Live data from Hacker News

FBI’s Advice on Ransomware? Just Pay the Ransom

securityledger.com

1–10 of 77 posts

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#3
Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups.

One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#4
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Just like the Brits could have used the cracked Enigma code to stop each and every German operation during the War, they refrained from doing so and used it only for very specific situations (in order to avoid their cover being blown).

Expect the same behavior from the NSA. They will use their power first and foremost whenever it benefits themselves, not to protect all citizens or corporations.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#5
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

Heck, with the NSA's budget, maybe they should be working on developing 'cures' for it.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#6

    And that is called paying the Dane-geld;
      But we've proved it again and  again,
    That if once you have paid him the Dane-geld
      You never get rid of the Dane.
http://www.poetryloverspage.com/poets/kipling/dane_geld.html

Paying ransom merely teaches the criminal that you're an easy mark that they should demand more ransom from in the future.

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#7
post #3

Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.

[deleted]

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#8
It's probably good advice for any individual person / company who gets infected. Unfortunately, it's terrible advice for society in general, because the blackmailers profit from their crime and will go on to target more people.

I'd guess that the malware users are being quite clever in keeping the ransom demands (relatively) small, to make it easy to choose to pay. They then profit in scale because targetting thousands of people is simple.

Since the ransom payments are in Bit-coin, it's possible to track the payments and work out how much money the scammers are making. Some estimates put it as high as $325 million: http://www.coindesk.com/cryptowall-325-million-bitcoin-ranso...

Re: FBI’s Advice on Ransomware? Just Pay the Ransom

#9
Note that this is not an official statement, this is something that an agent at a conference:

https://nakedsecurity.sophos.com/2015/10/28/did-the-fbi-real... has the official statement:

  The FBI doesn't make recommendations to companies; instead, the Bureau explains
  what the options are for businesses that are affected and how it's up to
  individual companies to decide for themselves the best way to proceed.
  That is, either revert to back up systems, contact a security
  professional, or pay.
Post reply on HN