4 ms·
So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could
by amima 3y ago
So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?
- jupp0r 3y agoI was assuming that countries would make it illegal to pay these ransoms.
- pc86 3y agoThe article doesn't seem to suggest that anywhere.
- jupp0r 3y agoYou are right. It's kind of a toothless tiger without that part though.
- kube-system 3y agoThe data sharing mentioned in the article will help authorities to target the criminals directly.
- Workaccount2 3y agoAn insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.
- pc86 3y agoThere are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.
- Workaccount2 3y agoSorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.
- pc86 3y agoThat doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups are infected.
- zmgsabst 3y agoInfected how? Our backups were the data, not code or systems (which were IaC and rebuilt as needed).
- pixl97 3y agoAre user accounts data or systems? Compromise of AD is a very common means. This said this can still be fixed before putting it back where it could reach the internet and cause trouble.
- xur17 3y agoFor a concrete example, someone could infect an image storing service with code that encrypts (and silently decrypts) the data when it's stored / retrieved. When the hacker removes the decryption key from the running service, the backups will also be inaccessible because they are also encrypted.
- Workaccount2 3y agoWouldn't this be a bright red flag that is trivial to check for?
- 3y ago
- raverbashing 3y agoThe dumbest take of companies was assuming insurance companies would keep paying their ransom because they were thinking fixing their networks was less important Oh well turns out it is not like that
- mcpackieh 3y agoNo reason such an insurance company couldn't be run in the early/mid 20th century manner, entirely with paper records. Send carbon copies of all documents to two remote locations to eliminate the threat of a fire wiping out the records. This is easy. It requires you to hire a lot of human clerks, but since the customers are large businesses that means there aren't a whole lot of customers in the first place. And if you can't get enough typewriters, there's no reason the clerk work couldn't be done on computers connected to printers, with all document storage still being done on paper. If the computers get pwned, throw them out and buy new ones; it doesn't matter because the documents weren't being stored on those computers.
- pc86 3y ago> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, and several people suggested paying the ransom but we ultimate decided not to and it ended up costing more than the ransom if you factor in payroll and lost revenue. I still think out of principle you shouldn't pay the ransom, ever. Assume whatever the ransom would cost is already gone, if you can rebuild for less than that (you probably can't) it's a win.
- beardyw 3y ago> I still think out of principle you shouldn't pay the ransom, ever There may have been a time when a company would act on principle, but I think it's very rare today. You hardly even expect people to do that. It's the world we have made.
- FredPret 3y agoAll human activities, including things like principles, charity, sacrifice, and duty, are ultimately self-serving attempts by the biological DNA and cultural memes that constitute us to replicate and improve it's standing.
- m-p-3 3y agoBut even when paying the ransom, you still need to roll back a portion of your environment after you've assessed the intrusion. Can you really trust you've patched everything and removed all trace of persistence that was put by the attacker as a contingency to get back in the system?
- miohtama 3y agoThe easiest targets are those that are publicly known to be vulnerable.
- 3y ago
- amalcon 3y agoNothing, so far. The alternatives to that would be to legislate penalties for paying, to mandate certain precautions like regular offline backups (which could usually be done through regulation), to forbid the government from doing business with entities that have paid in the past X time (procurement regulations are somewhat flexible) and/or to task some government agency with aiding private sector entities in recovery if they don't pay (which has varying difficulty depending on the jurisdiction). Obviously none of these make it impossible, but the goal needs to be to tip the value proposition the other way.