>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…
Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…
Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
61–70 of 200 posts
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#62Earlier quoted context omitted.
I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.
It hurts, but it’s the only way we can get the wealthy to take security seriously. Otherwise, to take an exaggerated example, only rich hospitals will be able to pay ransoms and poor people /hospitals will have no records (globally).
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#63It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.
I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.
In practice, this is the same as wishing that other people get hit with ransomware attacks.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#64Maybe it's also time that companies take cybersecurity more seriously, and maybe not just companies, but governments too.
If insurance companies would cover ransomware damage, you can be certain those insurance companies would IMMEDIATELY lobby the government to enforce cyber security standards, audits, pentesting etc.
It's not happening as long as the NSA is on top of the race of cyberweapons, but once that changes, you can be certain that software is going to be more secure.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#65Earlier quoted context omitted.
> there absolutely will be a legal way that you can't do much about No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers. To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.
DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them if the need arises.
You are vastly overestimating the federal government’s coherence and coördination. Yes, we use black hats. Yes, we still jail and sanction them.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#66So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…
We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#67So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…
We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.
It's sounds nice in the abstract; in practice it's political suicide.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#68Earlier quoted context omitted.
I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.
Can we get letters of marque as NFTs? C'mon, anything to make the cyberpunk future less lame than it's turned out to be.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#69Earlier quoted context omitted.
> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.
They are not useless, they bend the curve. Micro harms are everywhere.
Upwards. Second order effects of schemes like prohibition are much worse than the original problems.
It's also not quite analogous to the ransomware prohibition, because it's more akin to a prisoner's dilemma, and there's no inherent desire to pay ransomware criminals in the human psyche like there is to alter consciousness.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#70Earlier quoted context omitted.
Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.
That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…