Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

71–77 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#71

Earlier quoted context omitted.

That's true from a societal perspective, but from the perspective of the victim of ransomware, "just pay the ransom" is even worse advice. Once you have paid the ransom, what incentive does the hacker have to fulfill their end of the bargain? If, for example, a hacker encrypts your hard drive and demands bitcoins as payment, paying the hacker means you're likely out a few bitcoins AND your hard drive is still encrypt…

The hacker actually has incentive to fulfill their end of the bargain. If they didn't, the victim might go public with this, and then no one would ever pay the ransom. The hacker wants to be trustworthy here so that new victims will be more likely to pay the ransom because they believe they will actually get their data back.

What's stopping a victim from paying the ransom and still going public and asserting that the ransomer didn't decrypt the hard drive which hurts the reputation (ha!) of the ransomer and causes other people not to pay?

This might be one of the smarter moves to make so long as you kept your identity as a victim anonymous so you don't get retargeted by the ransomer.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#72
post #62

Earlier quoted context omitted.

> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it? From the perspective of the hacker, the hacker's best move is to take the money and simply demand more. There's zero incentive for the hacker to return the victim's data. This becomes a probablistic situation: the approach I'd take if I were a victim would be to borrow an analogy from poker for the problem of decidin…

"> Unfortunately, for the individual victim, paying is usually the best of a set of bad options Is it?" Also, think what would happen if a ransomer failed to give the data back after being paid. The only benefit for the ransomer on that mark is to then say, "No, now I want x-more dollars." What is the mark going to do then, once the ransomer has proven untrustworthy? Give them yet more money?

99% of the time, no, the mark will give them nothing, but it only takes 1% to make it viable.

I do buy the reputation argument when applied on a larger scale, though. I didn't realize that some of these operations were as large as other commenters have pointed out.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#73
post #14

I guess the ransomware will stop unless they throw a few of the crooks in to jail. I presume the NSA or someone like that could probably figure who they are but they are probably in Russia or similar where the courts won't do much. Hence a fix might be to do a deal with Putin or some such? - We'll drop some sanctions if you throw a couple of dozen cybercrooks in jail say.

I presume they are probably in US. Hence a fix might be to do a deal with Obama? really? If you have any evidence about authors, you can report to local police who will contact with Interpol and then Russia's police. Russia has all necessary laws to punish cyber criminals.

From some googling:

"..FBI’s most wanted list of cybercriminals: Russian hacker Evgeniy Bogachev. Bogachev, the authorities believe, was responsible for operating both viruses... GameOver Zeus and CryptoLocker" http://www.slate.com/articles/technology/technology/2014/06/...

"still appears to be at large in Russia, where officials have shown little interest in helping the FBI"..."What a talented guy," said Mikhail, 23, who recognised Bogachev's FBI photo as the man he would see in the lobby with his wife and nine-year-old daughter. "Sitting at his computer at home, he broke into our enemies' camp, but did not harm his fellow Russians." http://www.telegraph.co.uk/news/worldnews/europe/russia/1088...

"His alleged bank heists topped $100 million"..."Bogachev, 30, who lives luxuriously in Anapa, Russia, a beautiful seaside resort town of 60,000 on the northern coast of the Black Sea, and often sails his yacht to various Black Sea ports, remains a fugitive." http://www.usatoday.com/story/news/nation/2014/06/03/fbi-bus...

Guess the authorities can't find him because yachts are pretty tricky to spot.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#74
post #51

Earlier quoted context omitted.

That's true from a societal perspective, but from the perspective of the victim of ransomware, "just pay the ransom" is even worse advice. Once you have paid the ransom, what incentive does the hacker have to fulfill their end of the bargain? If, for example, a hacker encrypts your hard drive and demands bitcoins as payment, paying the hacker means you're likely out a few bitcoins AND your hard drive is still encrypt…

In this case, I believe both of you are wrong. The ability to blindly conduct ransom en masse changes the calculus. First, the ransomers have every incentive to actually abide by their promise to decrypt. In essence, they're running a business. Whereas in a kidnapping situation, ransoms are high ransomers tend to stay anonymous, and risk is high, with ransomware the monetary amounts involved are low, the ransomers ty…

> run a PR and news campaign attempting to convince the general population that ransomware groups will take the money and run

This would be not enough IMO. Creating and spreading malware that takes money and NOT decrypt data will probably do. PR and news will follow. (And give that money to orphans or starving as a self-justification :)

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#75
post #47

Earlier quoted context omitted.

First off, that is an excellent comment and again, I love Hacker News. How many communities on the planet will have a Rudyard Kipling poem in their lead comment??? I would have used this stanza as I think it's a little more applicable in this situation: "We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that plays it is lost!" As another…

For the cyber-criminals there is little or no per-user cost to implement this attack. The refuse-to-pay strategy works when there is some hope of making their attack not worth their effort. To make it not profitable, you would have to convince such a high percentage of people to not pay that the refuse-to-pay strategy is intractable. Instead, we need to rely on the FBI and other organizations to raise the risk of get…

Very well said - thanks!! :)

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#76
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

That poem has evidently been set to music by Leslie Fish. But all I can find is a parody -- https://www.youtube.com/watch?v=BllIODb81Q8

And if you don't get the parody reference -- it's to the classic "You Bash the Balrog".

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#77
post #6

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. http://www.poetryloverspage.com/poets/kipling/dane_geld.html Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

That poem has evidently been set to music by Leslie Fish. But all I can find is a parody -- https://www.youtube.com/watch?v=BllIODb81Q8 And if you don't get the parody reference -- it's to the classic "You Bash the Balrog".

Actually, I think Mineral Rights is another Fish/Kanefsky parody of the same song.

That one's a reference to a ST:TOS episode.

https://www.youtube.com/watch?v=FPvw0mHbyd0

Post reply on HN