3 ms·
Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked
by pluto_modadic 2y ago
Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.
- yardstick 2y agoDoes that extend to makers of buggy software, rather than those who often have little choice in what they use.
- nneonneo 2y agoIt’s not always buggy software; ransomware affiliates have been known to bribe company insiders to install malicious software on the network. The insider gets some cut of the eventual ransom. Works great on disgruntled employees or entry-level people. Fundamentally the financial incentive needs to be stopped in order to curb ransomware activities.
- halfcat 2y agoThe financial incentive to continue business operations will always be larger. Unless that’s the financial incentive you’re referring to.
- nradov 2y agoMaking it a criminal offense for a corporate officer to authorize a ransom payment would mostly eliminate the financial incentive. Very few employees will risk going to federal prison to protect their employer. Especially for publicly traded companies, large expenses are audited and difficult to hide.
- banish-m4 2y agoYep. Make it a crime to pay ransoms. No data is worth enabling and enriching criminals. Have tested backups stored offsite. If you fail at that, then you fail at business and deserve to go out of business.
- rjmunro 2y agoFor Ransomware, Backups need to be offline, not necessarily offsite. I.e. there needs to be no possibility of the hackers corrupting or deleting the backups too. If your data is in the cloud, it's probably good to have an offline backup onsite - sometimes cloud providers delete your account: https://news.ycombinator.com/item?id=40304666 https://news.ycombinator.com/item?id=40304666
- EvanAnderson 2y ago> Backups need to be offline... ...and tested on independent infrastructure. I worked with a financial Customer in the late 90s who, quarterly, sent a backup to an independent party for restore of the data into a freshly created application environment. They verified the backup with reproduction of key reports and random spot checks of data. It was impressive.
- banish-m4 2y agoThat's proper backup verification. At a minimum, restore to nearline temp storage. Ideally, backup and verify against hot storage SAN or FS volume snapshots. For absolutely business-critical data, I would consider using multiple backup approaches and/or vendors. Shout out to Tarsnap as vital here that every commercial enterprise should use for essential customer, contract, and accounting data.
- worthless-trash 2y agoHow would these companies survive if their systems caught fire, or had some kind of programmatic major data corruption, these companies that "can't survive" without paying the ransom perhaps needed to die, their management doesn't value business continuity.
- mschuster91 2y ago> I think hackers should get $0 from the victim, possibly get caught by police The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go for it [1]. Other cybercriminals like scam callcenters in India and Turkey have been found to bribe local governments to turn a blind eye or to warn against enforcement by federal authorities. The only way to hold them accountable is to cut the countries off from the global communications networks so they can't do any more damage until they show credible efforts and successes in being better netizens, but we don't want to do that for a variety of "realpolitik" reasons either. > and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers. EU GDPR has made some effort there, but in the end all software has security-critical bugs and there is only so much one can do to prevent getting hacked. [1] https://www.reuters.com/world/middle-east/explainer-how-close-is-iran-having-nuclear-weapons-2024-04-18/ https://www.reuters.com/world/middle-east/explainer-how-clos...
- Dolores12 2y agohow come there is no USA and Israel in your list?
- bluGill 2y agoUs and isreal only target specific orginizations. If you are not a 'terrorist' you won't have to pay and probably won't even notice them.
- mschuster91 2y agoThe difference is that - Stuxnet aside - Western nations (including Israel) do not run cyber extortion schemes against random individuals and companies. They do run intel campaigns against targets or sell the tools to run such campaigns, but so does every somewhat developed nation in this world. Intelligence operations are older than the Bible, they have been a part of civilizations ever since civilizations existed as a concept.