Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

41–50 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#41
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

Not really relevant where (1) they're generally not targeting specific individuals, and (2) once you pay the ransom one time, you can mitigate your future risk with backups and other measures.

> (2) once you pay the ransom one time, you can mitigate your future risk with backups and other measures.

This is assuming they bother to give back your data.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#42

Earlier quoted context omitted.

But are the criminals in this case targeting specific individuals? You can't teach them you're a good target if they're just firing at random anyway.

The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options

Is it?

From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data.

This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of deciding whether to call in order to possibly win a pot. First, I'd determine how much the data is worth to me, and use that to determine my "pot odds":

    pot_odds = ransom / value_of_data
I'd then try to figure out how often hackers actually return the data on a ransom:

    odds_of_data_being_returned ~= times_data_has_been_returned_after_ransom_paid / times_ransom_has_been_paid
At this point, we can decide whether it's a rational choice to pay the ransom:

    if pot_odds 
Areas for research: this is a pretty unsophisticated way of determining the odds of the data being returned. I don't have data on how often hackers return data upon being paid the ransom, but I suspect if we gathered data we could get a better probability. For example, one could use linguistic patterns in the hacker's communication to fingerprint different ransomware hackers, and use that to get a probability for each individual hacker. It's likely that some hackers never return the data, and some hackers always return the data, and each of these probabilities has drastically different effects on the outcome of our decision algorithm.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#43
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ever writing ransomware again.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#44

Earlier quoted context omitted.

> The NSA isn't interested in defensive work these days. Hasn't "a great offense is always the best defense" always been the name of the game? We've gone from fists, to stick and rocks, to spears, to swords, to Greek Fire, to gunpowder, to nuclear weapons. Why not now be the ones to own the power to take down any computer or network? Great efforts in defense aren't necessarily successful or rewarded either, e.g. Reag…

Hasn't "a great offense is always the best defense" always been the name of the game? An air offence against an airfield can put a billion dollars worth of planes out of operation permanently. There's no cyberattack equivalent of that - it's not like bricking a few $1000 PCs would disable foreign cyberattack capabilities.

Only a billion? This is the USA in 2015 we are talking about. A single F-35C costs a third of a billion dollars. So you are talking about 3 planes.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#45
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

That's true from a societal perspective, but from the perspective of the victim of ransomware, "just pay the ransom" is even worse advice. Once you have paid the ransom, what incentive does the hacker have to fulfill their end of the bargain? If, for example, a hacker encrypts your hard drive and demands bitcoins as payment, paying the hacker means you're likely out a few bitcoins AND your hard drive is still encrypt…

The hacker actually has incentive to fulfill their end of the bargain. If they didn't, the victim might go public with this, and then no one would ever pay the ransom.

The hacker wants to be trustworthy here so that new victims will be more likely to pay the ransom because they believe they will actually get their data back.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#46
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

That's true from a societal perspective, but from the perspective of the victim of ransomware, "just pay the ransom" is even worse advice. Once you have paid the ransom, what incentive does the hacker have to fulfill their end of the bargain? If, for example, a hacker encrypts your hard drive and demands bitcoins as payment, paying the hacker means you're likely out a few bitcoins AND your hard drive is still encrypt…

In practice the ransomers do exactly what they offer to do. Most of them are part of one of a very small group of criminal organizations. The Russian mob is making 10s of millions or 100s of millions a year on this. Why would you not fulfil your end of the bargain.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#47
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

First off, that is an excellent comment and again, I love Hacker News. How many communities on the planet will have a Rudyard Kipling poem in their lead comment???

I would have used this stanza as I think it's a little more applicable in this situation:

"We never pay any-one Dane-geld,

   No matter how trifling the cost;

For the end of that game is oppression and shame,

   And the nation that plays it is lost!"

As another commenter said, individuals can prevent themselves from being victimized again by starting a regime of proper backups. It isn't as ideal as arresting the motherfuckers and sentencing them to 25 years in federal prison, but it prevents an individual from being labelled a mark.

On the other hand, when the FBI says 'just pay it', I'd argue that it makes all of North America more vulnerable. The end of this game is oppression and shame, and the nation that plays it is lost.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#48
Um, isn't the reason we have an FBI is to shut down operations such as these? Can't they track payments and have the ransomware operators apprehended, with cooperation from authorities in other countries?

Maybe we should defund the FBI if this is the best advice they can think of.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#50

Earlier quoted context omitted.

The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…

Not in the long-term, because then they gain a reputation as someone not to be "trusted". Many of these outfits have their own support forums, make it easy to pay, etc and happily hand your data back over because they make money in volume, not from one particular mark. You gain a reputation as being easy to work with and unlocking data and offering the support to do so, many more people will pay just to get rid of the headache when their computers are locked down.
Post reply on HN