whatever), when both positions, while not entirely untrue, are mostly lazy.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#55
post #50
post #13

Earlier quoted context omitted.

Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.

> gross negligence by the user Not having tested, well scoped, and reasonably frequent backups for business critical corporate operations is gross negligence.

I think a constructive thing for governments to do is to gently push people in that direction.

Make high-quality, audited backups a legal requirement, or offer strong incentives for it, and much of the problem goes away. Companies may be able to outsource it, which arguably just shifts the attack vector elsewhere, but you would hope people who specialise in backups are better at it than their amateur clients.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#56

Earlier quoted context omitted.

The prospective of spending 30 years in jail is a disincentive.

This is only a disincentive to people who normally don't commit crimes. If you're part of a crime ring, this ins't something you are concerned with on a daily basis.

Organized criminals are aware of what brings the heat, what does not, and what crimes add up to what time. Their lawyers help them with that.

For the same reason they don't go after local business in Russia, because of the 'cost'.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#57

I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

The other approach is to remove the transaction system. Make bitcoin trivially traceable (or drive it out of existence entirely) and it becomes much more difficult to handle the ransom payments, and thus, to profit from the operation.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#58

Earlier quoted context omitted.

The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.

Make hiding ransomware attacks a criminal offense mandatory and offer whistleblower programs to companies that try to conceal it. This is an issue of national security. Individual alcohol problems are irrelevant and not comparable to large corporations.

And then you've just created a chain of legislation with the associated loopholes and confusion which will allow corporations to hide and deny any of it happening and then using legal fog to stonewall any Govt investigations and force people to risk their careers to call it out.

Forcing people to be whistle blowers is not a scalable enforcement plan. Very few people are willing to be one.

We need to legislate with the goal of corporate transparency not for more hidden behavior.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#59
post #40

Earlier quoted context omitted.

No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.

No. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least. What such an idiotic, short sighted policy would do is to encour…

If "all" of your data is being held to ransom and that will tank your company then you are a bad businessperson and deserve whatever you get.

Right now it's apparently cheaper to pay a ransom than it is to implement sane security and backup procedures. That needs to end.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#60

I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.

When a lot of culprits are state actors, stepping up enforcement is a naive and useless endeavour

You're confusing state actors with people who are taking advantage of jurisdictional and regulatory arbitrage to do crime.
Post reply on HN