5 ms·
If this is the definition of ransomware then I was indeed incorrect. I understood ransomware to be "threatens to perpetually block access to data" only.
by Timpy 6y ago
If this is the definition of ransomware then I was indeed incorrect. I understood ransomware to be "threatens to perpetually block access to data" only.
- calvinmorrison 6y agoSo at this point it's just a normal Ransom. There's no 'wares' doing it. Someone stealing something does not make it ransomware.
- jolmg 6y agoSince we're discussing word choices and definitions, I'd argue that it's not stealing either if the Hospital retained possession of the data. It might be better said that they "obtained without authorization" or "illegally obtained". What makes "stealing" particularly bad is that the rightful owner no longer has possession of their property. That's not necessarily the case with data.
- tomc1985 6y agoThis sort of thing is why people need to stop thinking that the digital world is analogous to our analog one. In digital, information wants to be free and many kinds of resources are effectively unlimited. There is no material scarcity. Therefore, theft, in the digital world, can't be the same as it is in our analog world. To be fair, this also applies to copyright and peoples' foolish notion that they can protect data without a great amount of preventing otherwise normal "physiological" processes. (Ironically, rather than having a wake-up moment where people realize their folly, we've institutionalized these resource-scarcity regimes into resource-abundant versions in the digital world) To summarize, info wants to be free, and since theft requires extra effort to deprive someone of what you stole, does that definition of theft really apply here? Or does it need to change given the context? And, as a secondary point, people like to think they can protect data but their brains are stuck in our analog, resource-scarce world
- riffraff 6y agobut it's not even ransom, "ransom" is the situation where something/someone is held until money is payed and then it's returned. There is nothing being returned here, since the hospital has not lost access to the data, and the threat is that private data will be published. This is just blackmail.
- tertius 6y agoWhat has been lost of the privacy of the data, which can be returned.
- plorkyeran 6y agoNo, it can't. It is impossible for the blackmailers to prove that they no longer have a copy of the data.
- celticninja 6y agoREvil is ransomware that locks you out but first exfiltrates your data. Then the attackers have 2 points of leverage, lock out which you may be able to circumvent with a safe backup process but that won't protect you from the release of your data. This gives the attacker 2 nites at the cherry when trying to convince you to pay.
- young_unixer 6y agoStealing would be breaking into their premises and taking the computers. Obtaining data isn't stealing.
- pc86 6y ago> Obtaining data isn't stealing. What is it then, if you don't have the legal right to the data?
- __MatrixMan__ 6y agoIf some law prevents you from having access to some data, then presumably that law has a name for whatever the crime is. It's not like we need the law to explicitly allow types of access. Anything not explicitly disallowed is allowed without a special name. "Stealing" happens when the original owner is deprived of the thing.
- ddingus 6y agoInfringement Seriously. Theft requires the property owner be denied their property. What happened is someone made a copy they were not supposed to. Textbook infringement.
- young_unixer 6y agoIt's something different from stealing. Both "hacking" and stealing are illegal in most countries, but they're still completely different actions: one is taking a physical object from someone, the other is sending and receiving electrical pulses trough a wire. You wouldn't call stealing and killing by the same word, either, even though both are illegal.
- g_p 6y agoWhen companies started restoring from their (new and existing!) backups when hit by ransomware, the ransomware authors looked at what would impact their "clients" the most -- if preventing them getting access to their data wasn't enough to make them pay up, then exposing their data and turning it into a breach that results in regulatory action helps them commercialise their "access". I think in a way, ransomware authors are following the "free market" approach, trying to best monetise their unauthorised access to other people's IT systems. Perhaps the prevalence of ransomware will eventually help businesses to properly cost in the risk of security to their business, and get their security in order, as there's a tangible cost threat?
- libria 6y agoNo I agree with your initial statement. The victim is not deprived of data or normal operation. As stated elsewhere it's blackmail. Adding: Wikipedia is also not necessarily authoritative.