Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

61–70 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#61
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Sure, some will probably do that but then they will have committed insurance fraud.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#62
post #57
post #53

Earlier quoted context omitted.

I have things to say on (French) AXA. Worst insurer I ever had the displeasure to deal with. I will spare you the multi-year history, but if you're an expat: AXA will pretend that once you move out, suddenly all 'modern' financial infrastructure has evaporated and only French cheques exist (not cache-able anywhere in my next country, Netherlands) when refunding the fines and erroneously incurred 'costs'. They'll will…

I used to work for AXA Health insurance. Up until about 2017(!), they were reimbursing people for treatment which was claimed back (as opposed to billed to the insurance company directly) by cheque exclusively, and there were rumours from the finance department that this was because lots of people never bothered to cash in their cheques because of the hassle compared to receiving a direct debit.

It's a large company: these things are not accidental (was home insurance btw). I know French law enforces cheques validity as legal tender, but it's a supremely asshole move to give them out to foreigners/people abroad. They did mail them abroad to me in the end! This is where someone's grandmother came in, but she couldn't cash them either, even with a letter authorising her. Out of all the countries I've lived in Europe, France is the only one where I ever saw cheques in actual usage!

In NL, cheques went out of fashion in the 80ies, and banks haven't had the infrastructure to process them for decades now.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#63

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

A modern manifestation of moral hazard lol

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#64

Earlier quoted context omitted.

If you follow security best practices, you have append-only backups that you can use to restore the encrypted data and don't need insurance at all...

If the ransomware operators follow best practices, their C2 is in those backups too. The data's not encrypted, but without good IT, not for long. Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.

Why is your data executable?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#65
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

You can still have your assurance pay the cost of setting your revenue stream back up the hard way. As long as the money isn't going to the criminal groups.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#66
post #52

Earlier quoted context omitted.

Somewhat interesting that you use an argument against utilitarianism to argue against deontological ethics.

Government intervention is government intervention no matter the context: it seems a good idea at first but it always backfires.

To govern is to intervene, if a government doesn't intervene then what purpose does it have?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#67

Earlier quoted context omitted.

Not surprising. Having insurance just means you're a more attractive target now.

And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…

> This makes you wonder who ends up paying for all of this (with time, energy, money, mental health).

> the insurers don't require you to actually make your security better

Dumb insurers it seems. Money going from dumb actor to smarter actors. This is capitalism.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#68

Earlier quoted context omitted.

If the ransomware operators follow best practices, their C2 is in those backups too. The data's not encrypted, but without good IT, not for long. Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.

Why is your data executable?

I'm really not sure that has a serious answer.

https://en.wikipedia.org/wiki/Infrastructure_as_code

https://en.wikipedia.org/wiki/Virtual_machine

https://en.wikipedia.org/wiki/Disk_image

https://en.wikipedia.org/wiki/Shadow_IT

https://en.wikipedia.org/wiki/Von_Neumann_architecture

Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#70

Earlier quoted context omitted.

Not surprising. Having insurance just means you're a more attractive target now.

And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…

> This makes you wonder who ends up paying for all of this (with time, energy, money, mental health).

The employees who are force-fed "security" crapware that some clueless CTO or other high level manager got sold at a golfing course (or got bribed to do such as Netskope did, see https://news.ycombinator.com/item?id=27047474), evaluated it on the specsheet as "fulfills the requirement of the insurance" and passed the can of turds down the line, for one.

Post reply on HN