4 ms·
That key word being _before_. A savvy attacker could be taking note of the private keys as they went; cashing out the Bitcoin only when the customer data has be
by bowmessage 4y ago
That key word being _before_. A savvy attacker could be taking note of the private keys as they went; cashing out the Bitcoin only when the customer data has been fully pilfered and the ransomware installed.
I suppose the balancing act here is in ensuring the Bitcoin amount is enticingly large enough to get an attacker to jump on it first?
- goodside 4y agoIt’s not worth it, because there’s a risk of the money being moved to another wallet if the intrusion is discovered. You want to take the money the instant you can.
- heavyset_go 4y agoIf someone or a group is going to hit businesses with ransomware, they're looking to get more than $10k.
- throwaway290 4y agoThat's 100% guaranteed $10k now vs. ransom maybe (how do you know if they have backup) paid some time later.
- loceng 4y agoThere's a pretty high payout rate.
- heavyset_go 4y agoAt least to me, it's like putting a $100 bill under a business' doormat to ward off burglars who know that there's 3 to 4 orders of magnitude more money and assets inside if they break in. It's a nice bonus, but if they're working with other people for high stakes payouts, a small amount of money like that isn't going to be worth it for them to move on. $10k is nothing when split between other people and when you can demand hundreds of thousands to millions otherwise.
- throwaway290 4y agoI do not think literally hundreds of people work on these hacks. But besides, in remote environment it is easier to be that guy who grabs the money and runs. $10k is $10k for a single person.
- dmurray 4y agoYou could also just rotate the private keys every week or month by policy, and make sure attackers know it's at least likely you're doing this.
- reflexco 4y agoEven better, rotate at random intervals.