Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

131–140 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#131
post #83

Earlier quoted context omitted.

It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?

Layoff. They were costing the company money for irrelevant problems.

Congratulations: you've just created a culture where people are afraid to report potential issues for fear of losing their jobs. Maybe there are some cases where you find that specific individuals end up acting irrationally more often than not, but on the whole, it is better to treat these acts as if they were good faith until proven otherwise.

Re: The push to ban ransom payments is gaining momentum

#132
post #83

Earlier quoted context omitted.

It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?

The answer from Toyota, where this kind of thing (anyone can stop the assembly line if they think there's a problem) originally came from: if the employee reasonably believed there was a problem, they suffer no consequences (and perhaps even get a merit) for pulling the red cord. Because you lose much more money next time there's a real problem, if no-one dares to stop the machine.

This is the correct policy. Many IT security incidents happen because someone’s afraid of raising the alarm.

If an employee opens a phishing attachment or something, they should be able to report it without fear of losing their job so the incident can be contained.

Instead - they are incentivised to say nothing and hope for the best for fear of getting fired.

Re: The push to ban ransom payments is gaining momentum

#133

Earlier quoted context omitted.

The idea would be to reduce the likelihood of a payout.

And just to spell it out: Fewer payout means fewer resources to spend on further operations. So I would absolutely think that the criminals care if there is an actual ban.

Except, this assumes that the cost of an operation being ran is beyond marginal.

The actual cost of launching an attack like this is basically nothing - initial access, etc, is largely automated and performed at scale.

The “costly” part is the hands on keyboard part, but even that can be largely automated, and even manually doesn’t take long.

Re: The push to ban ransom payments is gaining momentum

#134

For my MSc in Cyber Risk strategy & governance my final dissertation was built on the parallelism of Italy's ban on payment of ransoms for kindnappings and the current ransomware trend. It's difficult to take solid conclusions, the measure could be effective in disrupting some financially motivated attackers but, given the current landscape, I guess the threat actors could shift more towards extorting end users where…

So what’s interesting is only a few years ago, ransomware such as CryptoLocker largely targeted individuals home machines as opposed to companies. Companies being hit was rarer.

The ransom would be a few hundred dollars.

Things got rather interesting after WannaCry and NotPetya - some underground markets/sites banned discussion of ransomware for a while, a lot of groups went quiet.

Then it came back with almost exclusively targeting of enterprise/companies for big payoffs instead of a shitload of small payoffs.

Re: The push to ban ransom payments is gaining momentum

#135
This ban is only ethical if the law authority does this job to stop criminals. Otherwise we end up in the same place as street crime: illegal to defend yourself, but also unprotected the authority that finds it easier deploy violence against victims than criminals.

Re: The push to ban ransom payments is gaining momentum

#136
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

The idea would be to reduce the likelihood of a payout.

This is absurd. There are better ways to do that other than punishing victims...

Do you think we should do similar for theft? Should it be illegal for a store assistant to hand over money to armed robbers, because theoretically if less people handed over money there might be less armed robberies?

And I disagree with what you're saying anyway. I doubt this would stop ransomeware. I think if anything this would just push ransomware to become even more cruel so that they increase the likelihood of their victims choosing to break the law over not giving the ransomware owners what they want.

Re: The push to ban ransom payments is gaining momentum

#137

Earlier quoted context omitted.

They already must report breaches to the FTC and they must report their financials to the IRS. Most companies aren't going to cook their books over this.

Most companies aren't going to unfuck their entire IT infrastructure which was just encrypted and then turned off ? I mean, sure, if the only computer affected is the cafeteria cash register system, they shrug it off and reinstall. But more than a few of these attacks have absolutely crippled the victims, to the point that it would take months/years to roll out a scrubbed system, and even then data is irrevocably los…

I disagree. I think that removing the financial incentive will lead to fewer incidents.

Re: The push to ban ransom payments is gaining momentum

#138
I'm just waiting till the first customer of some shady contract binding them to a greedy software company would use that to declare a payment as illegal and therefore that they cannot make it. Would be funny news like "XYZ says it cant pay oracle, declares it a ransom payment" :D

Re: The push to ban ransom payments is gaining momentum

#139
post #45
post #36

Earlier quoted context omitted.

Are the world police implementing this ban? And are they starting a world war to enforce it? Or how does this ban go into effect in your view?

Well we start with say you, you trade some of your bitcoin holdings, the feds seize your winnings, fine you and toss you in prison.

How do they seize it? Say I’ve got a 256-bit number memorized and I live on a farm in El Salvador.

Is the US sending seal team 6 to interrogate every person trading bitcoin on earth? Or, is that maybe a bit unrealistic?

Re: The push to ban ransom payments is gaining momentum

#140
post #83

Earlier quoted context omitted.

good on your employee who pulled the plug first and asked questions later-- that's the sign of an organization where people aren't afraid to do the right thing. very scary situation.

It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?

If yanking the cord on a single system causes losses that are intolerable to the business, the business has serious continuity problems.

It was an employee today, but the cord was going to get yanked anyways. A data center tech who pulled the wrong cable out, a power cut, a backhoe with a taste for fiber, whatever.

So long as the employee was acting as best they could with the information they had, the resultant business implications are really the businesses' fault. Having a system that cannot be recovered is risky. Assuming that system will never die is foolish. Blaming the employee is pointless.

My vote would be to understand why the employee thought it was necessary to shut the system down, and then educate them (and the rest of the department, since it's probably a collective problem) on why it wasn't necessary and what they could have done instead or how they could have known it wasn't an issue.

That employee probably also deserves a couple days off once the system is recovered (delivered in person, by their manager). It sends a message that they're not in trouble, but more importantly, they're likely fried from trying to juggle internalizing their mistake, getting the system back up, and worrying they're going to get fired because _this_ is how the CEO learned their name. They probably shouldn't be near a prod system for a couple of days until they've come down from the adrenaline and had some time to internalize what happened.

Post reply on HN