Live data from Hacker News

UCSF admits it paid NetWalker more than $1M ransom

databreaches.net

41–50 of 68 posts

Re: UCSF admits it paid NetWalker more than $1M ransom

#41
post #36

Earlier quoted context omitted.

Don't even joke. Think of how many SEs you just shook out of their sleeveless jackets.

Sleeveless jackets? You mean the Patagonia vests?

Yeah lol, I meant to say vest, but I thought it was wrong and edited it to jackets.

Re: UCSF admits it paid NetWalker more than $1M ransom

#42
post #41

Earlier quoted context omitted.

Sleeveless jackets? You mean the Patagonia vests?

Yeah lol, I meant to say vest, but I thought it was wrong and edited it to jackets.

Wasn’t sure if Apple had rebranded vests as sleeveless jackets. Tim Cook like, “You’re going to love what we’ve created and we can’t wait to see how you use it to keep warm while waiting in line at Philz.”

Re: UCSF admits it paid NetWalker more than $1M ransom

#43

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

That poses at most a minor roadblock. You just take over the backup-and-restore service for a little while and corrupt the backups as they get made. If anybody tries to verify the backups they just restore them correctly until they make their demand. Would probably add between $10K and $100K to the cost of attack (probably closer to $10K), so would probably be immaterial to the profitability of this attack. Therefore, even if they did it they would almost absolutely still be attacked with exactly the same consequences if they did not pay the ransom.

Simple "common sense" solutions are pretty close to useless in these scenarios since they provide no meaningful impediment to halfway competent attackers. They stop children and script kiddies which is helpful in that there are a lot more of them, but essentially every actual economically-motivated attack remains viable.

To provide an analogy, the fence around a military base does good work stopping people from just walking onto base, but it does not stop the enemy tanks. That does not mean the fence is useless, it stops one kind of threat, but if tanks might actually attack the base you either need to have a way to stop them or be willing to take the loss. Throwing up more fences so it takes longer for the tanks to roll over all of them is not really meaningful if losing the base is still an unacceptable loss.

Re: UCSF admits it paid NetWalker more than $1M ransom

#44
post #43

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

That poses at most a minor roadblock. You just take over the backup-and-restore service for a little while and corrupt the backups as they get made. If anybody tries to verify the backups they just restore them correctly until they make their demand. Would probably add between $10K and $100K to the cost of attack (probably closer to $10K), so would probably be immaterial to the profitability of this attack. Therefore…

Ehh, a decent backup service (https://www.tarsnap.com/) will give you the ability to make write-only backups over time, i.e. you should be able to roll back to 6 months ago without any chance of something corrupting the backup process.

Of course, it depends how much data you're backing up.

Re: UCSF admits it paid NetWalker more than $1M ransom

#45
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

At the very least, it should be non-negotiable government policy for no government, government agency or public body at any level to pay ransoms.

Re: UCSF admits it paid NetWalker more than $1M ransom

#46
Why isn't paying ransom illegal?

Points:

* Anytime any ransom is paid it is in the most literal sense funding ransom, even more directly than funding terror in the most direct way possible: when you send a check to ISIS that may or may not actually fund terror. Maybe whoever you sent it to is just good at making an ISIS recruitment page and doesn't do much real terror, just marketing.

* But paying a ransom by definition directly funds ransom, far more directly than sending money to ISIS directly funds terror.

* Whoever gets the money at ISIS might spend it at a brothel, there's no proof of terror.

* But whoever gets your ransom when you are ransomed by definition engages in ransom.

* You are funding ransom by definition.

* Additionally, since all rich nations are generally pretty law-abiding, making paying a ransom strongly illegal means that the companies have no choice. They're simply not able to write the check or wire the funds.

* Finally, another strong reason to make it illegal: anyone could claim falsely to be ransomed. If I wanted to fund ISIS I could literally write on a piece of paper which messages to send me in what sequence, and then I could send them money and claim falsely to be ransomed by them.

* Paying a ransom should be strongly illegal.

* Also note that this is a good analogy with "possession of stolen goods" - the fact that such is a crime largely destroys the market for stolen goods. The market would be much stronger if possession of stolen goods weren't a crime.

* There is an argument made about direct consequences: "But if we don't pay they will actually kill my daughter!" The same argument applies directly to paying bribes: "But if we don't pay, we actually can't get a license to sell in that country!" Still, paying bribes abroad for routine administrative work is illegal. Companies can't do it. If they do it, they get fined. Result? 1) (immediately) companies stop doing it. 2) administrators stop requiring it.

The world becomes free of bribery. This proves that making paying bribes illegal works.

Why wouldn't it work for making ransoms illegal? UCSF just funded a ransomist $1M. That should be illegal.

The going rate for a thug in a third world country might be $800 per month. UCSF just paid for one thousand two hundred and fifty man-months of abduction.

Re: UCSF admits it paid NetWalker more than $1M ransom

#47
post #23
post #21

Earlier quoted context omitted.

It's insurance that negotiates and pays ransom. How is that not comparable?

One has to do with a human life. The other has to do with ones and zeroes on a hard drive.

Ones and zeroes on a hard drive and humans lives are fungible.

I don't get this alternate point of view outside of perhaps a belief in god and god may control things without a soul like a hard drive and can't control things with a soul.

Re: UCSF admits it paid NetWalker more than $1M ransom

#48
post #36

Earlier quoted context omitted.

Don't even joke. Think of how many SEs you just shook out of their sleeveless jackets.

Sleeveless jackets? You mean the Patagonia vests?

The Patagonia vests are quite nice though. Fortunately for me I live in a very non-hip locale where nobody else wears them or is aware of their association.

Re: UCSF admits it paid NetWalker more than $1M ransom

#49
post #36

Earlier quoted context omitted.

What if the ones and zeros have to do with human life? Imagine there was a cyber attack on Juicero and software engs throughout SF couldn’t make their Soylent-Bitcoin shakes.

Don't even joke. Think of how many SEs you just shook out of their sleeveless jackets.

I thought that was a stereotype of "wall street bros" and/or billionaires.

Re: UCSF admits it paid NetWalker more than $1M ransom

#50

Why isn't paying ransom illegal? Points: * Anytime any ransom is paid it is in the most literal sense funding ransom, even more directly than funding terror in the most direct way possible: when you send a check to ISIS that may or may not actually fund terror. Maybe whoever you sent it to is just good at making an ISIS recruitment page and doesn't do much real terror, just marketing. * But paying a ransom by definit…

It is true that making a law is how you deal with the conflict between self interest and public interest.

However, if you make something illegal that people have a strong motivation to do, they may just keep doing it, only not as publicly. And in that case, the people who demand ransom will not be particularly discouraged. Their business may improve, because victims will have an incentive to keep the whole thing secret.

Think about how people worry that enforcing immigration laws will lead to violent crime being ignored.

Post reply on HN