6 ms·
>if everyone refused to pay there would be no profit in it Of course it's very saintly of you to refuse to pay, but often not paying is a very bad business dec
by FDSGSG 5y ago
>if everyone refused to pay there would be no profit in it
Of course it's very saintly of you to refuse to pay, but often not paying is a very bad business decision. You can be sure that enough people will pay for your refusal to not make any difference.
- noduerme 5y agoIt wasn't for saintly reasons; I saw clearly that it would do no good. If we paid, there was no guarantee the attack wouldn't come back the next day. It would solve nothing - actually, it would be worse because it would put us at their mercy. If we couldn't overcome it, get back online and block the next attack, then I didn't deserve my job and the company would have been better without me. Paying wouldn't make the problem go away, it would have made it infinitely worse for me. So saintly? No way.
- Jach 5y agoStill, the GP's point stands. Especially as attackers create a "brand" and establish trust -- if a few quick searches show other people reporting that they paid and things were restored, then you can bet people will feel much more at ease with the idea of paying and actually being left alone after. When a business depends on it, when data loss is at play instead of just downtime, even more so. People will pay.
- noduerme 5y agoI think paying is a dumb move, regardless of the "brand" of extortionist you're dealing with. It just signals that you're a mark. It might briefly make an executive's life easier, but it'll come back and bite you. I didn't refuse to pay because I thought it would be inspirational or set an example or bla bla bla. It was because I'm not a dumb mark, and I'm not going to let my clients be. And personally, I'd rather burn my house to the ground than let someone rob it.
- FpUser 5y ago>"And personally, I'd rather burn my house to the ground than let someone rob it." That is your personal choice and you're more than welcome to go up in flames if that is what you wish. You should have no rights however to force your personal choice upon the others. They might have a different perspective.
- FDSGSG 5y agoPaying can't be a dumb move when your business continuity depends on an attacker returning your encrypted files. I agree that with DDoS extortion the situation is way more complicated, and the attacker will eventually move on if you don't pay. > And personally, I'd rather burn my house to the ground than let someone rob it. I think we can all agree that this is just plain stupid. Cutting off your nose to spite your face.
- hermes8329 5y agoI think we can all agree that this is just plain stupid. Cutting off your nose to spite your face. No we can't alI agree on that and I think you would be surprised. Personally I'd be seen with a gas can and a box of matches
- FDSGSG 5y agoIt is well known that there are many stupid people in this world, perhaps you are one of them?
- hermes8329 5y agoNo personal attacks buddy
- bluGill 5y agoBut if people don't pay the attackers give up on attacking the next target. By paying out your are rewarding the attackers for being evil.
- FDSGSG 5y agoYeah, but this just completely detached from real life. Companies will always pay, even if you make it illegal, companies will still pay. Will fewer companies pay? Sure. Does it matter? No. Ransomware gangs wouldn't go anywhere even if their average payments got cut down by 90%, and the stuff they might switch to (BEC) isn't going to go away either.
- bluGill 5y agoMaybe, but even if just a few don't pay, they will do other things. The attacks ransomware uses will become harder and harder to exploit. (already it is a lot harder than 20 years ago). More things will be invented to prevent them in the first place. Maybe formal proofs of all code? There are a lot of things that companies who aren't going to pay will start demanding of their vendors who they will pay.
- FDSGSG 5y ago> Maybe, but even if just a few don't pay, they will do other things You're joking. There are already many who don't pay, payment rates could fall by 90% and it wouldn't slow them down a bit. You clearly have no idea how hugely profitable ransomware is. If less companies pay, the ransomware operations will just scale up their customer support teams and further automate deployment. This really isn't going to be a problem for them. > Maybe formal proofs of all code? There are a lot of things that companies who aren't going to pay will start demanding of their vendors who they will pay. Haha. Funny. Have you ever worked with formal proofs in a software context?
- bluGill 5y ago> There are already many who don't pay, payment rates could fall by 90% and it wouldn't slow them down a bit. You clearly have no idea how hugely profitable ransomware is. You misunderstand. Those who don't pay still have the problem. They will invest in solutions. Some (like good well tested backups) only affect them, but others like hardening software make it harder for ransomeware to get anyone in the first place. > f less companies pay, the ransomware operations will just scale up their customer support teams and further automate deployment. This really isn't going to be a problem for them. True. Though the less companies that pay, the more examples of not paying get out there and so the more likely it is other companies will get good protection for themselves. Probably not enough to really affect profits too much, but still helpful to limit the amount of investment "big evil" can afford to do. > Have you ever worked with formal proofs in a software context Just a little bit. I'm looking to work with them more because for my area quality is important and we have reached the limits of what unit and manual testing can do. (but not the limits of other automatic code analysis which I'm also looking into)
- mistrial9 5y agovery telling how the "real" people fight over how much they can deny any and all "saintly" motivations ; edit- apologies to noduerme who appears to have dealt with a serious situation respect . second thought - here in the USA in the mid-2000s there were waves of identity theft and also mortgage fraud.. massive waves, very large numbers of accounts and even larger dollar amounts. I believe it was BANK-related employess and USA-based people who knew the credit system, performing quite a bit of all of that, with eyes open! the reputed phrase was "you wont be here, I wont be here" about the consequences down the road. Sure, name-your-enemy Eastern Europeans are caught doing these things, outside of the reach of the casual US law.. but is it ONLY outsiders? or, you just dont know how badly your own money system employees are stealing from you now.
- FDSGSG 5y agohttps://imgur.com/a/oBEj3Jy https://imgur.com/a/oBEj3Jy Try to find a not-russian site with as many people discussing this stuff. It really do be like that sometimes.
- deleted 5y ago[deleted]
- mistrial9 5y ago> It really do be like that are you accustomed to talking like that? why do you have those screenshots?
- FDSGSG 5y ago>are you accustomed to talking like that? It's a "meme". Unless you refer to the really badly google translated screenshot, in which case yes, but I've now learned sufficient Russian that it's easier for me to read without. >why do you have those screenshots? I follow a bunch of these forums for intelligence gathering purposes. There are companies paying ridiculous amounts for a few of these screenshots and a little accompanying text, it's apparently called "threat intelligence".
- Tuna-Fish 5y ago> Of course it's very saintly of you to refuse to pay, but often not paying is a very bad business decision. You can be sure that enough people will pay for your refusal to not make any difference. And this is something where the law can help. Paying a ransom in these kinds of situations needs to be a felony. The punishment needs to be dealt to everyone who acted or knew and didn't report, and it needs to be harsh enough that even in the worst cases people would rather call the cops and report than risk it. (Or, at least some employee in the organization would report it and save their own hide than risk it to protect their boss.) The ramsomware crisis is really bad now, and it keeps getting worse. It will not stop getting worse until the money dries up. Small businesses cannot be expected to have the level of IT knowledge that they absolutely can't be hacked. The reason they weren't victimized before at this level was that the money wasn't there. There are enough places in the world where the authorities will look the other way (or actively cheer on the criminals), meaning this will not end until the flow of money is stopped. If you want to mitigate the losses caused by ransomware gangs, create a subsidized insurance system that helps the victims. Just, that insurance is not allowed to pay off the criminals, just help the business get back on it's feet.
- FDSGSG 5y agoCompanies would still pay even if making ransomware payments was a felony. The ransomware gangs would not go away, companies would just have a bigger incentive to hide ransomware attacks. These groups aren't going to go away even if 95% of companies suddenly stopped paying, deploying ransomware costs next to nothing. There's also a huge incentive for ransomware actors to punish this sort of regulation. > The ramsomware crisis is really bad now, and it keeps getting worse. How come everybody is crying about the "ransomware crisis", but you never hear about a "BEC crisis"? BEC losses are bigger than ransomware losses, and they keep getting worse.