Live data from Hacker News

Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

ciphercue.com

1–10 of 101 posts

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#2
It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists.

Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#6
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies.

Basic hygiene security hygiene pretty much removes ransomware as a threat.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#8

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

[deleted]

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#9
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

> Basic hygiene security hygiene pretty much removes ransomware as a threat.

It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets.

And no, backups aren't the solution either, they only limit the scope of lost data.

In the end the flaw is fundamental to all major desktop OS'es - neither Windows, Linux nor macOS meaningfully limit the access scope of code running natively on the filesystem. Everything in the user's home directory and all mounted network shares where the user has write permissions bar a few specially protected files/folders is fair game for any malware achieving local code execution.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#10

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

I don't think you can enforce such a rule. I think it's a good approach too.

Another issue is that not paying up and risking restore from underfunded ops dept. might be more expensive than paying up AND making a selected executive look bad. And we can't have that, can we.

Post reply on HN