Paying a ransom signals 3 things: 1) you are vulnerable to attack 2) you cannot recover from an attack 3) you've got cash
The result is that you get attacked much, much more. You could ask me how I know, but I wouldn't tell you :)
221–230 of 257 posts
Paying a ransom signals 3 things: 1) you are vulnerable to attack 2) you cannot recover from an attack 3) you've got cash
The result is that you get attacked much, much more. You could ask me how I know, but I wouldn't tell you :)
Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
Its a boon to both the company and the country when a hacker makes a big public deal out of it. Because they get the chance to repair something before its intentional damaging misuse by a hostile state actor.
The hackers here deserve every cent plus possibly more.
And theres always the problem that the hackers would still get paid, they just wont report the payments making tracking difficult.
on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…
This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…
I doubt if everyone would be better off if state level actors found and used these vulnerabilities instead of ransom seekers.
does "yes, I deleted the data" in an email count as digital evidence?
Earlier quoted context omitted.
... except that "policies" don't cut it. Criminal penalties for paying are what you need, and not just for payments to specific designated entities, either. The executive making the decision to pay has to have a real fear of personally spending time in actual prison.
A criminal penalty is a form of policy
Except for payments to specifically sanctioned organizations, the policy is "we'd really rather you didn't do that, but whatever".
The specific sanctions don't cover most of the groups, either, and even when they do cover the group who got paid, you can't necessarily prove the people who got paid were the ones on the list. And there may be a scienter requirement even then; I don't know.
Making a list of specific criminals you can't pay is just stupid. No ransoms, ever, period, or it's da slammah.
on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…
This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…
This will progress the game theory to the point where nobody will pay ransom because the thieves won't honor the deals anyway.
Earlier quoted context omitted.
This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music
Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.
Leaks are inevitable, but the current situation is absurd. The liabilities and incentives to do anything about them are virtually nonexistent and security is almost always viewed as a cost.
Earlier quoted context omitted.
This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music
Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.
Infrastructure’s motivations must have lain elsewhere…
Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
Extortion and terrorism seem similar in many ways except the latter involves physical harm.
I’d asssume a company paying money to terrorists shouldn’t be acceptable.
It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place.
Might as well use a bank whose safe deposit boxes are made of cardboard… They can just bribe the thieves to give some things back.
I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to. (1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but expl…
Those (now former) customers can the be patrons of a competitor that doesn’t let such happen again.