3 ms·
Oh yes, all companies have backups. I think you didn't understand the point.
by Avtomatk 6y ago
Oh yes, all companies have backups.
I think you didn't understand the point.
- viraptor 6y agoNot all companies have backups, but it's not possible to check this at scale. You can't verify everyone's software environment and verify that the DR plans actually work. Also some cases don't care about data loss - there are areas where you can repave everything and ignore the incident happened. Where it's actually required, we already have checks like PCI-DSS, data retention laws, government policies, etc. and you'll be audited. But again - this is very selective to make it realistic. Can you imagine there's a government entity which can come to your independent company at any point and say "show us your recent backups, how you restore it, and validate it's complete"? There's no way anyone would agree to this, or fund it. What we know is that backups are the lowest barrier and if you don't have them for data you're prepared to pay for, you are pretty much sponsoring the ransomware business.
- xoa 6y ago>Oh yes, all companies have backups. I think you didn't understand the point. I assume you're using sarcasm in the first part there, but that in turn it's you who aren't getting the point. All companies may not have backups, but all companies could have backups. And the industry as a whole could be taking far more measures to mitigate ransomware, it's not some impossible problem. As well as prevention measures, ransomware is quite detectable actively because it necessarily changes the entropy of stored data in extremely obvious ways that a watchdog could detect. Or there could just be automated systems that constantly sample backups and verify they're restorable. If companies don't do that and choose to externalize some of the costs onto society (by funding criminals who will go on to hurt others in this case) it's completely appropriate for government to step in and stop them. There are lots of situations where people and organizations are expected to exercise reasonable diligence or face the consequences. In contrast, at least for now backing up humans is not in fact an option. People aren't being lazy or failing to make reasonable efforts by failing to back themselves or their dependents up because that just doesn't exist. It's not the "same logic" at all, and how you made the mental leap of equating perfectly reproducible digital data with children is a real question.
- Avtomatk 6y agoLook, an example with apples: Jhon is a guy who does not care about the security of his company and does not create backups, suddenly he receives a ransomware attack and all his data is now encrypted, he has no option but to pay the ransom or all his intellectual property will be unusable , so he pays, and since he paid the criminals, he also pays a fine for incentivizing ransomware ... At the end of the day nothing was fixed and the ransomware groups are happier than ever. In a parallel universe we have an improved system, here it is regulated that all companies have either a backup of their information or a very robust system without back doors. Here Jhon also does not care about the security of his company, then it is discovered that Jhon does not have a backup copy and he is fined, Jhon pays and is forced to improve the security of his company, then he does it, then he receives an attack of ransomware, but Jhon refuses to pay because his company already has better security ... At the end of the day Jhon paid a fine, but the ransomware teams didn't get what they wanted, the problem was fixed here.
- chipsa 6y agoThe target of this isn't Jhon. It's Jhon's insurance company. His insurance will have requirements for him to have a backup plan instead of them being willing to maybe pay the ransom. And they can just not cover him if the backups don't work.
- bsder 6y agoSo, we should allow shitty companies without backups to fund criminal organizations without penalty? I hope they start enforcing this stuff with an iron hand, actually. Suddenly the CFO would have to put "ransomware fines" on the budget with enough zeros to make the C-suite put "reliable backups" on the budget.