5 ms·
That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it
by codegeek 5y ago
That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.
- elondaits 5y agoAlso, there are middle-man "security companies" that you can pay to "help you decrypt your files" and what they do is simply pay the ransom under the table for you... So you can't really tell if a company paid the ransom or not.
- snapetom 5y agoYep. It's like governments that forbid use of things like facial recognition software by its police departments. Sure, the police department doesn't use facial recognition, but they commonly work around this by using a vendor that may or may not use facial recognition. This model is actually commonly employed by both companies and that are forbidden to do something.
- Enginerrrd 5y agoYou can also make it illegal to seek assistance from an out-of-jurisdiction middle-man. Thus, any middle men are going to be subject to the same regulations.
- spywaregorilla 5y agoNo those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.
- nindalf 5y agoNo. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least. What such an idiotic, short sighted policy would do is to encourage corporations to pay the ransom in secret. This only strengthens the hackers because now law enforcement has no idea who is being hit, when, and with what malware.
- gopher_space 5y agoIf "all" of your data is being held to ransom and that will tank your company then you are a bad businessperson and deserve whatever you get. Right now it's apparently cheaper to pay a ransom than it is to implement sane security and backup procedures. That needs to end.
- camjohnson26 5y agoThat would be true if it was possible for any company to have perfect processes, but that’s not the case. Companies are run by real people with real flaws and a perfect system doesn’t exist.
- codegeek 5y agoThat's like saying "Right now it's cheaper to not have locks so lets punish the homeowners who don't lock their doors instead of punishing the thieves and robbers" Yes, security and backup measures are critical and companies SHOULD be scrutinized for those things especially if you deal with mission critical data/information. But that has nothing to do with Ransomware Gangs.
- WalterBright 5y agoI thought we were done with blaming the victim.
- 5y ago
- 908B64B197 5y agoExcept in this case you can just... restore your wallet from back-up. Pretty much the reason wallets are worthless is that if you snag one, all you get are plastic cards that are going to get cancelled in the next minutes/hours. S3/Azure/Backblaze are really cheap and just work.