5 ms·
The only way people would reliably help with the sabotage is if the group had a reputation for paying out. Kind of the same way ransomware works already- if nob
by SerLava 5y ago
The only way people would reliably help with the sabotage is if the group had a reputation for paying out. Kind of the same way ransomware works already- if nobody gets their data back, people will be advised never to pay
- stickfigure 5y agoUnless some employees get caught, there's no way for the group to acquire this reputation. Certainly they can't be trusted at their word ("we pay out" - sure you do).
- csydas 5y agoI strongly disagree based on my experience consulting and the countless articles you can find about this very situation happening prior to the rise of cryptocurrency and ransomware gangs. Disgruntled employees doing shift+delete on a critical directory after missing backups or rotating encryption passwords to gibberish on their last day is very common. (or of course both and more) For me it's not hard to believe at all that someone who is already at a low point and motivated with malicious intent would read up on such an offer and think to themselves "I can screw my boss __and__ get a cool million in etc? Just for 'accidentally' uploading some ssh keys with a misplaced wildcard?" Even before the covid pandemic, stress in IT was high and disgruntled employees doing damage on the way out was making headlines. Search 'Disgruntled employee destroys data' on google and check the date of some of the news articles. Here's one that made US national news in 2014 about how data theft was a trend.[0] Whether or not there's a real payout is of no consequence it seems. I'm only able to immediately find articles about such incidents in the US and the UK, but I am fairly sure it's not limited to such locations, or that outsourced IT isn't just as vulnerable. I've written it before on HN for other reasons, but people like to talk about new laws/standards/etc, but IT doesn't have problems that need legal solutions, as an industry, IT needs to improve discipline across the board and stop letting situations where one person can be so destructive happen. Too many places still run their IT like it's the 80's/90's where one or maybe two with absolutely control over everything. This leads to burnout first of all, which is horrible, but it also creates these bad situations of unregulated control in the first place. [0] https://www.wsj.com/articles/fbi-warns-of-rise-in-disgruntled-employees-stealing-data-1411516389 https://www.wsj.com/articles/fbi-warns-of-rise-in-disgruntle...
- 908B64B197 5y ago> I've written it before on HN for other reasons, but people like to talk about new laws/standards/etc, but IT doesn't have problems that need legal solutions, as an industry, IT needs to improve discipline across the board and stop letting situations where one person can be so destructive happen. Too many places still run their IT like it's the 80's/90's where one or maybe two with absolutely control over everything. I mean, it's like having the neurosurgeon at the hospital retire/quit for a software company to lose it's IT. The issue is, many software companies don't know/think they are a software company.