And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.
First off, that is an excellent comment and again, I love Hacker News. How many communities on the planet will have a Rudyard Kipling poem in their lead comment??? I would have used this stanza as I think it's a little more applicable in this situation: "We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that plays it is lost!" As another…
FBI’s Advice on Ransomware? Just Pay the Ransom
61–70 of 77 posts
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#62Earlier quoted context omitted.
The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.
> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…
Is it?"
Also, think what would happen if a ransomer failed to give the data back after being paid. The only benefit for the ransomer on that mark is to then say, "No, now I want x-more dollars." What is the mark going to do then, once the ransomer has proven untrustworthy? Give them yet more money?
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#63Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#64Earlier quoted context omitted.
They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ev…
"If you hunt them down and physically punish them yourselves, you'll go to jail" The U.S. Constitution actually has provisions for legally doing that. Lobby your congressmen to issue "letters of marque and reprisal", which Congress is authorized to provide precisely for businesses to engage in warlike behavior against pirates et al, which includes the modern form in "ransomware".
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#65Earlier quoted context omitted.
While I'm sure this is true and some hackers behave based on this idea, there are two issues: 1. "Many of these outfits" is not all: we still need a way to determine whether we should pay a ransom. 2. I'm sure I could manufacture a support forum which shows me to be trustworthy in an afternoon.
For (1), this is the reason the ransom is small. Since "many" are actually trustworthy, it's a small risk to pay the relatively small ransom. (Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.) For (2), could you also find a way to get the FBI to release a statement saying you are trustworthy?
How so? Presumably they use a different one for each payment, no? Otherwise, how could they tell who paid?
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#66Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.
There is also a defensive side to NSA's mission that is defense-oriented (IAD), but the most recognizable contributions that most of the HN crowd may be familiar with are SELinux and perhaps a modest body of research involving how to secure your systems (the defense side is much more open than the offensive side). The problems I see there is that these measures are all very much aimed at large corporations, not start-ups (seriously, I can count the number of start-ups outside the intelligence / DoD space I've ever heard of that use SELinux or follow NSA hardening guidelines on two fingers) and there is clearly a huge gap between how much big businesses take security seriously compared to start-ups from both a cultural and business driven set of motivations.
The number of start-ups derailed / completely wiped out by extortion attempts is rather small compared to the number that actually exist but the legions of security consulting companies around the DC beltway wants everyone to think that it's really terrible and that everyone's a target. The truth is that everyone needs to be secure "enough" to not be as vulnerable as the really stupid guys and that while it might sting a lot to be down for a few hours or so and lose revenue / trust from users, diverting your company's resources towards hardening so much is quite costly for smaller companies and it's just more practical to have really fast re-provisioning set as a priority for your devops / ops engineers (most start-ups can do this far better than larger companies).
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#67Earlier quoted context omitted.
The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…
SELinunx and SE for Android are two examples of NSA doing defensive work recently. Also NSA's Information Assurance Directorate puts out guidance[1]. But as to the level of investment in offense versus defense, you'll have to draw your own conclusions. [1] https://github.com/iadgov
To speak about SE for Android: I'm not sure how much weight I would lend to a few NSA employees helping Google/AOSP create SELinux profiles for Android. (It is recent work, though!)
I'm fairly certain that I would lend a lot of weight to public efforts to harden systems against the kinds of attacks that their TAO division launches.
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#68Earlier quoted context omitted.
For (1), this is the reason the ransom is small. Since "many" are actually trustworthy, it's a small risk to pay the relatively small ransom. (Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.) For (2), could you also find a way to get the FBI to release a statement saying you are trustworthy?
Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back. How so? Presumably they use a different one for each payment, no? Otherwise, how could they tell who paid?
http://www.coindesk.com/cryptowall-325-million-bitcoin-ranso...
Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#69Re: FBI’s Advice on Ransomware? Just Pay the Ransom
#70Earlier quoted context omitted.
The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.
> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…