Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

121–130 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#121
post #50
post #47

Earlier quoted context omitted.

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.

There is no need to ban, because Monero is already so niche cryptocurrency that it is unusable for paying ransoms.

You cannot ask ransoms in a currency the victim cannot access.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#122
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

Any lawyer or cyber insurance rep can tell you yes it already exists, and it is called cyber insurance. Lol

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#123

It's unclear who in the USG is actually responsible for enforcing this, especially against those organizations that do send payments anyways.

Any executive action on this would be via sanctions, I presume.

Action by who? The President himself?

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#124
post #41
post #6

Earlier quoted context omitted.

> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, a…

But even when paying the ransom, you still need to roll back a portion of your environment after you've assessed the intrusion. Can you really trust you've patched everything and removed all trace of persistence that was put by the attacker as a contingency to get back in the system?

The easiest targets are those that are publicly known to be vulnerable.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#125
post #40

Earlier quoted context omitted.

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

In the case of corporate, it is often not despair but incompetence and lack of consequences: CEO will get their yearly bonus if the ransom is paid. If the ransom is not paid, the information might leak out that the company lacks good cybersecurity practices and there will be a new CEO.

Or even worse, like shareholder or regulator action, see SolarWinds

https://news.ycombinator.com/item?id=38076636

Note that in the EU under GDRP companies are still liable for privacy violations and related fines if ransomware attackers gain access to your personal details, random or no random (a hack is enough).

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#126

Earlier quoted context omitted.

Any executive action on this would be via sanctions, I presume.

Action by who? The President himself?

The Treasury's Office of Foreign Assets Control is the executive branch department tasked with enforcing sanctions.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#127
post #25

Earlier quoted context omitted.

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

It's not like a bank account. Creating a new address is trivial and scalable.

Now think about how you get funds into that wallet: if your shiny new account has a transaction chain tracing back to a banned address, legitimate merchants aren’t going to accept transactions from you and you’re going to be selling a discount.

If you use a mixer, that expands to cover all of your transactions. Any legitimate business has to worry about complying with local laws and they’re going to stop using options which don’t allow that or cost too much.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#128
post #55

Earlier quoted context omitted.

DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them if the need arises.

> DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them You are vastly overestimating the federal government’s coherence and coördination. Yes, we use black hats. Yes, we still jail and sanction them.

Which is straight out of Macchiavelli's playbook.

The first thing you do after conquering the throne is to bundle up all your pending atrocities in one and eliminate competition. The second thing you do is slaughter the mercenaries you had hired to win your war of ascension.

No reason to leave them around and let the next usurper hire them to dethrone you.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#129
post #40
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

If it's a criminal offence it'll still happen, it just won't be reported.

The gov will pat themselves on the back telling everyone how they've caused a drop in the number of incidents.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#130
post #70
post #18

Earlier quoted context omitted.

That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups…

Can't they check their backups once every few months from an isolated infrastructure?

If they could check the backups for evidence of an intrusion, they would be able to check production for evidence of an intrusion.
Post reply on HN