So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…
Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
21–30 of 200 posts
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#22Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#23Earlier quoted context omitted.
Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.
That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…
Our backups were the data, not code or systems (which were IaC and rebuilt as needed).
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#24>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…
I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#25>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…
Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since a public ledger allows you to transitively taint every transaction downstream, significantly reducing the value of certain tokens and removing the ability of people to say they didn’t know the funds they are receiving were connected to a crime.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#26First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").
Nations setting up financial regulations on who you can and cannot pay is a standard accounting practice these days. If you consider that a tight control, then we're already far past that.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#27Earlier quoted context omitted.
That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…
Infected how? Our backups were the data, not code or systems (which were IaC and rebuilt as needed).
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#28It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#29So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?
An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.
Oh well turns out it is not like that
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#30So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…
It wouldn't surprise me if places like Nigeria have a bunch of semi-whitewashed English speaking faces/voices to perform this kind of grey area work. Even better if some of their family is part of a hostage taking gang so they can burn the candle from both ends.