Earlier quoted context omitted.
As an alternative question, how much is this worth stopping? As how much is being spent on these payments overall each year? How would that compare to the massive IT fortification project people are demanding? We don't meaningfully fight bike theft for this reason. The cost of doing so relative to the benefits is just too high. We can debate whether that is reasonable, but that is essentially what has been decided as…
> how much is this worth stopping? Having a physical write-enable switch on the backup devices costs about three cents.
Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
171–180 of 267 posts
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#172Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#173I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…
Paying ransoms can be illegal if it is happening with a sanctioned entity. We need to start holding companies criminally liable having security vulnerabilities that get breached. It is true that there will always be exploits but the issues are usually much more wildly irresponsible security practices and not “didn’t know about the latest 0day” There needs to be a statutory liability to customers and required insuranc…
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#174Earlier quoted context omitted.
They possibly could but a lot of executives would probably prefer that their soon to be ex-company took a hit than that they became personally liable for breaking a federal law.
“We purchased security consulting services who were able to decrypt our ransomware-infected files. We’re not sure of the exact method they used but it worked.”
If they wanted to prevent this kind of behavior there are two straightforward approaches:
- make it also illegal for the consulting company to pay a ransom.
- attach Strict Liability to any ransom payment, even if made through an intermediary. The executives quoted above from the paying company could still face criminal liability for such a payment disguised with plausible deniability https://en.m.wikipedia.org/wiki/Strict_liability
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#175Earlier quoted context omitted.
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
That gets discussed every time, hackers were using prepaid cash services. Ransomware predates cryptocurrencies by decades.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#176Enough of this insanity - these are acts of war, and those responsible should be dealt with through covert, proportional military strikes.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#177The US is going to end up tracking and assassinating these people, if we're not already. Messing with the old money usually doesn't turn out well for whoever's doing it.
Are there actual examples of the US "assassinating" bad actors in this way? That seems farfetched, as opposed to just going after them in the judicial system.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#178Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#179Earlier quoted context omitted.
We don't meaningfully fight bike theft for this reason. And this erodes trust in society and rule of law, and gradually leads to vigilantism, privatization of security, and segregation due to middle-class flight from high-crime areas.
As I said, we can dislike it, but as a society we have basically decided that anything short of reasonably straightforward violent crime/extreme violent crime and high value property crime and easy to prosecute drug crime is not worth the effort. I don't disagree, but I hear very little discussion about low solve rates for smaller crimes.
No, I would say that a few counties have decided this, but the majority of counties have not. In most places, you do get arrested for property crimes, you still serve prison time for this, police still do things like use bait cars and exert resources to catch those who steal, and the idea that property crime should not result in jail time is not widely accepted by the majority of the population.
Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
#180I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
[1] https://www.wired.com/2010/03/manipulated-stock-prices/ [2] https://www.reuters.com/article/us-cybercybersecurity-hackin...