4 ms·
Russian hacking gangs are putting silicon valley entrepeneurs to shame. They've made every element of ransomware something that can be specialized in and outsou
by LogonType10 5y ago
Russian hacking gangs are putting silicon valley entrepeneurs to shame. They've made every element of ransomware something that can be specialized in and outsourced. Initial access? Ransomware? C2 infrastructure? Negotiation? Customer service? It can all be outsourced to a Russian company that specializes in their niche.
Everyone is scrambling to build a cyber army. Looks like Putin is letting the invisible hand build it for him.
- rectang 5y ago"Silicon valley entrepreneurs" are doing business in a war zone. The general security situation is fraught because multiple nation states are at least sheltering and sometimes sponsoring attackers who damage the economy of the opponent.
- deleted 5y ago[deleted]
- caf 5y agoModern-day privateers?
- LogonType10 5y agoDespite what narcissistic Zero-to-Oners would tell you, their startups aren't important in the grand scheme of things. Nation states are hacking intelligence agencies, governments, established IT vendors (not startups), power grids, and hospitals in that rough order. Ransomware gangs are hacking companies that have real money right now, not lottery tickets pre-IPO. These companies can afford good cybersecurity but don't want to spend more money than the damages they would incur from a successful attack.
- deleted 5y ago[deleted]
- AmericanChopper 5y ago> Ransomware gangs are hacking companies that have real money right now, not lottery tickets pre-IPO Funded startups have a lot of money. Milking money out of startups is a highly profitable market segment. Why would ransom gangs not want to get in on that? They don’t tend to ask for the ransom to be paid in ISOs…
- LogonType10 5y agoMost startups don't have a ton of data you can encrypt and chokehold them with. If hospitals don't have their medical records then people die. If your startup has to reimage all its laptops and redeploy its application code from github then it's a lost weekend.
- jnorthrop 5y ago> These companies can afford good cybersecurity but don't want to spend more money than the damages they would incur from a successful attack. A bit off your "real" point: No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. That is just good business, but the reality is that companies generally won't spend more on cybersecurity than their peers (either as a percentage of revenue or percentage of IT spend). Whether that is the proper balance for a risk/spend calculation is the real topic. The problem is that we can't accurately calculate the probability of a cyber event and the cost impact of that event. So the company is stuck waiting for an attack on themselves or one of their cohorts so they can adjust.
- jacquesm 5y ago> No company should ever spend more mitigating a risk than the potential cost they could incur from the risk Funny, after the fact they are usually out a lot of money and they decide that they now do want to mitigate that risk.
- hluska 5y agoIt’s genuinely interesting how poorly companies perform when you gauge their ability to cost out a successful attack. Pre-attack, many seem to make an economic decision not to mitigate it. Post attack, the fifth CISO in four years gets fired, the CEO vows to do better and the cycle repeats all over…
- trhway 5y ago>No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. basically you summed up the opening scene from the FightClub. The human life cost H millions, so until it is going to kill N such that N * H >= cost of the fix ...
- LogonType10 5y ago>No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. I've heard hospital administrators make this argument after I've warned them about their security infrastructure being vulnerable to ransomware. I'm not convinced.
- _jal 5y agoMostly true, although the ceiling at which you become interesting is dropping for multiple reasons. Given the time cost of retrofitting effective security, waiting until you become a worthwhile target doesn't work. But hiring secops and spending time on security engineering instead of your product is also deadly to startups. It is another knife-edge for startups to walk.
- ByThyGrace 5y agoCould you expand on that? Any high-profile cases? Edit: found this comment in this same thread https://news.ycombinator.com/item?id=29158450 https://news.ycombinator.com/item?id=29158450
- seibelj 5y agoExcept normal entrepreneurs can sleep easy at night and not worry about going to jail for life. Or at least right now, political situations can change and even conducting legal business can be dicey.