Live data from Hacker News

Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

ciphercue.com

61–70 of 101 posts

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#61
post #56

Earlier quoted context omitted.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

> all mounted network shares where the user has write permissions This is very literally what 'basic hygiene prevents these problems' addresses. Ransomeware attacks have shown time and again that they way they were able to spread was highly over-permissioned users and services because that's the easy way to get someone to stop complaining that they can't do their job.

"Insider threat model".

Basic security hygiene in the modern world is "assume your employees can be a threat", either because they're incompetent ("I accidentally deleted the shared spreadsheet, I thought it was my copy"), malevolent ("I will show them all!") or compromised ("I clicked a link in my email and now my computer is slow.")

If you aren't designing your systems to be robust against insider threats, they will fail.

(If you design them to be robust against insider threats, they will probably also fail, so you have to be constantly working to understand how to limit the consequences of any individual failure.)

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#62

Earlier quoted context omitted.

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

If the important data is in a web app and the Windows PC is effectively a thin client, this lowers the ransom value of the local drive. Of course business disruption in the form of downtime, overtime IT labor cannot be mitigated by just putting everything online. The next step is just to move to security by design operating systems like ChromeOS where the user is not allowed to run any non-approved executables. If tr…

Getting rid of Windows in favor of an OS with a proper application sandbox like Android would solve so, so many security issues, but that's not viable in most cases because so much software depends on the outdated user-based permissions model most desktop OSs are built around.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#63
post #17

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind. Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'…

If you make it expensive enough to pay ransoms outright, throwing money at security starts looking more appealing.

A ban on paying ransoms isn't the right tool for this. Fine them, punitively, with a portion set aside to incentivize whistleblowing.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#64
post #43

Earlier quoted context omitted.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

OK I agree basic security hygiene removes ransomware as a threat. Now take limited time/budget and off you go making sure basic security hygiene is applied in a company with 500 employees or 100 employees. If you can do that let’s see how it goes with 1000 employees.

I'm not really sure what point you're making. Is the point that it is harder to to secure more things? Is it that security events happen more frequently the higher your number of employees goes?

If so, I bristle at this way that many developers (not necessarily you, but generally) view security: "It's red or it's green."

Attack surface going up as the number of employees rises is expected, and the goal is to manage the risk in the portfolio, not to ensure perfect compliance, because you won't, ever.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#65
post #3

The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

Basic hygiene security hygiene pretty much removes ransomware as a threat.

I cant tell if you’re being flippant, or naive. There is nothing that removes any category of malware as a threat.

Sure, properly isolated backups that run often will mitigate most of the risks from ransomware, but it’s quite a reach to claim that it’s pretty much removed as a threat. Especially since you would still need to cleanup and restore.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#66
post #45
post #17

Earlier quoted context omitted.

It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind. Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'…

That's fine, those are acceptable casualties. Make paying any sort of ransom a criminal offense.

It's all fun and games until it's your livelihood at stake, and then it makes a lot more sense to acquiesce, lick your wounds, and keep your business alive.

Getting hacked is no fun, but companies don't deserve to die because something in their tech stack was vulnerable.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#67
post #64
post #43

Earlier quoted context omitted.

OK I agree basic security hygiene removes ransomware as a threat. Now take limited time/budget and off you go making sure basic security hygiene is applied in a company with 500 employees or 100 employees. If you can do that let’s see how it goes with 1000 employees.

I'm not really sure what point you're making. Is the point that it is harder to to secure more things? Is it that security events happen more frequently the higher your number of employees goes? If so, I bristle at this way that many developers (not necessarily you, but generally) view security: "It's red or it's green." Attack surface going up as the number of employees rises is expected, and the goal is to manage t…

Point is: basic things at scale are hard.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#68
post #41

Earlier quoted context omitted.

The lawsuits come from the issues though.

"We did everything we could, like any decent person would"

Exactly, it's very 'No Way to Prevent This,' Says Only Nation Where This Regularly Happens

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#69
post #45
post #17

Earlier quoted context omitted.

It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind. Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'…

That's fine, those are acceptable casualties. Make paying any sort of ransom a criminal offense.

Sounds impossible to enforce.

The penalty for not paying is often catastrophic. The penalty for paying will have to be similarly impactful.

Post reply on HN