Live data from Hacker News

Ring LLC home security company ransomed by ALPHV ransomware

web.archive.org

41–50 of 124 posts

Re: Ring LLC home security company ransomed by ALPHV ransomware

#41
post #37

Earlier quoted context omitted.

Apart from leaks harming the privacy of customers, paying ransoms does social harm by providing an income and incentive to criminals. I found leaked details of Royal Mail's negotiations with their attackers fascinating [0]. I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted throu…

It’s been tried. Laws against paying just make people not report to the police at all.

well, i guess laws against murder, makes murder no report them self...

Re: Ring LLC home security company ransomed by ALPHV ransomware

#42
post #34
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

I am very much with you on this but I think the biggest hurdle in this theory is that introducing such regulation would create a de-facto hostile innovation environment in that jurisdiction. And no regulator will lightheartedly put themselves into the position of being the guy that “drove away all the innovators/startups/research/business”

[dead]

Re: Ring LLC home security company ransomed by ALPHV ransomware

#43
post #13
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

> I've said it before and I'll say it again Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.

>Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents.

Absofuckinglutely. Never talk to a politician without remembering that if they don't get a cut...

Re: Ring LLC home security company ransomed by ALPHV ransomware

#44
post #35
post #29

Earlier quoted context omitted.

Definitely some tradeoffs there. I recall going back and forth in my head "I'm paranoid, I don't need to enable this" to "what if there was a breach..". and well.. here we are.

E2E encryption only protects the data while it is in transmission. If there is a breach, all of your data is accessible because it is decrypted at the endpoint.

Thats not what E2E encryption means. Encryption during transmission is called transport layer encryption (eg via TLS). E2E (end to end) encryption is encryption where the data is encrypted in transit and at rest. Generally E2E systems only have the keys to decrypt the data on the user's (endpoint) device.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#45
post #31

Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.

>company is closed permanently in the interest of public security.

So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#46
post #31

Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.

>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.

Well, I'd argue if the first two high penalties did not have an effect, the company is likely rotten from within and can not really be fixed, so close it.

Also, I find your "but you have to think about the children^WJobs" argument pretty hollow. Nothing can be changed, because some gay lesbian from a foreign country might loose their already precarious job. Come on, is this really an argument for something?

Re: Ring LLC home security company ransomed by ALPHV ransomware

#47
post #37

Earlier quoted context omitted.

It’s been tried. Laws against paying just make people not report to the police at all.

well, i guess laws against murder, makes murder no report them self...

> laws against murder, makes murder no report them self

One of these is more universally repulsive than the other. Were it illegal, I'm not sure I could be bothered to blow a whistle on a company paying a cyberransom. That's obviously different for murder.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#48
post #13

Earlier quoted context omitted.

> I've said it before and I'll say it again Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.

>Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. Absofuckinglutely. Never talk to a politician without remembering that if they don't get a cut...

> never talk to a politician without remembering that if they don't get a cut

Most voters don't care about digital security. That means most politicians, reasonably, don't care either. Most voters do care about their economies. So linking what you're talking about to talking points the political can use is helpful. Not because they're going to get a cut.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#49
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

> companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers

This is zealous. If consumers don't care, and nobody can show tangible damages, "massive fines" and "criminal charges" are closer to moral outrage than prudent lawmaking.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#50
post #31

Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.

>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.

That makes all of them vested in the outcome that that company was actually good in its security of sensitive information. If they are important to anyone actually involved in the company, the company will take care of things properly.

The same argument is made for why breadwinners shouldn't get jail time when they commit a felony.

Post reply on HN