4 ms·
It really bugs me when I hear of institutions paying these ransoms. Regardless of the damage, I'd just take the bullet, fix my security, and not pay. Be consis
by scott-smith_us 6y ago
It really bugs me when I hear of institutions paying these ransoms.
Regardless of the damage, I'd just take the bullet, fix my security, and not pay. Be consistent in this, and keep it up for a while. Long term: no more extortion for anyone.
- gowld 6y agoYou can't retroactively fix your security. It can take a lot money (well spent, so that's fine) and time (which can be devastating) to recover the compromised system.
- gk1 6y ago> Regardless of the damage, I'd just take the bullet, fix my security, and not pay. It's irrational to "bite the bullet" if the damage is significantly greater than the ransom. Sure, it's better in the long term, but not for the person/organization being ransomed.
- reaperducer 6y agoIt's irrational to "bite the bullet" if the damage is significantly greater than the ransom. It's not irrational. It's called doing the right thing. Sure, it's better in the long term, but not for the person/organization being ransomed. That's called being selfish. One would expect an institution like UCSF to act for the benefit of all of society and not like a six-year-old grabbing all the Easter eggs at the hunt and saying, "I got mine!"
- recursive 6y agoWhat you call "selfish" is also known by some as "rational". Maybe that will help.
- jbm 6y agoWe can't survive in a society where min/maxing benefit is the sole form by which we determine whether something is the correct action or not. I am sure you would agree that gender-based abortion, deforestation, and infinite copyright periods could be seen as "rational" to people in certain societies and certain economic situations. It doesn't mean that we should let such actions go without comment.
- recursive 6y agoI totally agree with you. I was responding to "It's not irrational". Doing the right thing isn't always rational from a direct comparison of objective metrics.
- kelnos 6y agoThe two things are not mutually exclusive.
- exolymph 6y agoThat's real easy to say when the gun isn't up against your head. Call us when your principles in this matter have been tested in practice.
- colejohnson66 6y agoExcept if you’re a company with millions of users, losing everything would be a lot worse. As @gowld mentioned: you can’t retroactively fix security.
- LinuxBender 6y agoI think this assumes an organization has proper data backup strategies in place. If you have daily snapshots and full weekly backups, then ransomware should just be a nuisance and cause some people to work weekends / after hours.