Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

21–30 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#21
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

It wouldn't surprise me if places like Nigeria have a bunch of semi-whitewashed English speaking faces/voices to perform this kind of grey area work. Even better if some of their family is part of a hostage taking gang so they can burn the candle from both ends.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#23
post #18

Earlier quoted context omitted.

Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…

Infected how?

Our backups were the data, not code or systems (which were IaC and rebuilt as needed).

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#24
post #11
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.

Hey, but I can sell you a 21st century e-hammer with AuthentiCode licensing. Swing power savings of up to 2% can be achieved. (Requires constant internet connection).

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#25
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly.

Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since a public ledger allows you to transitively taint every transaction downstream, significantly reducing the value of certain tokens and removing the ability of people to say they didn’t know the funds they are receiving were connected to a crime.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#26
post #15
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

Nations setting up financial regulations on who you can and cannot pay is a standard accounting practice these days. If you consider that a tight control, then we're already far past that.

“These days”? Nations have been restricting trade for millennia.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#27
post #18

Earlier quoted context omitted.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…

Infected how? Our backups were the data, not code or systems (which were IaC and rebuilt as needed).

Are user accounts data or systems? Compromise of AD is a very common means. This said this can still be fixed before putting it back where it could reach the internet and cause trouble.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#28

It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#29
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.

The dumbest take of companies was assuming insurance companies would keep paying their ransom because they were thinking fixing their networks was less important

Oh well turns out it is not like that

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#30
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

It wouldn't surprise me if places like Nigeria have a bunch of semi-whitewashed English speaking faces/voices to perform this kind of grey area work. Even better if some of their family is part of a hostage taking gang so they can burn the candle from both ends.

Nigeria (my country) is pretty bad, but we don't do ransomware, lol.
Post reply on HN