5 ms·
> The Hospital Group, which has a long list of celebrity endorsements, has confirmed the ransomware attack. This isn't a ransomware attack, they're not encrypt
by Timpy 6y ago
> The Hospital Group, which has a long list of celebrity endorsements, has confirmed the ransomware attack.
This isn't a ransomware attack, they're not encrypting the company's drives and demanding a ransom to unencrypt them. Not every "I hacked you now pay me or bad things happen" situation is ransomware.
- bigbubba 6y agoThey're not using cryptography, but aren't they demanding ransom? Is the use of cryptography an essential part of what it means for something to be ransomware, or is it merely a common implementation detail?
- derivagral 6y agoTo me, ransomware attacks are specifically "the malware got in and turned all my data to mush; the attacker doesn't care about my data, just that I'll pay to un-mush it." This is "the malware got in and sent copies back home; now home base is threatening release and expecting payment to prevent it." To me, this is blackmail done via hacking, not ransomware.
- Godel_unicode 6y agoFwiw, many actors doing the former are also doing the latter. If someone paid you once to unencrypt, presumably they'll pay you again to not disclose the data. The line between those two business models is pretty blurry.
- flyGuyOnTheSly 6y agoThey are demanding a ransom, but Ransomware has a commonly accepted definition which requires encrypting files and demanding payment to decrypt them. [0] [0] https://en.wikipedia.org/wiki/Ransomware https://en.wikipedia.org/wiki/Ransomware
- zimpenfish 6y agoThe very first sentence of that link would include this under "ransomware" > Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. (added emphasis)
- flyGuyOnTheSly 6y agoThat's a single sentence pulled from a very long definition, though. Here's the third sentence from that very same paragraph: >It encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. Not everything can be explained in a single sentence.
- tompazourek 6y agoThey are not demanding ransom. Ransom is (per Merriam Webster): "a consideration paid or demanded for the release of someone or something from captivity". They copied the data, and they want money otherwise they will release it. It's ordinary blackmail.
- bigbubba 6y agoPerhaps you could say they are ransoming the exclusive ownership of the data. But yes, 'blackmail' seems like a better fit.
- curryst 6y ago> They're not using cryptography, but aren't they demanding ransom? No, a ransom is a fee paid for the release of something you value. Cryptography is one way to take a user's data, and release it back to them on payment. This is blackmail. They want payment to not release something.
- heavyset_go 6y agoIt's blackmail.
- ajay-b 6y agoAgainst whom? Where is the profit mechanism? Are the hackers really prepared to track down every patient and try to blackmail them? It’s like the emails you get some times from hackers that have an old password of yours and threaten to release that video of you pleasuring yourself. Seriously?
- heavyset_go 6y agoAgainst the firm that let their patients' private data leak. Medical groups tend to have deep pockets.
- jMyles 6y agoRansom usually means, "I have some(one|thing) of yours, and if you want it back, you need to pay me." Calling this "randomware" subtly blurs the line between copying and stealing. The attackers here didn't remove access to the data (clearly stealing), they made a copy (clearly a crime other than stealing, at least in my view). It's more like blackmail than kidnapping.
- throw14082020 6y agoTimpy :P, your understanding of Ransomware is different to Wikipedias: > Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid.
- threatofrain 6y agoIf somebody breaks into a psychiatrist's office and threatens the release of embarrassing or sensitive data unless there's payment, isn't that just classic blackmail?
- BoorishBears 6y ago... what? What moral question? This thread is someone questioning calling it was a ransomware attack, it was one. Being a ransomeware attack doesn't preclude it from being blackmail, and I don't think anyone you replied to has questioned the morality of it...
- deleted 6y ago[deleted]
- Timpy 6y agoIf this is the definition of ransomware then I was indeed incorrect. I understood ransomware to be "threatens to perpetually block access to data" only.
- calvinmorrison 6y agoSo at this point it's just a normal Ransom. There's no 'wares' doing it. Someone stealing something does not make it ransomware.
- jolmg 6y agoSince we're discussing word choices and definitions, I'd argue that it's not stealing either if the Hospital retained possession of the data. It might be better said that they "obtained without authorization" or "illegally obtained". What makes "stealing" particularly bad is that the rightful owner no longer has possession of their property. That's not necessarily the case with data.
- jahewson 6y agoExtortionware would be appropriate.
- smarx007 6y agoWhat you are talking about are cryptolockers and they are a subset of ransomware. Not all ransomware are cryptolockers. In this case, ransomware exfilled the data without a need for cryptolockers. They are still asking for a ransom.