Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
101–105 of 105 posts
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#102Can’t we just disallow email messages from anyone that is not either in the organisation or messaged by a user before? No more ransomware, or at least not as easily.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#103Earlier quoted context omitted.
a cybersecurity company to which you pay an annual retainer will just pay the attackers instead. Communication will be done by lawyers and subject to strong confidentiality protection, no one will ever know. Basically, exactly how it happens with kidnappings today.
Attorney-client privilege does not extend to lawyers doing illegal things on your behalf. For example, you can't ask your lawyer to hire a hitman to off a guy, and any evidence related to such activity will not be protected by attorney-client privilege.
It's literally illegal to pay certain sanctioned organizations today for kidnappings - because they are designated terrorist orgs.
Who negotiates the ransom? Lawyers and security firms, been going on for a long long time.
Amusingly enough, this has even gone through courts in some places, you might wanna look up caselaw. They just decided to classify kidnappers as "criminals" for the ransom purposes, or some other such wordsmithing.
In the US these laws are simply ignored outright.
"The United States Code prohibits funding terrorist organizations, which includes the payment of ransom monies to terrorist organizations.2 However, the outlook in the United States on ransom payments being made to terrorist groups has softened. In June 2015, President Obama announced that private parties may negotiate with and pay ransoms to terrorist groups without fear of criminal prosecution, which has been the informal practice for years. In fact, nobody has ever been prosecuted for paying a ransom in the United States."
Just imagine your election prospects after jailing a mother who paid a ransom to save her child.
Imagine defending a claim that such law is constitutional, moral and just.
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#104Earlier quoted context omitted.
Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…
The chance of actually getting the data back are not that good https://www.msspalert.com/cybersecurity-research/71-ransomwa...
Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
#105Earlier quoted context omitted.
I'm really not sure that has a serious answer. https://en.wikipedia.org/wiki/Infrastructure_as_code https://en.wikipedia.org/wiki/Virtual_machine https://en.wikipedia.org/wiki/Disk_image https://en.wikipedia.org/wiki/Shadow_IT https://en.wikipedia.org/wiki/Von_Neumann_architecture Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.
> https://en.wikipedia.org/wiki/Infrastructure_as_code > "definition files" Not executable. Text. Readable by humans. Inspectable by humans so you can root out rootkits. Not even the valuable data that cyber criminals go for anyway - they go for personal and financial data , not k8s config files. > https://en.wikipedia.org/wiki/Virtual_machine > https://en.wikipedia.org/wiki/Disk_image Neither of those are relevant.…
> If those are actually shadow IT, they won't be in the backups anyway.
Okay whatever then. I really don't have the energy. I'm just depressed people might believe you.