Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

61–70 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#61
post #25
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

It's not like a bank account. Creating a new address is trivial and scalable.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#62

Earlier quoted context omitted.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

It hurts, but it’s the only way we can get the wealthy to take security seriously. Otherwise, to take an exaggerated example, only rich hospitals will be able to pay ransoms and poor people /hospitals will have no records (globally).

Or instead of banding together to not pay, organizations/nations could pool money to help poorer hospitals pay. Maybe that, too, would make the rich think more about global security.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#63

It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

> I wish my health provider had paid the ransom.

In practice, this is the same as wishing that other people get hit with ransomware attacks.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#64
Yup.

Maybe it's also time that companies take cybersecurity more seriously, and maybe not just companies, but governments too.

If insurance companies would cover ransomware damage, you can be certain those insurance companies would IMMEDIATELY lobby the government to enforce cyber security standards, audits, pentesting etc.

It's not happening as long as the NSA is on top of the race of cyberweapons, but once that changes, you can be certain that software is going to be more secure.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#65
post #55

Earlier quoted context omitted.

> there absolutely will be a legal way that you can't do much about No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers. To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.

DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them if the need arises.

> DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them

You are vastly overestimating the federal government’s coherence and coördination. Yes, we use black hats. Yes, we still jail and sanction them.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#66
post #40
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

Right, everyone's a hardliner until it's your grandson's finger in the envelope.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#67
post #40
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

Have fun being the DA who presses charges against a mother of three who paid so their kids could see daddy again instead of watching him get beheaded by terrorists.

It's sounds nice in the abstract; in practice it's political suicide.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#68
post #11

Earlier quoted context omitted.

I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.

Can we get letters of marque as NFTs? C'mon, anything to make the cyberpunk future less lame than it's turned out to be.

I honestly feel like the attackers operating out of Russia are 21st century privateers.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#69

Earlier quoted context omitted.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

They are not useless, they bend the curve. Micro harms are everywhere.

>they bend the curve

Upwards. Second order effects of schemes like prohibition are much worse than the original problems.

It's also not quite analogous to the ransomware prohibition, because it's more akin to a prisoner's dilemma, and there's no inherent desire to pay ransomware criminals in the human psyche like there is to alter consciousness.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#70
post #18

Earlier quoted context omitted.

Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…

Can't they check their backups once every few months from an isolated infrastructure?
Post reply on HN