Live data from Hacker News

Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

nbcboston.com

121–130 of 267 posts

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#121

A federal ban on paying ransomeware would reduce the incentive to commit these attacks.

Would this result in not paying or them hiring consultants who pay on their behalf and just invoice them for "resolution services"?

I wonder where this pop-understanding of the law that seems prevalent on HN comes from.

Loopholes exist, but in general the government is not terrible at figuring out basic schemes like this and adapt administration of the law.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#122
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

The Risky Business podcast #624 talks about pretty much all your questions if your want to listen to it. But here's some relevant info: Hardening can help, but we'll always have new exploits and some of the time the intrusion comes from standard fishing rather than automation, so tech can't solve it. Crypto coins enable payment at scale, but Russia enables the operation to not worry about consequences (a lot of ransomware will disable itself on Russian computers to avoid local prosecution).

And in my opinion it's only a matter of time till something so crucial will be affected that the big guns will be rolled out. (I.e. targeted 3 letter agencies efforts) The podcast argued that touching the energy delivery / pipeline was already it - Fox asking daily how the current administration fails to deal with securing energy may be the point when some real action happens.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#123

A federal ban on paying ransomeware would reduce the incentive to commit these attacks.

It wouldn't reduce the incentive for state-level or state-funded attackers to target foreign infrastructure, though.

> wouldn't reduce the incentive for state-level or state-funded attackers to target foreign infrastructure

No, that’s what our military is for. That said, we have limited evidence any of these recent attacks were state backed.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#124
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.

How do you know that we’re not less secure?

It wouldn’t surprise me at all if our systems are on average far less secure simply because so much more is online now, to speak nothing of increases in the complexity of and opportunities for errors and misconfigurations in today’s systems.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#126

Earlier quoted context omitted.

You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that? Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business…

You would be able to get affordable private insurance if you had a cyber security team.

[deleted]

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#127
post #103

Earlier quoted context omitted.

Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.

That gets discussed every time, hackers were using prepaid cash services. Ransomware predates cryptocurrencies by decades.

It's a bit of the "we have X at home" meme situation. Sure, ransomware existed before, but the scale was not even close to that. You can't move hundreds of millions in gift / prepaid cards without getting found. It's a completely different level of comfort for the operators.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#128
post #8

Earlier quoted context omitted.

Nope, no point banning the thing the criminals use, because they don’t follow the law anyway. Ban paying ransoms, the corporations are much more likely to follow the law.

Of the three most common ransomware-combating suggestions I've been observing over the past few months, I'm strongly opposed to the first two (banning cryptocurrencies or banning ransom payments) and would instead strongly advocate for the third: reinstitute letters of marque for privateers. Enable activity instead of futilely trying to ban activity. Instead of focusing on punishing the victims and unrelated third pa…

So your answer to the problem is to encourage more ransomware attacks? You don't think ransomware itself is bad, you just take issue with the idea that you may be the victim? Training more people to use it's probably going to backfire on you then.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#129

Earlier quoted context omitted.

Would this result in not paying or them hiring consultants who pay on their behalf and just invoice them for "resolution services"?

I wonder where this pop-understanding of the law that seems prevalent on HN comes from. Loopholes exist, but in general the government is not terrible at figuring out basic schemes like this and adapt administration of the law.

I think a lot of the HN crowd think of laws like computer code- that it needs to be very exact. Most laws are fairly generalized with broad coverage, and the cases where they're not tend to be the exception, not the rule.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#130

The US is going to end up tracking and assassinating these people, if we're not already. Messing with the old money usually doesn't turn out well for whoever's doing it.

Not just the US. A lot of countries care. Western Europe (not sure about the east) does as well and will do something even if they aren't as violent as the US. (In fact they are probably going to claim the moral high ground of not assassinating people only because they give evidence to the US and look the other way). South America, South Asia, and Africa will all have at least some helping out, though it isn't clear who will do what.

Most of the blame is going to Russia, though North Korea is a possible source of this, as are a few random countries scattered around. Most stand to lose more than they gain from allowing such crime. (their military might be interested in the ability, but those will be more careful about who they target)

Post reply on HN