5 ms·
Aren't these criminals providing a useful service to society? Corporations (and the governments that are supposed to set and enforce standards) are clearly fai
by autosharp 6y ago
Aren't these criminals providing a useful service to society?
Corporations (and the governments that are supposed to set and enforce standards) are clearly failing to protect the data that is collected about people. These criminals are increasing the incentive for corporate data security.
The Equifax case is a good example of the problem. They leaked data on lots of Americans, who never agreed to their data being collected, they externalized an enormous amount of damage they created, and they are still in business. Government is clearly failing here.
I feel safer knowing that there are people out there, hunting down these unsecured caches of data.
- intrasight 6y agoAn analogy. Perhaps 20% of modern integrated circuits are dedicated to testing. Perhaps the same percent of GDP is spent combating crime. In a ideal world, we'd not need to waste all that silicon real estate on testing. And in an ideal world, we wouldn't be wasting resource on combating crime. But the world is not ideal.
- hammock 6y ago>Aren't these criminals providing a useful service to society? Maybe if the ransom paid was required to be spent on data security improvements...
- emidln 6y ago> I feel safer knowing that there are people out there, hunting down these unsecured caches of data. There's very little difference between maliciously encrypting someone's data once you have managed to establish code execution vs exfiltrating all of the data and then using any PII to open lines of credit. For you as a consumer, the former doesn't harm you. The later has the ability to harm you quite a bit in ways that take months/years to sort out. Do you really feel safer because the criminals that cracked these systems flipped a coin that landed on the "extort our victim" side rather than the "free leads to customers of our victims" side?
- c22 6y agoYes, that's the point. These organizations holding my PII haven't historically given half a damn if all my data gets exfiltrated or not. By electing to pursue the other side of the coin these attackers provide incentive for those companies to batten down the hatches, causing my PII to become more protected as a side-effect, thus leading to a greater feeling of safety.
- gowld 6y agoOK but they aren't.
- zie 6y agoMore incentive to at least make sure their backups work.. but not enough incentive... yet, to actually increase security. So I don't disagree with your premise, I'm just not sure it's actually true in real life, where companies are not punished by anyone for being lazy.
- c22 6y agoI don't have any evidence either way so all I can do is appeal to common sense, but I can't imagine most of the organizations hit by ransomware didn't at least devote some extra amount of attention or resources towards IT security in response. At a bare minimum I'd expect them to at least patch the vulnerability that the ransomware used to infect their systems. Are there any examples of orgs that have been repeatedly hit by ransomware over and over? Working backups are not enough to insulate you from this threat. If you allow an attacker to remain within your systems long enough you might find they've encrypted all your backups!
- zie 6y agoagreed. I prefer your version of reality, I'm just not sure it's true.
- nkrisc 6y agoThere's three possible outcomes: 1. The victim organization that has my data gets everything encrypted and is forced to pay a ransom. 2. The same happens, but the hackers also release the stolen data, including my PII. 3. The hackers just sell the stolen PII from the start. As a consumer, I far prefer option 1. Maybe it will teach them to protect their system, and my PII, better. If my PII is released somehow, well that's what used to happen anyway. So it not happening is an improvement.
- inasio 6y agoYou could use the same argument for bank robbers.
- autosharp 6y agoDo you see banks getting robbed left and right and banks/governments not caring enough to take action against it? And is it being made your problem or the bank's problem when they do get robbed?
- mikorym 6y agoOne should be careful to confound people's carelessness or complacency with a right to exploit people. I also don't think the people being ransomwared are the same people who try to weaponise your data, hospitals being a good example.