Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

11–20 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]:

    I suggest that the cybersecurity tool-set favors offense these days.
    Chris Inglis, recently retired NSA Deputy Director, remarked that
    if we were to score cyber the way we score soccer, the tally would
    be 462-456 twenty minutes into the game, i.e., all offense.  I will
    take his comment as confirming at the highest level not only the
    dual use nature of cybersecurity but also confirming that offense
    is where the innovations that only States can afford is going on.
This is a serious problem, not only from the problems intelligence angies with many powers and poor oversight; ignoring defense is going to bite a lot of people in bad ways. We are already seeing the beginnings of this with the escalating impact computer-based attacks are having on their victims.

I also recommend considering Jacob Appelbaum's response to this question[2] from the audience - from someone currently working for the NSA. The summary is that we need people doing NSA-style work, but on the defense side, and we need it now. If the NSA isn't doing that, then maybe people that want to actually protect their country should find somewhere else to work that is actually working on defense.

[1] https://www.youtube.com/watch?v=nT-TGvYOBpI#t=478

[2] https://www.youtube.com/watch?v=n9Xw3z-8oP4#t=4027

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#12
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

This is precisely exactly like saying that if in xyzland rape with impunity becomes rampant, "Looks like free enterprise has just introduced a rape tax on not having brothers."

To be blunt, if you think like this and make legal arguments like this, you don't understand western civilization and should go and think for a while about all of society.

Unless of course you're kidding and being cynical.

It's 2015: computing is part of society, and computing free from attacks is little different from walking about in public unharmed. It takes massive contortions of perception to feel otherwise. Everyone is online! (Just as everyone goes out now and then.)

Ransomware is almost literally still just ransom.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#13
post #4
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Just like the Brits could have used the cracked Enigma code to stop each and every German operation during the War, they refrained from doing so and used it only for very specific situations (in order to avoid their cover being blown). Expect the same behavior from the NSA. They will use their power first and foremost whenever it benefits themselves, not to protect all citizens or corporations.

Um, what?

The Brits acted sparingly using the cracked Enigma code precisely because they were trying to protect as many citizens as they could -- if they acted every time, the Germans would have figured out the code was compromised and switched to a stronger code.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#14
I guess the ransomware will stop unless they throw a few of the crooks in to jail. I presume the NSA or someone like that could probably figure who they are but they are probably in Russia or similar where the courts won't do much. Hence a fix might be to do a deal with Putin or some such? - We'll drop some sanctions if you throw a couple of dozen cybercrooks in jail say.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#15

Surely more sensible advice would have been: make sure you have offline backups; but if you don't, pay the ransom.

   Still, the Boston head of cyber said that organizations
   that have procedures in place for regularly backing up 
   their data can avoid paying a ransom at all, by simply 
   restoring the infected system to a state prior to the 
   infection.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#16
post #4
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Just like the Brits could have used the cracked Enigma code to stop each and every German operation during the War, they refrained from doing so and used it only for very specific situations (in order to avoid their cover being blown). Expect the same behavior from the NSA. They will use their power first and foremost whenever it benefits themselves, not to protect all citizens or corporations.

Except now everyone knows a lot about the capabilities of the NSA, and every serious criminal is already using the strongest encryption available and doesn't have any course of action for when the NSA is onto them.

It would be like if the British "blew their cover" and the Germans could only respond by completely ceasing all encrypted communication. Not the best possible outcome if they do, but still a positive outcome.

It's an even better outcome for cybercrime, since ceasing all communications would mean ceasing everything. If the NSA did this, the criminal would probably just stop operating, which means they might not be brought to justice, but at least the attacks would stop.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#17
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

But are the criminals in this case targeting specific individuals? You can't teach them you're a good target if they're just firing at random anyway.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#18
post #11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

Exactly my thoughts. NSA was supposed to provide measures to protect the network of the government. But see the OPM's breach as one example.

Seems NSA is obsessed with penetrating everywhere using 'terrorism' as a means to ensure continued funding. Thus the 'defense' nature is quite boring and sadly ignored.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#19
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

But are the criminals in this case targeting specific individuals? You can't teach them you're a good target if they're just firing at random anyway.

Even firing at random is a better strategy in a target-rich environment compared to an environment where your targets either don't pay out or attempt to fight back.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#20
post #8

It's probably good advice for any individual person / company who gets infected. Unfortunately, it's terrible advice for society in general, because the blackmailers profit from their crime and will go on to target more people. I'd guess that the malware users are being quite clever in keeping the ransom demands (relatively) small, to make it easy to choose to pay. They then profit in scale because targetting thousan…

It's irrelevant advice for society in general, because just like with spam, the costs of producing this are so low that even if the FBI had convinced 99% of people not to pay, it'd still be worth it for the scammers.
Post reply on HN