Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

61–70 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#61
post #47
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

First off, that is an excellent comment and again, I love Hacker News. How many communities on the planet will have a Rudyard Kipling poem in their lead comment??? I would have used this stanza as I think it's a little more applicable in this situation: "We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that plays it is lost!" As another…

For the cyber-criminals there is little or no per-user cost to implement this attack. The refuse-to-pay strategy works when there is some hope of making their attack not worth their effort. To make it not profitable, you would have to convince such a high percentage of people to not pay that the refuse-to-pay strategy is intractable. Instead, we need to rely on the FBI and other organizations to raise the risk of getting caught.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#62

Earlier quoted context omitted.

The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…

"> Unfortunately, for the individual victim, paying is usually the best of a set of bad options

Is it?"

Also, think what would happen if a ransomer failed to give the data back after being paid. The only benefit for the ransomer on that mark is to then say, "No, now I want x-more dollars." What is the mark going to do then, once the ransomer has proven untrustworthy? Give them yet more money?

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#64
post #43

Earlier quoted context omitted.

They want you to reinforce the ransomware creator's behaviour, but if you hunt them down and physically punish them yourselves, you'll go to jail. Why does a democratic government exist, and why do I pay taxes to support it? In my opinion, the FBI is the slacker here. We are paying taxes to the government for services which should include hunting down and making examples of the perps so that they think twice about ev…

"If you hunt them down and physically punish them yourselves, you'll go to jail" The U.S. Constitution actually has provisions for legally doing that. Lobby your congressmen to issue "letters of marque and reprisal", which Congress is authorized to provide precisely for businesses to engage in warlike behavior against pirates et al, which includes the modern form in "ransomware".

That's a slippery slope which is bound to harm innocent parties. Large corporations would just love to get letters of marque and reprisal, let's hope that it is not authorized by Congress anytime soon.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#65

Earlier quoted context omitted.

While I'm sure this is true and some hackers behave based on this idea, there are two issues: 1. "Many of these outfits" is not all: we still need a way to determine whether we should pay a ransom. 2. I'm sure I could manufacture a support forum which shows me to be trustworthy in an afternoon.

For (1), this is the reason the ransom is small. Since "many" are actually trustworthy, it's a small risk to pay the relatively small ransom. (Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.) For (2), could you also find a way to get the FBI to release a statement saying you are trustworthy?

Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.

How so? Presumably they use a different one for each payment, no? Otherwise, how could they tell who paid?

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#66
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

The government is already accused of being in bed with commerce all the time ala fascism comparisons, NSA helping companies directly like this could be viewed as favoritism for big companies and politically dangerous. Also, NSA's offensive mission is historically to attack nation-states aligned to the federal government's needs rather than to attack commercially motivated hackers. This is blurring with national security issues like espionage and economic terrorism coming into play, but this again raises the question of where the dividing line between helping private enterprise with tax dollars should go compared to doing something for everyone's benefit.

There is also a defensive side to NSA's mission that is defense-oriented (IAD), but the most recognizable contributions that most of the HN crowd may be familiar with are SELinux and perhaps a modest body of research involving how to secure your systems (the defense side is much more open than the offensive side). The problems I see there is that these measures are all very much aimed at large corporations, not start-ups (seriously, I can count the number of start-ups outside the intelligence / DoD space I've ever heard of that use SELinux or follow NSA hardening guidelines on two fingers) and there is clearly a huge gap between how much big businesses take security seriously compared to start-ups from both a cultural and business driven set of motivations.

The number of start-ups derailed / completely wiped out by extortion attempts is rather small compared to the number that actually exist but the legions of security consulting companies around the DC beltway wants everyone to think that it's really terrible and that everyone's a target. The truth is that everyone needs to be secure "enough" to not be as vulnerable as the really stupid guys and that while it might sting a lot to be down for a few hours or so and lose revenue / trust from users, diverting your company's resources towards hardening so much is quite costly for smaller companies and it's just more practical to have really fast re-provisioning set as a priority for your devops / ops engineers (most start-ups can do this far better than larger companies).

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#67
post #25
post #11

Earlier quoted context omitted.

The NSA isn't interested in defensive work these days. As Dan Geer explained[1]: I suggest that the cybersecurity tool-set favors offense these days. Chris Inglis, recently retired NSA Deputy Director, remarked that if we were to score cyber the way we score soccer, the tally would be 462-456 twenty minutes into the game, i.e., all offense. I will take his comment as confirming at the highest level not only the dual…

SELinunx and SE for Android are two examples of NSA doing defensive work recently. Also NSA's Information Assurance Directorate puts out guidance[1]. But as to the level of investment in offense versus defense, you'll have to draw your own conclusions. [1] https://github.com/iadgov

SELinux made its public debut seventeen years ago, so it's not the best example of "recent" defensive work done by the NSA. ;)

To speak about SE for Android: I'm not sure how much weight I would lend to a few NSA employees helping Google/AOSP create SELinux profiles for Android. (It is recent work, though!)

I'm fairly certain that I would lend a lot of weight to public efforts to harden systems against the kinds of attacks that their TAO division launches.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#68

Earlier quoted context omitted.

For (1), this is the reason the ransom is small. Since "many" are actually trustworthy, it's a small risk to pay the relatively small ransom. (Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back.) For (2), could you also find a way to get the FBI to release a statement saying you are trustworthy?

Also, you can verify via bitcoin address if you're dealing with a hacker who is known to give data back. How so? Presumably they use a different one for each payment, no? Otherwise, how could they tell who paid?

Apparently they reuse the primary wallet quite frequently:

http://www.coindesk.com/cryptowall-325-million-bitcoin-ranso...

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#69
For the record, it's the FBI's advice on cryptowall, cryptolocker and their ilk that it's easier to pay the ransom because it's largely automated to the point that no human is directly involved in processing your ransom and returning the keys to your files - the web site you're directed to even gives you one single file recovered for free. Isn't technology grand? Aren't the disenfranchised youth of Eastern Europe (the primary agents responsible for crypto-ransomware) generous? So unless you had backups from before you were infected, pay the automated system its Bitcoin. It's a shame that so many people have this as their introduction to cryptocurrency.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#70

Earlier quoted context omitted.

The 'you' in this case is all of us, collectively. Unfortunately, for the individual victim, paying is usually the best of a set of bad options, even though it is not the best one for us, collectively.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…

The vast majority of the "hackers" never see you signing in and paying the Bitcoin. The systems are automated to the point that paying the ransom triggers a process that results in the browser passing the decryption key back to the client-side malware which then decrypts your file. Electronic software delivery is a much more economical way for these enterprising thugs to be profitable at scale.
Post reply on HN