8 ms·
Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
- CoastalCoder 6mo agoIt seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?
- deleted 6mo ago[deleted]
- ArcHound 6mo agoI don't think you can enforce such a rule. I think it's a good approach too. Another issue is that not paying up and risking restore from underfunded ops dept. might be more expensive than paying up AND making a selected executive look bad. And we can't have that, can we.
- finghin 6mo agoAgreed - it’s not that it’s a bad point but it would be an ineffective rule which is usually an excuse to forgo other more effective (usually more expensive) options
- TeMPOraL 6mo agoUnfortunately the actual solution will probably have to mirror real world, which means balkanizing the Internet to clarify legal jurisdiction, maybe some international police task force to aid with cross-border investigation, but ultimately it all hinges on whether and how much the countries with most nuclear aircraft carriers are willing to pressure other countries to take this seriously.
- wongarsu 6mo agoIt would make the ransomware statistic go down without actually stopping crime. Any company that considers paying the ransom would have a strong incentive to never report the security incident to avoid being punished for ransom payments
- entuno 6mo agoPlus it gives the ransomware gangs a whole new angle they can use. So, remember how you illegally paid us a ransom a few months ago? Unless you want to go to prison, then you better... We're already seeing this against companies who pay ransoms and fail to report the breaches when they're legally required to - but it would be much worse if it's against individuals who are criminally liable.
- nradov 6mo agoMake employees criminally liable for making ransom payments, along with whistleblower protections. Very few employees will risk going to prison to protect their employer. You can always get another job.
- ArcHound 6mo agoI don't think this helps anybody. There will always be some poor soul taking the blame for the crimes of the higher ups. And what exactly the crime would be? Using company money to pay an unspecified third party? Also pretty hard to enforce.
- nradov 6mo agoIt should be a crime to knowingly transfer money to criminals for any reason. And it wouldn't not hard to enforce: offer bounties to whistleblowers who turn in their colleagues.
- bigfatkitten 6mo agoIt likely is in many places, under laws relating to dealing with proceeds of crime, but I’m not aware of any prosecutions having ever been made on this basis.
- cucumber3732842 6mo agoAll that does is make the problem more expensive by whatever cut the middle men who will pop up take and however much the overhead of the obfuscation is. It might reduce payments at the margin, but probably not enough to be worth the cost.
- entuno 6mo agoIt's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind. Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'd all love to get there. But outlawing paying ransoms basically sacrificing everyone who gets ransomwared in the meantime until we get to that state for the greater good. And where companies get hit, they'll try hard to find ways around that, because the alternative may well be shutting down the business. But if something like a hospital gets hit, are governments really going to be able to stand behind the "you can't pay a ransom" policy when that could directly lead to deaths?
- nradov 6mo agoThat's fine, those are acceptable casualties. Make paying any sort of ransom a criminal offense.
- qzw 6mo agoYou know what's an even more acceptable casualty that would greatly reduce ransomware? Cryptocurrencies.
- flipped 6mo ago[dead]
- HeWhoLurksLate 6mo agoIt's all fun and games until it's your livelihood at stake, and then it makes a lot more sense to acquiesce, lick your wounds, and keep your business alive. Getting hacked is no fun, but companies don't deserve to die because something in their tech stack was vulnerable.
- nradov 6mo agoNah, those companies deserve to die. Let them fail. Creative destruction.
- Tangurena2 6mo agoI work in the state government space. Many targets/victims of ransomware are small/local government agencies and the ransom demands are greater than their annual budgets. Not every agency is big enough to have someone (bored) come in on Sunday, notice stuff getting encrypted and then run in to the server room and hit the big red button like Virginia's legislature in 2021[0]. Many ransoms are far more than the victim can actually pay. Not all ransom payments result in a decryption key that actually works. Notes: 0 - https://www.nbcnews.com/politics/politics-news/officials-virginia-state-agency-hit-ransomware-attack-n1285913 https://www.nbcnews.com/politics/politics-news/officials-vir...
- nradov 6mo agoMost local governments lack the scale and budget to competently maintain their own IT infrastructure. It's not just security but everything. They should outsource the infrastructure layer to a large contractor, or possibly to the state government.
- acdha 6mo agoContracting IT services at that level overpays by a whole number multiple for worse results because the government doesn’t have the in-house expertise to tell when the contractor is doing something wrong. (This is one reason why many construction projects go over budget: someone saved by laying off the engineers, so they pay 2-3x more for contractor A to oversee contractor B, guaranteeing 3+ party disputes for every problem) What does work better is outsourcing an entire function: if you pay Gmail for email services, you know exactly how much it will cost per user and have an SLA for problems which they can’t blame on you.
- bogwog 6mo ago> penalize the payment of ransoms If you mean ban all crypto currencies, then you're correct.
- alopha 6mo agoThe idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.
- bigfatkitten 6mo agoIt’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.
- mschuster91 6mo ago> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And no, backups aren't the solution either, they only limit the scope of lost data. In the end the flaw is fundamental to all major desktop OS'es - neither Windows, Linux nor macOS meaningfully limit the access scope of code running natively on the filesystem. Everything in the user's home directory and all mounted network shares where the user has write permissions bar a few specially protected files/folders is fair game for any malware achieving local code execution.
- ArcHound 6mo agoAFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.
- mschuster91 6mo agoIn the end the limiting factor will be the bandwidth of your disk arrays... enough compromised machines and they will get overwhelmed.
- _tk_ 6mo agoI think this article mostly shows that publicly announcing a successful ransoming of a company is now more popular than a couple years back.
- CodeCompost 6mo agoThanks, Satoshi
- super256 6mo agoDon't worry, ransomware already existed before BTC. The ransomware demanded Ukash and Paysafecard instead.
- ravenstine 6mo agoThanks, Tim Berners-Lee.
- deleted 6mo ago[deleted]
- shrubble 6mo agoI don't think there is a reasonable correlation, since stopping ransomware doesn't require that much of an increase in spending; it's a culture thing more than a money thing.
- Waterluvian 6mo agoMoving security tickets to the top of the stack is absolutely a money thing. Training is a money thing. Exchanging velocity for security is a money thing. Changing culture takes money.
- mewpmewp2 6mo agoWhat do you need to do to improve culture in the correct way?
- nradov 6mo agoAll senior leaders need to visibly spend time on areas of cultural focus. Employees will ignore an email from some random IT department middle manager. But if they see C-suite executives putting sustained effort into something then they'll pick up on that and start to do likewise.
- everdrive 6mo agoIf ransomware spending must scale directly with ransomware attacks then I don't see how companies could possibly keep up with the spending. A lot of the "gaps" in cybersecurity are essentially spending problems. Companies want to spend as little on it as they can.
- maxlegav 6mo ago[dead]
- Frieren 6mo agoStopping Ransomware is trivial if governments knew where the money goes. But cryptocurrencies and lax capital control pushed by the uber-rich makes it impossible. The technology is there and it is used to track the average citizens every move. But when it comes to rich people then the money goes and comes without control (and without taxation). Cryptocurrencies are a great solution to enable criminal activity. Their only use and highly appreciated by terrorists, criminals and dictatorial governments around the world.
- GuB-42 6mo agoIt is far from trivial. What are you going to do if the money goes to an enemy country? And while cryptocurrency are certainly popular with criminals, it is far from the only option for hiding transactions. As for the technology, if it exists, it is not very effective. The shadow economy is going strong even among average citizens, from drug trade to babysitting. If governments can't stop even the most trivial kind of unreported work in their own country, how to you expect them to stop well organized international gangs, sometimes backed by nation states.
- Frieren 6mo ago> It is far from trivial. What are you going to do if the money goes to an enemy country? Who send it? > And while cryptocurrency are certainly popular with criminals, it is far from the only option for hiding transactions. Start by removing the cryptocurrency option, that's an easy win. Go after other options afterwards. Removing cryptocurrencies is not going to stop all the crime but it will stop a lot of it and push criminals to more risky and easy to trace ways of getting money. > how to you expect them to stop well organized international gangs, sometimes backed by nation states. Removing their financing like cryptocurrencies. All that you say is that crime is impossible to stop. Bollocks. Start by banning Bitcoin and other crypto-crime-enablers and continue from there. You gave zero arguments to why cryptocurrencies should not be banned.
- BoiledCabbage 6mo agoCrypto is such a net negative for society. What cracks me up is how much crypto is emblematic of Libertarianism. Sounds promising if you think about it a superficially, but is obviously bad if you actually think about it in any real world terms. And not just abstractly - they both fall apart for the exact same reasons. Libertarianism is essentially "But, what if we scaled up the failures of crypto to all of society?"
- rbbydotdev 6mo agoI wonder what kinds of market hypotheses you could derive from the game theory here
- mystraline 6mo agoWell, given that C levels see cybersecurity has a bad return on investment (read: insurance), Ive seen countless numbers of people laid off these jobs. So yeah, I'm surprised its only 3x, and not even more. A good abliterated local LLM is great at finding dumb exploits and writing ransomware code. And the cybersec professionals? Yeah, theyre pivoting elsewhere and gone.
- ingohelpinger 6mo agoThe davos oracle https://youtube.com/shorts/Pqig_vIR4zI?si=G_JpJP90xqO0AQAd https://youtube.com/shorts/Pqig_vIR4zI?si=G_JpJP90xqO0AQAd
- rkozik1989 6mo agoWait until companies try powering their businesses with agentic systems. Then businesses aren't paying a ransom to prevent privacy law lawsuits, but rather they'll be paying a ransom equivalent to the black market value of their business.
- wslh 6mo agoThere is a publication making a related point in the DeFi security context: as TVL rises, the incentive to attack rises too, and defenses do not (or cannot) automatically scale with it[1]. [1] https://web.archive.org/web/20240911103423/https://www.bittrap.com/resources/defis-growing-pains:-as-tvl-raises-so-does-the-probability-of-being-hacked https://web.archive.org/web/20240911103423/https://www.bittr...
- flipped 6mo ago[dead]
- addybojangles 6mo agoCompany culture, training, resources. Sure, that costs money - but there isn't a direct correlation between spend this to prevent that.
- pxc 6mo agoCompanies spend a ton of money on very sophisticated, powerful, invasive, and expensive software to protect themselves against ransomware. But the best antidote to many forms of ransomware isn't security software at all— it's offline backups. Like so much in cybersecurity, an analysis by spending categories like this feels like vendors and their marketing teams driving the discourse. Even if we accept that dollars provide the right lens through which to look at this problem, companies that spend more on making sure they have good backups and good restore procedures aren't going to show up as spending more on cybersecurity in this kind of analysis.
- CodesInChaos 6mo agoThe company losing access to the data is only one half of the ransomware thread. The other half is unauthorized parties gaining access to the data. Backups only protect against the former.
- pxc 6mo agoThat's true, but the leakage component is characteristic of many kinds of breaches and not specific to ransomware. Likewise its defenses are not ransomware-specific.
- juancn 6mo agoWhy should it increase linearly?? If your counter measures are effective, you would expect sub-linear growth, heck you should demand it! The security industry is so fucked up.