Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

101–110 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#101

Earlier quoted context omitted.

>...there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. I've heard this as well. A professor was flying into a less than stable area or Afghanistan and for some reason they were descending just like a normal commercial flight. "What are you doing, we're going to get shot down!". He was used to a steep descent or a spiral to the runway to minimize the risk of getting hi…

You have to wonder how much of that transaction is saving face? The warlord doesn't have to deal with the messy business of trying to shoot down jets belonging to a well-funded army; the military doesn't have to deal with the difficult business of engaging a warlord with local connections and support. Both sides get to wink and imply that they each got the better end of a "business deal". It's Clausewitz in reverse -…

It's the Coase theorem [0] in action! No matter what the laws may or may not be against shooting down planes, the socially efficient outcome of planes not being shot down was arrived at through negotiation.

[0] https://en.wikipedia.org/wiki/Coase_theorem

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#102
post #98

Earlier quoted context omitted.

Umm, no. A well-known sales technique is inflating your own demand. There's no way to know whether she's telling the truth or doing that.

Inflating what, sorry? Unless you have someone who's been kidnapped you're hardly in the market.

You're mistaking what someone says for the way things actually are. I'm talking about them exaggerating how in demand their own services are. The danger of this is especially acute if they do more than one thing.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#103
post #63

Earlier quoted context omitted.

> I wish my health provider had paid the ransom. In practice, this is the same as wishing that other people get hit with ransomware attacks.

I don't think that's quite fair. Each organization, especially ones that possess sensitive customer data, have a custodial duty to secure that data. Most of these attacks are very preventable by following well documented best practices and industry recommendations. I think that "I wish my health provider paid the ransom" and "Health organizations should be responsible for protecting my data" are completely compatible…

If nobody paid the ransom, ransomware attacks would be reduced to nearly zero. Paying the ransom means that other people will get ransomware attacks. So, effectively speaking, wishing someone paid the ransom means that you're also wishing that other will get hit with attacks because that's a direct consequence of paying.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#104

The HN title matches the article headline, but the article headline is horribly inaccurate. This is not about making ransom payments illegal, as many commenters have assumed. They are setting up an international information-sharing system to help track cryptocurrency wallets that are receiving ransom payments.

The headline isn't inaccurate. "End ransomware payments" doesn't necessarily mean "make illegal the act of victims sending ransom payments", even though many are presuming that.

Most of the action on this is on the receiving end of the payment process -- making it difficult for criminals to cash out, freezing their assets, or finding them.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#105
post #86
post #77

Earlier quoted context omitted.

She's now an elementary school teacher so really doubt she has anything to sell.

As a father of 3, I can tell you elementary school teachers negotiate with terrorists on a daily basis.

Best comment of the year. Maybe she's hoping to be rescued if she can get her old job back without so much conflict ;-)

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#106
post #81

Earlier quoted context omitted.

Infected how? Our backups were the data, not code or systems (which were IaC and rebuilt as needed).

For a concrete example, someone could infect an image storing service with code that encrypts (and silently decrypts) the data when it's stored / retrieved. When the hacker removes the decryption key from the running service, the backups will also be inaccessible because they are also encrypted.

Wouldn't this be a bright red flag that is trivial to check for?

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#108
I think this needs to be combined with ways to make companies more resistant to ransomware attacks, and more able to restore their computers if an attack does happen.

If companies could get back on line within 24 hours, they wouldn't pay the ransomware.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#109
post #40

Earlier quoted context omitted.

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

I think ransomware is not really like drugs or hostages.

For drugs, there’s some inherent desire for some people to consume them. Maybe they harm society a bit (in the sense that they might destroy the people that take them), but the main cost for the rest of us is that they fund criminal enterprises because they are illegal. People want drugs, if they could buy them at CVS I suspect they would.

Ransomware is already illegal, we don’t create a new criminal enterprise by making it illegal to do business with them, we just make it harder.

Also, lots go the biggest ransomware gets have been big institutional entities where everything is documented. People just buy drugs in small amounts and consume them, two parties, neither of whom wants to get caught, minimal paper trail. Basically impossible to ban.

For physical hostages—people are desperate to get their friends and family back, and so they’ll go to desperate measures to pay. For ransomware, it is usually an economic decision, nobody’s life is at risk (other than when, like, a hospital is hit). Increasing the cost increases the chance the decision will go the other way. And increases the incentives to keep IT defenses up to date. (I know you didn’t bring up the hostage analogy, I think it is worth noting that the desperation you point to here is really an artifact of the tangent we’re on from the analogy leading us astray).

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#110
post #64

Yup. Maybe it's also time that companies take cybersecurity more seriously, and maybe not just companies, but governments too. If insurance companies would cover ransomware damage, you can be certain those insurance companies would IMMEDIATELY lobby the government to enforce cyber security standards, audits, pentesting etc. It's not happening as long as the NSA is on top of the race of cyberweapons, but once that cha…

Not sure if you're aware, but ransomware insurance is already a significant industry, and the contracts usually stipulate that the client company undergoes some type of regular auditing. From what I've heard, insurance companies are actually kinda souring on the business because it's incredibly bad from an actuarial perspective: many of those targeted are SMBs (i.e. they're not paying the kind of premiums that would…

> that one load-bearing Windows Server 2008 machine in a closet

Hah, that is literally how an old employer of mine got hacked and ransomwared big time.

Post reply on HN