I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…
The Risky Business podcast #624 talks about pretty much all your questions if your want to listen to it. But here's some relevant info: Hardening can help, but we'll always have new exploits and some of the time the intrusion comes from standard fishing rather than automation, so tech can't solve it. Crypto coins enable payment at scale, but Russia enables the operation to not worry about consequences (a lot of ranso…
I remember reading how supposedly adding a Russian or a few other keyboard layouts might fool some of the malware to ignore the machine [1].
I guess one idea for the Western intel agencies could be to play off of that, and somehow disable that check (infect their malware) such that it can and does attack the Russian infrastructure.
[1] https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...