Live data from Hacker News

UCSF admits it paid NetWalker more than $1M ransom

databreaches.net

31–40 of 68 posts

Re: UCSF admits it paid NetWalker more than $1M ransom

#31
post #11

Earlier quoted context omitted.

I know the university I attended has learned nothing at all. State university in a wealthy US area with over 30,000 students. They still think security is forcing everyone to change passwords once every 6 months. No offer of 2fa of any sort for any service. I stopped using my email address between transcript requests because the whole student/faculty directory is rampant with student employees of local businesses sen…

> A permanent link is a complete mystery of a concept to them as well. Every time sun shines on an article in public media for them the glory is sure to be short lived, because google's link will be broken in 6 months tops. I am baffled that universities (and so many others) don't just use WordPress for publishing their media.

Why would you use crappy free Wordpress when you can pay a couple hundred thousand for a vastly superior MS SharePoint setup...

Re: UCSF admits it paid NetWalker more than $1M ransom

#32

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

What type of insurance does UCSF have for ransomware? Last year, ProPublica noted how some insurance companies like to pay ransom for their business [0].

[0]: https://www.propublica.org/article/the-extortion-economy-how...

Re: UCSF admits it paid NetWalker more than $1M ransom

#34
post #12
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

How about kidnapping insurance? Should that be illegal?

There are reasonable precautions that organizations can take to mitigate a ransomware attack before they happen. You might even say that organizations should be obligated to have some minimum IT infrastructure in place if they're going to be responsible for customer (or student) data in any fashion.

Organizations that try to pinch pennies year after year by avoiding paying for the basics are harming IT in general and they're further harming society by sending money out to criminals that will go on to spend that money on attacking other people and organizations.

Re: UCSF admits it paid NetWalker more than $1M ransom

#35
post #23
post #21

Earlier quoted context omitted.

It's insurance that negotiates and pays ransom. How is that not comparable?

One has to do with a human life. The other has to do with ones and zeroes on a hard drive.

What if the ones and zeros have to do with human life?

Imagine there was a cyber attack on Juicero and software engs throughout SF couldn’t make their Soylent-Bitcoin shakes.

Re: UCSF admits it paid NetWalker more than $1M ransom

#36
post #23

Earlier quoted context omitted.

One has to do with a human life. The other has to do with ones and zeroes on a hard drive.

What if the ones and zeros have to do with human life? Imagine there was a cyber attack on Juicero and software engs throughout SF couldn’t make their Soylent-Bitcoin shakes.

Don't even joke. Think of how many SEs you just shook out of their sleeveless jackets.

Re: UCSF admits it paid NetWalker more than $1M ransom

#37
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

Saying that paying ransoms should be a criminal offense should be a criminal offense

Begin recursion in 3 2 1 go

Re: UCSF admits it paid NetWalker more than $1M ransom

#38
post #12
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

How about kidnapping insurance? Should that be illegal?

Yes. Paying ransom funds the next kidnapping.

Re: UCSF admits it paid NetWalker more than $1M ransom

#39

Earlier quoted context omitted.

> A permanent link is a complete mystery of a concept to them as well. Every time sun shines on an article in public media for them the glory is sure to be short lived, because google's link will be broken in 6 months tops. I am baffled that universities (and so many others) don't just use WordPress for publishing their media.

Why would you use crappy free Wordpress when you can pay a couple hundred thousand for a vastly superior MS SharePoint setup...

Or Drupal, if that's still a thing...

Re: UCSF admits it paid NetWalker more than $1M ransom

#40
post #36

Earlier quoted context omitted.

What if the ones and zeros have to do with human life? Imagine there was a cyber attack on Juicero and software engs throughout SF couldn’t make their Soylent-Bitcoin shakes.

Don't even joke. Think of how many SEs you just shook out of their sleeveless jackets.

Sleeveless jackets? You mean the Patagonia vests?
Post reply on HN