Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

11–20 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#11
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#12
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

I would guess that the affected entities here are not companies, but public entities. Federal departments, the state governments, and municipal governments all run their own IT systems and have been affected by ransomware; if there is a top-down policy of "don't pay the ransom" it presumably affects policy for all of those.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#13
post #10

Earlier quoted context omitted.

An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.

There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.

Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#14
So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired.

I strongly suspect this too will end up mostly a jurisdiction/accounting nuance rather than a substantial change.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#15
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

Nations setting up financial regulations on who you can and cannot pay is a standard accounting practice these days. If you consider that a tight control, then we're already far past that.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#16
post #6
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, a…

> I still think out of principle you shouldn't pay the ransom, ever

There may have been a time when a company would act on principle, but I think it's very rare today. You hardly even expect people to do that. It's the world we have made.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#17
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

Nothing, so far. The alternatives to that would be to legislate penalties for paying, to mandate certain precautions like regular offline backups (which could usually be done through regulation), to forbid the government from doing business with entities that have paid in the past X time (procurement regulations are somewhat flexible) and/or to task some government agency with aiding private sector entities in recovery if they don't pay (which has varying difficulty depending on the jurisdiction).

Obviously none of these make it impossible, but the goal needs to be to tip the value proposition the other way.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#18
post #10

Earlier quoted context omitted.

There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.

Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups are infected.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#19
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

[dead]

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#20
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

I would guess that the affected entities here are not companies, but public entities. Federal departments, the state governments, and municipal governments all run their own IT systems and have been affected by ransomware; if there is a top-down policy of "don't pay the ransom" it presumably affects policy for all of those.

Even if there is a top down policy of not paying ransoms, the attackers still have an incentive to format the drives and leak the data to gain credibility for their next attack.

Many types of attack don't actually know where they're breaking into at the time they break in. And once you're in, you might as well try running a ransom attack.

Post reply on HN