6 ms·
Is this standard? From my layman perspective, I would never pay a ransom because I can't see any possible assurance that they'll actually honor their end and/or
by teqsun 2y ago
Is this standard? From my layman perspective, I would never pay a ransom because I can't see any possible assurance that they'll actually honor their end and/or quietly tampered/backdoored for future exploitation.
Is there a BBB for ransomware hackers that informs the insurance whether the deal will be honored?
- luma 2y agoTrust is established through interaction with the ransoming party. The interaction will be some version of a trial solution that will decrypt some subset of the locked systems to prove that they can in fact recover your systems. I've been engaged on a few of these, my general impression so far is that the technical support you get from the ransomware gangs is better than the contracted support I get from Microsoft.
- jMyles 2y ago> better than the contracted support I get from Microsoft. ...that's a pretty low bar. It seems to me that they'd have to be quite reliable and responsive to be able to routinely collect.
- stackskipton 2y ago>It seems to me that they'd have to be quite reliable and responsive to be able to routinely collect. Nope, they rely on compliance to collect. So many compliance/regulatory schemes are like "Do you have vendor support on all your software, including OSes?" so you end up paying Microsoft money or paying Red Hat money.
- jMyles 2y agoSorry; I was unclear. I meant that the ransomware admins need to be reliable and responsive.
- accrual 2y agoIs Microsoft's B2B support really that bad? I've never directly interacted with them, but from what I've heard within my org, they are at least fairly responsive and helpful when you're paying them millions for software.
- stackskipton 2y agoGetting them to answer the phone? They are really good at that. Getting out of Tier 1 hell? Pretty frustrating and difficult. Getting them to fix the problem? Depending on your issue, it's either "Here is a patch" or "It's been added to backlog, early estimates are sometime in 2030s"
- EvanAnderson 2y agoI've never worked for a business paying MSFT millions so I can't comment on that. As a business paying several hundred thousand I had no success getting any help with an issue with Windows Server (July 2021). My organization was willing to spend money but couldn't get anyone at MSFT to take it.
- dole 2y agoIf your company has enough sunk into MS as far as infrastructure and MSDN Developer licenses and whatnot, you can and do get more attentive direct developer support for esoteric problems, legacy support and the likes.
- deleted 2y ago[deleted]
- jonstewart 2y agoIf the ransomware gangs made off with the ransoms, victims would stop paying them. Most victims pay the ransom (after negotiation) and the vast majority of ransomware operators provide valid keys/decryptors in return. It's a functional market, however warped. There's no BBB, but, yes, insurance carriers keep notes on the different ransomware gangs.
- recursive 2y ago> victims would stop paying them Only if the victims are communicating with each other. It seems like most victims are not interested in publicizing their experience. These incentives might be even stronger if one got scammed for the ransom. It's not a good look.
- jonstewart 2y agoThe victims often have insurance and the insurers definitely pay attention.
- teqsun 2y agoThanks for the answer, very interesting stuff. I guess my next question is how do you establish that it's actually the group with the "good" reputation, and not just one claiming or pretending to be them?
- jonstewart 2y agoYou won’t get anywhere to complete certainty but the different gangs each have their own modus operandi. And of course it’s in their interest to act as enforcers and keep bad actors out.
- rtkwe 2y agoThey're mostly decent about getting the systems unlocked after you pay. The incentive for these groups is that if they become known as unable or unwilling to get you your systems back they're far less likely to get paid. A few years back I read an article talking about this exact problem where the groups were fairly active and responsive so that their victims are more likely to actually pay.
- teqsun 2y agothat's my question: if you were the ransomee, how do you establish that you're working with a "reliable" ransom group? Is there a BBB for ransom groups? If so, how do you establish that the ransom group is actually the group with the good reputation? I guess I'm intrigued by how you achieve all that when you're talking about the perpetrator of a crime that is obfuscating their identity.
- rtkwe 2y agoVerification is an issue but if places do pay and they can't decrypt the victim is likely to talk about it. Also for this reason, like others have said, the ransomware tools have trial decrypts built in or the ability to generate a program/key that decrypt some of the files so that the victims can see that the attackers have the ability to decrypt some of their files. That requires zero trust and is more difficult than just having a single key that encrypts or decrypts everything.
- yardstick 2y agoThey’ll be able to prove they can decrypt a few of your files first. That’s generally enough for most people to move forward with paying the ransom. If they can prove they can decrypt, they have very little to lose by not releasing the decryption key after being paid.