Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

51–60 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#51
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

That's true from a societal perspective, but from the perspective of the victim of ransomware, "just pay the ransom" is even worse advice. Once you have paid the ransom, what incentive does the hacker have to fulfill their end of the bargain? If, for example, a hacker encrypts your hard drive and demands bitcoins as payment, paying the hacker means you're likely out a few bitcoins AND your hard drive is still encrypt…

In this case, I believe both of you are wrong. The ability to blindly conduct ransom en masse changes the calculus.

First, the ransomers have every incentive to actually abide by their promise to decrypt. In essence, they're running a business. Whereas in a kidnapping situation, ransoms are high ransomers tend to stay anonymous, and risk is high, with ransomware the monetary amounts involved are low, the ransomers typically conduct their actions under an established pseudonym, and the risk in upholding their side of the bargain is low. If they were to not hold up their end of the bargain and it became known that "LeetSquad" doesn't actually decrypt data, victims would stop paying. This would be a disaster.

Furthermore, while it's correct that a victim who pays signals their ease of being shaken down, again, the economics of the situation work in the victim's favor. These attacks aren't targeted. Given an effectively endless supply of potentially-paying victims, direct targeting is unnecessary, wasted effort. And again, risk of reputational damage is high. For evidence, look no further than this FBI recommendation!

For further evidence, consider the fact that in practice, these groups overwhelmingly keep their promises and don't appear to specifically re-target previous victims. They even, no joke, have online support staff who will work with you in the event of difficulties unlocking your data!

I had the idea once that one way to combat these groups would be to run a PR and news campaign attempting to convince the general population that ransomware groups will take the money and run, and that they'll just come after you again. Even if it isn't true, a successful campaign might do some serious damage to their profit margins.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#52
post #14

I guess the ransomware will stop unless they throw a few of the crooks in to jail. I presume the NSA or someone like that could probably figure who they are but they are probably in Russia or similar where the courts won't do much. Hence a fix might be to do a deal with Putin or some such? - We'll drop some sanctions if you throw a couple of dozen cybercrooks in jail say.

I presume they are probably in US. Hence a fix might be to do a deal with Obama?

really?

If you have any evidence about authors, you can report to local police who will contact with Interpol and then Russia's police. Russia has all necessary laws to punish cyber criminals.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#53
post #28

Earlier quoted context omitted.

No matter what the FBI says, ransomware is going to continue until vendors ship systems that are secure enough to prevent ransomware by default. Meanwhile, "don't pay the ransom" is not an honest answer to "what's the best thing for me to do now that I'm infected".

is it possible for vendors to ship a system like this that would also allow for users to encrypt their entire hard drives? Maybe it would be something like OS X firmware lockdown, but that is less convenient and takes away a lot of the options for the user. Is this an either/or scenario?

Lots of vendors ship encrypted hard drives. Some of them are even almost secure.

Or are you asking can a vendor prevent a compromised user account from installing pgp and encrypting everything? Probably not very well.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#55

Earlier quoted context omitted.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…

Not in the long-term, because then they gain a reputation as someone not to be "trusted". Many of these outfits have their own support forums, make it easy to pay, etc and happily hand your data back over because they make money in volume, not from one particular mark. You gain a reputation as being easy to work with and unlocking data and offering the support to do so, many more people will pay just to get rid of th…

While I'm sure this is true and some hackers behave based on this idea, there are two issues:

1. "Many of these outfits" is not all: we still need a way to determine whether we should pay a ransom.

2. I'm sure I could manufacture a support forum which shows me to be trustworthy in an afternoon.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#56
post #43
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ev…

[deleted]

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#57
post #28

The FBI should always advise companies never to pay ransoms. It's the only way to stop it. The Bureau doesn't care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive. Whoever is advising people to "just pay the ransom" is a fool.

No matter what the FBI says, ransomware is going to continue until vendors ship systems that are secure enough to prevent ransomware by default. Meanwhile, "don't pay the ransom" is not an honest answer to "what's the best thing for me to do now that I'm infected".

"Don't pay the ransom" is just the first sentence. The rest of the paragraph would be: "Restore your data from backups, and have an IT professional come in and remove the malware if it's also on the backup."

Just telling people to pay the ransom is idiotic. It actually leaves the malware in place, and what guarantee is there that they won't be blackmailed again the next day?

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#58
post #43
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ev…

"If you hunt them down and physically punish them yourselves, you'll go to jail"

The U.S. Constitution actually has provisions for legally doing that. Lobby your congressmen to issue "letters of marque and reprisal", which Congress is authorized to provide precisely for businesses to engage in warlike behavior against pirates et al, which includes the modern form in "ransomware".

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#59
post #43
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ev…

This all assumes that the FBI's purpose is to go after criminals who are harming the citizenry. I am no longer certain that is the purpose of the police (federal, state, or municipal), given their exceptionally poor record of preventing crime, and finding those responsible for crimes.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#60

Earlier quoted context omitted.

Not in the long-term, because then they gain a reputation as someone not to be "trusted". Many of these outfits have their own support forums, make it easy to pay, etc and happily hand your data back over because they make money in volume, not from one particular mark. You gain a reputation as being easy to work with and unlocking data and offering the support to do so, many more people will pay just to get rid of th…

While I'm sure this is true and some hackers behave based on this idea, there are two issues: 1. "Many of these outfits" is not all: we still need a way to determine whether we should pay a ransom. 2. I'm sure I could manufacture a support forum which shows me to be trustworthy in an afternoon.

For (1), this is the reason the ransom is small. Since "many" are actually trustworthy, it's a small risk to pay the relatively small ransom. (Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.)

For (2), could you also find a way to get the FBI to release a statement saying you are trustworthy?

Post reply on HN