13 ms·
How common is it that paying the ransom doesn't work? Seems bad for the business model of ransomware, though I guess competing malware writers don't necessarily
by Asdfbla 9y ago
How common is it that paying the ransom doesn't work? Seems bad for the business model of ransomware, though I guess competing malware writers don't necessarily feel compelled to keep the market intact if they can squeeze out a bit more for themselves without the effort of writing a functional decryption routine.
- rplnt 9y agoI think there were instances where the "service" went down after intervention (banned domains, etc). So no one to pay, no one to get keys from.
- croon 9y agoI believe the common rule is that paying works, as per the business reasons you mention. The issue is the victims on aggregate would rather not support the viability of that business. If no one has to pay, the business dies out. Perhaps a pipe dream, but less money at least means fewer actors in the space.
- mnw21cam 9y agoIt works if the good guys haven't shut down the C&C servers used to get the decryption key to the victim.
- LeifCarrotson 9y agoThis is why the phrase "We do not negotiate terrorists" makes sense as a general policy to advocate. It's weakened when we ignore it in individual cases.
- geofft 9y agoLike the prisoner's dilemma, it's a superrational strategy—it yields the best outcomes if you genuinely believe that everyone else is being superrational too. If you don't believe that, the rational thing to do is defect and protect your own interests as best as you can. In the case of superpowers and terrorists, there are usually few superpowers, and (usually) they believe each other to be smart and to have stability of the status quo in mind. In the case of individual ransomware victims, you have no such expectations.
- crdoconnor 9y agoThe good friday agreement was essentially brokered by ignoring it. That seemed preferable to me to the decades of sustained bombings. It seems to me that no government can make a fully plausible promise that they won't yield under pressure and, in any case, terrorism is extremely ill defined.
- alextheparrot 9y agoI believe the phrase is rational for and applied to ransom situations - just generally pursuing peace with opposing parties is not encapsulated in that phrase, to my understanding.
- geofft 9y agoWhat distinguishes an opposing party from a terrorist? (My answer would be, the success of their terrorism. If you are mostly unsuccessful, nobody needs to negotiate with you.)
- 21 9y agoThe Iraq journalist kidnapings from a decade ago showed that all governments negotiate with, and pay terrorists.
- mtmail 9y agoNotPetya/Petya/Netya are also known as 'wipers' because after reverse engineering it turned out the boot sector gets deleted rather than encrypted, so nobody can write a recovery routine. "Affected users are advised to refrain from paying the ransom as that would by no means help them decrypt their data. This advice is particularly true for the NotPetya incident, as the attackers have no means to restore victims’ data." http://www.securityweek.com/notpetya-destructive-wiper-disguised-ransomware http://www.securityweek.com/notpetya-destructive-wiper-disgu...