Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

161–170 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#161

Earlier quoted context omitted.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

The randsomware seems like a side issue. Evidently, your health provider doesn't care that much about your health records. Even ignoring security issues, they had no reliable backup. A fire would have produced this result.

[deleted]

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#162
post #122
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

Any lawyer or cyber insurance rep can tell you yes it already exists, and it is called cyber insurance. Lol

Once you get into the nuts and bolts of cyber insurance you often find you aren't covered in that regard and it is becoming extremely expensive

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#163

It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

This is the reality of where the pay/don't pay falls down.

If your records have been encrypted and taken, you have already taken a reputational hit to sensitive information. If you can recover your operations then you shouldn't even think about paying the ransom. However, if your systems have been encrypted AND you can't recover them AND not having your systems is catastrophic to your business continuing then you may consider paying the ransom. Hopefully with a renewed understanding of how important it is to have appropriate information security controls in place.

The only way not paying ransoms will happen, is if it is made illegal or there are significant penalties as a result of doing so. Otherwise, for some businesses not paying the ransom when their systems are offline is too risky.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#164
post #41
post #6

Earlier quoted context omitted.

> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, a…

But even when paying the ransom, you still need to roll back a portion of your environment after you've assessed the intrusion. Can you really trust you've patched everything and removed all trace of persistence that was put by the attacker as a contingency to get back in the system?

That's the job of an external cyber incident response team who can trace how it occurred and to check that the vulnerability has been appropriately eradicated and locked before resuming business operations

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#165
The reality of where the pay/don't pay falls down.

If your records have been encrypted and taken, you have already taken a reputational hit to sensitive information. If you can recover your operations then you shouldn't even think about paying the ransom.

However, if your systems have been encrypted AND you can't recover them in a reasonable way AND not having your systems is catastrophic to your business continuing then this is where companies consider paying. Hopefully with a renewed understanding of how important it is to have appropriate information security controls in place.

The only way not paying ransoms will happen, is if it is made illegal or there are significant penalties as a result of doing so. Otherwise, for some businesses not paying the ransom when their systems are offline is just too risky.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#166
post #69

Earlier quoted context omitted.

>they bend the curve Upwards. Second order effects of schemes like prohibition are much worse than the original problems. It's also not quite analogous to the ransomware prohibition, because it's more akin to a prisoner's dilemma, and there's no inherent desire to pay ransomware criminals in the human psyche like there is to alter consciousness.

> Second order effects of schemes like prohibition are much worse than the original problems. There are loads of countries that have illegalized alcohol and not devolved into levels of organized crime that the US did. Specifically, nearly every Muslim nation on earth. I feel this one example is way overplayed by advocates of legalization

Well, I guess if you think ruin or death is a valid consequence for fairly low stakes "crimes", you can implement pretty much any regime you like, assuming you've got enough boots and knives.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#167
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

Essentially all countries do this, regulating trade is a very basic governmental function.

Is paying ransom considered a trade in conventional sense?

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#168
post #167

Earlier quoted context omitted.

Essentially all countries do this, regulating trade is a very basic governmental function.

Is paying ransom considered a trade in conventional sense?

"Trade" encompasses anything that involves the transfer of goods, services, and/or money between different parties.

Those who do ransoming and racketeering are participating in a subset of trade more specifically called "illicit trade".

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#169

Earlier quoted context omitted.

Action by who? The President himself?

The Treasury's Office of Foreign Assets Control is the executive branch department tasked with enforcing sanctions.

On domestic organizations, local governments, etc.?

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#170
> Partner countries will share a "black list" through the U.S. Department of Treasury that will include information on digital wallets being used to move ransomware payments

I don't think they realize how easy it is to generate new wallet. Nobody is going to use their home wallet address to demand ransom

Post reply on HN