Live data from Hacker News

Negotiating ransoms: when to play and when to fold

zetter.substack.com

11–20 of 35 posts

Re: Negotiating ransoms: when to play and when to fold

#11
post #4

I don't think I would ever pay ransom under any circumstances. Not for data or system functionality. I'd throw the computers in the river. I know this about myself because I had to deal with a kidnapping and extortion of my best friend in south america around 15 years ago.. and a few years later a ddos extortion attempt on one of my servers (the criminal was released from prison recently and I won a federal judgment…

For the attacker, this may just be another bullet, another target. Killing or erasing your company's data, for the attacker, may mean absolutely nothing.

How do we go from here? Your job as a negotiator is to get them get them off their "fight mode" through the use of time, dialogue, and empathy.

By saying "I wont negotiate" you're building a gloom vision that there is no future. If the threat is real, you're out of time and out of luck. As Voss says, "She's dead"*

Further readings:

Stalling for Time: My Life as an FBI Hostage Negotiator ( by Gary Noesner)

Never Split the Difference (Chris Voss)

Ego, Authority, Failure (Derek Gaunt)

Movie: A Hijacking (IMDB)

* "60 seconds or she dies" challenge on Youtube (Chris Voss).

Re: Negotiating ransoms: when to play and when to fold

#12
post #11
post #4

I don't think I would ever pay ransom under any circumstances. Not for data or system functionality. I'd throw the computers in the river. I know this about myself because I had to deal with a kidnapping and extortion of my best friend in south america around 15 years ago.. and a few years later a ddos extortion attempt on one of my servers (the criminal was released from prison recently and I won a federal judgment…

For the attacker, this may just be another bullet, another target. Killing or erasing your company's data, for the attacker, may mean absolutely nothing. How do we go from here? Your job as a negotiator is to get them get them off their "fight mode" through the use of time, dialogue, and empathy. By saying "I wont negotiate" you're building a gloom vision that there is no future. If the threat is real, you're out of…

Link to the interesting “60 secs or she dies” roleplay: https://m.youtube.com/watch?v=_NWElrHgbGo

Re: Negotiating ransoms: when to play and when to fold

#14
post #12
post #11

Earlier quoted context omitted.

For the attacker, this may just be another bullet, another target. Killing or erasing your company's data, for the attacker, may mean absolutely nothing. How do we go from here? Your job as a negotiator is to get them get them off their "fight mode" through the use of time, dialogue, and empathy. By saying "I wont negotiate" you're building a gloom vision that there is no future. If the threat is real, you're out of…

Link to the interesting “60 secs or she dies” roleplay: https://m.youtube.com/watch?v=_NWElrHgbGo

There's a bunch of videos (some better than others), that's why i didn't link to one or another.

The goal of this exercise is to control your emotions and behavior. Easier said than done. I can see how the author above had a problem being logical about the situation. I still have those issues myself even knowing what needs to be done, things just happen. Tough skills and even tougher for a "natural born assertive".

Re: Negotiating ransoms: when to play and when to fold

#15
post #3

Before it gets mentioned here is a good post why ransomware gangs love (traceable) Bitcoin. Most of ransomware gangs are more or less well known, not really anonymous. http://jpkoning.blogspot.com/2021/06/why-do-ransomware-gangs...

The FBI could set up a website where you can check whether your Bitcoins were involved in some crime.

This would set up an interesting experiment. Would you accept a $20 dollar bill in the supermarket if you knew it was used in some ransom case? And what if suddenly you knew you owned such a $20 dollar bill? Would you try to get rid of it as quickly as possible?

Re: Negotiating ransoms: when to play and when to fold

#16
post #3

Before it gets mentioned here is a good post why ransomware gangs love (traceable) Bitcoin. Most of ransomware gangs are more or less well known, not really anonymous. http://jpkoning.blogspot.com/2021/06/why-do-ransomware-gangs...

Bitcoin recent changes now allow for untraceable atomic swaps with Monero, breaking any hope of traceability in bitcoin.

Re: Negotiating ransoms: when to play and when to fold

#17
From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild.

But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomware financially viable. IMHO it needs to become socially unacceptable to be ill-prepared for a ransomware attack. I don't care if it was a 0day or whether your security was sloppy. It was your job to be prepared for this.

At CCC events you commonly find a sticker at the exchange tables that reads "Kein Backup, kein Mitleid" - "no backup, no compassion".

But the post makes a good point - you don't need backups. You need restore. Which takes time and is frequently ill planned. Sadly.

Re: Negotiating ransoms: when to play and when to fold

#18

> So you’re like, “Oh great. We have backups, the data is there, but the application to actually do the restoration is encrypted.” From my experience dealing with ransomware, most encrypted applications are not recoverable, even with the key. Those app servers need to be rebuilt or restored. File servers and individual files can be decrypted using the key, but applications get scrambled.

They need to be rebuilt. There’s no ifs or buts about that, once a server has been compromised by a malicious actor it can no longer be trusted. Even if you could just restore functionality you have no guarantees that there’s not a time bomb ticking away to hit you again at some later date now they’ve established you’ll pay out.

Re: Negotiating ransoms: when to play and when to fold

#19
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

Actually — even better point from the post:

> If you discover that the data was corrupted during the encryption process, is it game over?

> Most of the time, yeah. If it’s database files, typically they’re gone.

I hadn't even considered what happens when ransomware tries to encrypt a database while it is in use. That's not gonna end well...

Re: Negotiating ransoms: when to play and when to fold

#20
post #19
post #17

From a practical viewpoint, the question is simply whether the money multiplied by the chance of success is a better option than the money needed to rebuild. But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomwar…

Actually — even better point from the post: > If you discover that the data was corrupted during the encryption process, is it game over? > Most of the time, yeah. If it’s database files, typically they’re gone. I hadn't even considered what happens when ransomware tries to encrypt a database while it is in use. That's not gonna end well...

The ransomware I've come across has lots of special heuristics to try and not destroy your data... Things like taking a copy and then doing an atomic replace...
Post reply on HN