8 ms·
It is always a temptation for a rich and lazy nation, To puff and look important and to say: -- "Though we know we should defeat you, we have not th
by pdkl95 5y ago
It is always a temptation for a rich and lazy nation,
To puff and look important and to say: --
"Though we know we should defeat you,
we have not the time to meet you.
We will therefore pay you cash to go away."
And that is called paying the Dane-geld;
But we've proved it again and again,
That if once you have paid him the Dane-geld
You never get rid of the Dane.
It is wrong to put temptation in the path of any nation,
For fear they should succumb and go astray;
So when you are requested to pay up or be molested,
You will find it better policy to say: --
"We never pay any-one Dane-geld,
No matter how trifling the cost;
For the end of that game is oppression and shame,
And the nation that pays it is lost!"
https://www.poetryloverspage.com/poets/kipling/dane_geld.html https://www.poetryloverspage.com/poets/kipling/dane_geld.htm...
We've known for hundreds (thousands?) of years that paying ransom only encourages more demands for ransom in the future. The solution to this is backups and improved security. I know that's expensive. Pay that cost now or continue paying more dane-geld proving over and over again that you are a mark that will pay.
> or, increasingly, to prevent them from being leaked
Why did high-risk data exist in the first place? Maybe stop gathering so much risky data.
- arcticbull 5y agoThis sounds a lot like a victim blaming to justify the existence of a technology which intentionally seeks to make transactions like these easier.
- loa_in_ 5y agoThe victims' only mistake was the way they underfunded their IT security. It's not a small mistake though, and the financial losses of the victim itself can in certain cases easily be dwarfed by losses of people who got their data exposed.
- meowface 5y agoIt's more than that, though. Many of the modern ransomware gangs are filled with talented, dedicated attackers who specifically target certain companies. You could invest a ton into security, have a competent security team, follow best practices, set up lots of security appliances and software, have lots of analysts monitoring and responding to alerts and actively hunting for threats and writing custom SIEM rules etc., and there could still be one small mistake that lets a sophisticated attacker in. As the adage goes, the defenders have to win every time and the attackers only have to win once. A group of sufficiently motivated, dedicated, resourceful, and talented attackers who face zero risk of any sort of repercussions will very likely get in if they put enough time and effort into it. This isn't just old-school ransomware that merely tries to infect as many computers as possible in general and just happens to land on a corporate machine and automatically spreads from there. These are trained, experienced red teams manually targeting companies and everyone who works at them. In many cases the victims do indeed have poor security, but a company doesn't necessarily need to have poor security to fall victim to ransomware.
- matheusmoreira 5y agoThere is no need to justify it. Cybercrime is a relatively small price to pay compared to the value provided by private cryptocurrencies. Their usage by criminals is actually a great way to see if they really work.
- arcticbull 5y ago> Cybercrime is a relatively small price to pay compared to the value provided by private cryptocurrencies. Which is what exactly? Speculation? And...
- thedevelopnik 5y agoDestruction of this really annoying planet we live on!
- matheusmoreira 5y ago1. Store any amount of money easily and securely 2. Transact quickly, easily, cheaply, globally, limitlessly 3. Nobody knows your balance 4. Nobody knows transaction amounts, senders, receivers, history 5. Nobody knows about anything you do 6. Nobody can randomly freeze your assets 7. Nobody can move those coins without the key Have you ever had your money taken away from you? My country suffered through hyperinflation in the 90s, the government got desperate and just froze the bank accounts of everybody. The amount of disruption this caused is legendary. It doesn't matter how much energy it consumes or how much crime it enables. If it allows us to escape government stupidity it's more than worth it.
- arcticbull 5y agoI mean roughly each of those points doesn’t apply to every major crypto. But also no, I’m properly invested. You get to escape government stupidity into the open arms of criminals and scammers. Out of the frying pan and into the fire so to say [1] It’s like replacing the local police with the Sicilians. They even have a comparable customer service policy, i.e. SFYL. [1] https://ag.ny.gov/sites/default/files/2021.02.17_-_settlement_agreement_-_execution_version.b-t_signed-c2_oag_signed.pdf https://ag.ny.gov/sites/default/files/2021.02.17_-_settlemen...
- brightball 5y agoI was shocked when I heard a ransomware expert at a security conference tell everybody to just pay the ransom. Shocked.
- Spooky23 5y agoWhat else do you do? If you don’t have a backup and need the stuff, you’re out of options.
- ENGNR 5y agoMaybe he/she has an alter ego who does ‘research’ into ransomware in the middle of the night </conspiracy>
- fungiblecog 5y agoBut it's the right answer for an individual org in that situation. Of course the correct answer for everyone, in the long term, is to have backups and not pay.
- meowface 5y agoIn my opinion, even then the cost of not paying may still be far, far higher than paying. A reply to the parent: https://news.ycombinator.com/item?id=27102599 https://news.ycombinator.com/item?id=27102599
- meowface 5y agoIf your options are 1) company is ruined and has to shut down temporarily or permanently, with much higher total costs than the ransom payment, or 2) pay the ransom, of course you're going to pick option 2. Backups aren't necessarily enough. Sure, a lot of companies don't backup. And sure, a lot of companies backup but keep the backups on network shares that the ransomware can reach and encrypt. And sure, a lot of companies keep isolated backups which aren't encrypted, but which are missing the past few days of production data. But even if you have a perfect backup solution up to the minute before the attack occurred, you'll still be coerced to pay. These ransomware operators are general extortionists - they manually target specific companies and come up with the most impactful threats to pressure you to pay. They screenshot all of the sensitive documents, emails, IMs, trade secrets, and PII they've gathered and say they'll post it online and mail it to every local, regional, and national press outlet, every company you partner with, and every customer email they've harvested. (And they do indeed make good on this threat if you don't pay by a deadline.) They call all your executives every hour of every day and target their personal devices. They might SWAT your executives' houses. If you don't have backups, the overall, reputational, and financial cost is probably way higher than the ransom payment. But even if you do, it still might be higher than the ransom payment. Even if you really want to take the moral high ground and inform your customers, partners, and the media of your choice and that you won't negotiate with terrorists or whatever, all of the damage (especially to your reputation and trust) may still be so extreme that you have to shutter your company. I don't think you can fault someone for paying the ransom when they're being explicitly targeted by sophisticated attackers and when so much is at stake.
- beloch 5y agoImagine for a moment that, despite all the precautions you yourself take, a clever crook manages to lock you out of some important files and demands a ransom. What do you do? It's easy to say cost is no object, but what if no amount of money, even far exceeding the cost of the ransom, can recover your files? The attitude that people who are hacked should have taken better precautions and should fend for themselves is a big part of what makes us soft targets to cybercrime. Imagine if we treated murder this way. "Oh, sure, he was killed, but he was walking down the wrong street at the wrong time of day. He should have known better! Let's start an educational initiative to make sure other people know what streets they shouldn't walk down at night!" We must expect the state to do a competent job of protecting citizens from cybercrime but, in most jurisdictions, governments do not devote adequate resources to this task. That needs to change. New technology and inadequate response from governments is what has created this bonanza for a new kind of criminal.
- nradov 5y agoPaying any sort of ransom should be illegal with severe criminal penalties. If that means that some businesses or people are ruined then so be it. That would be an acceptable cost to reduce similar attacks against others in the future.
- gambiting 5y agoWell, fortunately you don't get to decide that. Also imagine how well this would go - your child was kidnapped, but now you have to go to prison because you had the gall to make sure they go home safe. Like, I get your point, but it's one of those armchair social science ideas that can go into a cabinet full of really cool and really obvious ideas that won't ever be implemented in reality.
- chrischen 5y agoIf you pay the ransom you’ve doomed future children to be kidnapped as well.
- 1vuio0pswjnm7 5y ago"As ransomware has grown, so has the industry promising to protect firms from it." In the aggregate, there may be more money being siphoned off businesses by offering "protection" as a service than from ransom demands.
- paulpauper 5y agoransomware is full disk encrpytion but you dont know the key. this is hard to do with modern bios settings. Upgrading to windows 10 makes ransomware much harder to install.
- asiachick 5y agoDo you have more info on what Windows 10 does WRT ransomware?
- yongjik 5y agoOff-topic, but I really hate this poem - it's a geopolitical equivalent of "Why don't they eat cakes instead?" Many small and weak nations are barely clinging on for survival by any means necessary - they cannot afford to not pay Dane-geld, and I think they'd appreciate not being mocked as a weakling by someone born to the British Empire.
- pessimizer 5y agoKipling is a "Dane" pretending that how his country got that way is because of its moral superiority and toughness, which makes it's own demands for geld justified by the burden of maintaining its flawless character.
- samuelizdat 5y agoGold is for the mistress -- silver for the maid -- Copper for the craftsman cunning at his trade." "Good!" said the Baron, sitting in his hall, "But Iron -- Cold Iron -- is master of them all." https://www.poetryloverspage.com/poets/kipling/cold_iron.html https://www.poetryloverspage.com/poets/kipling/cold_iron.htm...