Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

81–90 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#81
post #18

Earlier quoted context omitted.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…

Infected how? Our backups were the data, not code or systems (which were IaC and rebuilt as needed).

For a concrete example, someone could infect an image storing service with code that encrypts (and silently decrypts) the data when it's stored / retrieved. When the hacker removes the decryption key from the running service, the backups will also be inaccessible because they are also encrypted.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#82
post #62

Earlier quoted context omitted.

It hurts, but it’s the only way we can get the wealthy to take security seriously. Otherwise, to take an exaggerated example, only rich hospitals will be able to pay ransoms and poor people /hospitals will have no records (globally).

Or instead of banding together to not pay, organizations/nations could pool money to help poorer hospitals pay. Maybe that, too, would make the rich think more about global security.

So some asshat will be in charge of IT at [poor hospital], some rich people will foot the bill, and somehow that will improve...what? What is "global security?"

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#83
post #64

Yup. Maybe it's also time that companies take cybersecurity more seriously, and maybe not just companies, but governments too. If insurance companies would cover ransomware damage, you can be certain those insurance companies would IMMEDIATELY lobby the government to enforce cyber security standards, audits, pentesting etc. It's not happening as long as the NSA is on top of the race of cyberweapons, but once that cha…

Not sure if you're aware, but ransomware insurance is already a significant industry, and the contracts usually stipulate that the client company undergoes some type of regular auditing.

From what I've heard, insurance companies are actually kinda souring on the business because it's incredibly bad from an actuarial perspective: many of those targeted are SMBs (i.e. they're not paying the kind of premiums that would make it worthwhile), but even for large corps as time passes the odds of a ransom event approach 1. I mean, can anyone think of a large non-tech enterprise that doesn't have that doesn't have that one load-bearing Windows Server 2008 machine in a closet?

So to an extent, this seemingly represents the industry collectively declaring that even massive monthly insurance premiums are insufficient for companies to get their security posture together, and so they're trying to cut it off at the source by making ransomware as an endeavor unprofitable.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#84
post #25

Earlier quoted context omitted.

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

It's not like a bank account. Creating a new address is trivial and scalable.

Adding text to a blacklist is also trivial and scalable.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#85
post #49
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

You should have pointed out that her view is self-serving. if you are a hostage negotiator (retired even or whatever), it's natural to argue that we will still negotiate with terrorists. Just like programmers argue about whether we'll still have a job even as ai gets better and better ;-)

I mean "people still keep hiring me, even people who have a policy of not negotiating" is a pretty neutral take.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#86
post #77
post #49

Earlier quoted context omitted.

You should have pointed out that her view is self-serving. if you are a hostage negotiator (retired even or whatever), it's natural to argue that we will still negotiate with terrorists. Just like programmers argue about whether we'll still have a job even as ai gets better and better ;-)

She's now an elementary school teacher so really doubt she has anything to sell.

As a father of 3, I can tell you elementary school teachers negotiate with terrorists on a daily basis.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#87
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

Essentially all countries do this, regulating trade is a very basic governmental function.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#88
post #63

Earlier quoted context omitted.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

> I wish my health provider had paid the ransom. In practice, this is the same as wishing that other people get hit with ransomware attacks.

I don't think that's quite fair. Each organization, especially ones that possess sensitive customer data, have a custodial duty to secure that data. Most of these attacks are very preventable by following well documented best practices and industry recommendations.

I think that "I wish my health provider paid the ransom" and "Health organizations should be responsible for protecting my data" are completely compatible views to hold.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#89
> This will see the launch of two new information-sharing platforms for participating countries. One will be created by Lithuania while another will be jointly created and hosted by Israel and the United Arab Emirates.

Nice to see smaller countries taking the initiative and also being trusted for projects like this.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#90
post #74

Earlier quoted context omitted.

It took what, over two decades to convince Switzerland and Austria to get on board for (part of) money laundering treaties? And ransom(ware) is not anywhere as pressing.

> took what, over two decades to convince Switzerland and Austria to get on board for (part of) money laundering treaties Yet they still complied with U.S. sanctions. (Or were arrested abroad for defying them.) You seem to misunderstand that sanctions are not a treaty obligation. If your country deals with a sanctioned entity, it gets sanctioned as well. That enforces compliance indirectly. America and and does unila…

Thanks, it's great to know that money laundering is a solved problem.
Post reply on HN