Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

21–30 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#21
post #11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

I assume part of the problem is that it is hard to quantify successes or wins in defense.

What is a good way to protect against ransomware? Symantec buries the lede with the answers (possibly because of conflicting business interests) which are

1. Limit end user access to mapped drives

2. Deploy and maintain a comprehensive backup solution

http://www.symantec.com/connect/blogs/ransomware-dos-and-don...

But really, how do we justify spending thousands of dollars on hardware? I hate myself for saying this but there are real risks of doing too much as well. We could have our own mini tyrannical regime of secure computing a la the TSA security theater.

Effective user education is challenging. Even developers are prone to use elevated user permissions where none is strictly required just for the sake of convenience. I know I've found myself right-clicking visual studio and clicking "Run as administrator" reflexively after just a few months of working on ASP.NET and IIS.

This is a little off-topic but I imagine the whole funding offense vs defense might be a little more "natural" than we like to admit. Imagine you're a defense manager and there's this other guy who is an offense manager. Just as a football analogy, how do you justify your team's worth when the other team says that there is no good way to quantify the worth of the work you're doing and there is a good way to quantify their team's work? I guess what I'm asking is how do we put a dollar and cent value to defensive cyber security? Can we just ask "How much does the business stand to lose if we lost all our data to ransom ware or worse to a competitor?" or would business think that is overreaching?

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#22
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

Or, paying random teaches yourself to make backups. Cryptolocker is essentially a "get-out-of-data-loss-for-a-small-price" card. Alternatives, like your disk having a fatal error, are not nearly as forgiving.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#23
post #11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

> The NSA isn't interested in defensive work these days.

Hasn't "a great offense is always the best defense" always been the name of the game? We've gone from fists, to stick and rocks, to spears, to swords, to Greek Fire, to gunpowder, to nuclear weapons. Why not now be the ones to own the power to take down any computer or network?

Great efforts in defense aren't necessarily successful or rewarded either, e.g. Reagan's "Star Wars"/SDI https://en.wikipedia.org/wiki/Strategic_Defense_Initiative which was widely criticized and failed miserably.

While cyberdefense is not in the same unrealistic realm as SDI was in the 80s, the ways that most people think about security- firewall on the perimeter and/or securing each node, pen testing, patches, and locking down what can be installed/used- don't really solve the problem of having a wide attack vector. Imagine if you could shoot a single soldier out in the field and it would kill his/her whole battalion, the base in which he/she was stationed, and perhaps destroy or weaken the entire army or even armed forces to which he/she belonged? That is the situation now.

Playing ultimate defense requires much more isolation. We shouldn't be on the same network, we shouldn't always be connected, and we should really limit how the outside world can affect each node. That isn't often the case with the networks we have currently.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#24
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Free enterprise? This is an embarrassing extension of the idea of enterprise (Since when can enterprises tax anyhow?). This is racketeering 101 plain and simple. I will burn your business down unless you pay me to protect your business. It is a new application of a very old concept.

Can you imagine the FBI saying, just pay the mafia?

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#25
post #11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

SELinunx and SE for Android are two examples of NSA doing defensive work recently. Also NSA's Information Assurance Directorate puts out guidance[1]. But as to the level of investment in offense versus defense, you'll have to draw your own conclusions.

[1] https://github.com/iadgov

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#26
The FBI should always advise companies never to pay ransoms. It's the only way to stop it. The Bureau doesn't care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive.

Whoever is advising people to "just pay the ransom" is a fool.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#27
post #11
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

This talk by Dan Geer is really great. Worth watching, or reading [1].

[1] http://geer.tinho.net/geer.blackhat.6viii14.txt

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#28

The FBI should always advise companies never to pay ransoms. It's the only way to stop it. The Bureau doesn't care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive. Whoever is advising people to "just pay the ransom" is a fool.

No matter what the FBI says, ransomware is going to continue until vendors ship systems that are secure enough to prevent ransomware by default.

Meanwhile, "don't pay the ransom" is not an honest answer to "what's the best thing for me to do now that I'm infected".

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#29

The FBI should always advise companies never to pay ransoms. It's the only way to stop it. The Bureau doesn't care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive. Whoever is advising people to "just pay the ransom" is a fool.

Next up, FBI will say you should negotiate with the terrorists.

From removing advice that you should encrypt your data, to arguing for backdoors, to advising that you should pay ransoms, Comey has been a complete buffoon.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#30
post #29

The FBI should always advise companies never to pay ransoms. It's the only way to stop it. The Bureau doesn't care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive. Whoever is advising people to "just pay the ransom" is a fool.

Next up, FBI will say you should negotiate with the terrorists. From removing advice that you should encrypt your data, to arguing for backdoors, to advising that you should pay ransoms, Comey has been a complete buffoon.

This has fuck-all to do with James Comey. You might as well blame Obama, or Ban Ki-moon.
Post reply on HN