Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So a hacker has your data, and demands money.

The government's proposal:

1. If you pay the hacker, we want money because you paid a hacker.

2. If you don't pay the hacker, we want money because you leaked your users' data.

The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.



> The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.

The rationale for outlawing ransom payments is that it eliminates the incentive for ransomware attacks.

The real question is whether "no-concessions" policies reduce the incidence of ransomware attacks. The answer to that question isn't obvious. However, conditional on no-concessions working in the case of ransomware, "kicking corps while they're down" is not a relevant consideration. The cooperate-cooperate quadrant of the game has higher expected value than the defect quadrants, so you force cooperation by whatever means necessary, even if that means some actors don't get the best possible outcome from their own perspective.

NB: there's some evidence that no-concessions policies don't work particularly well in the case of kidnapping [1]... I'd take care extending this finding to ransomware gangs. If you read the whole PDF, it'll become clear why this behavior is interesting but might not transfer to today's ransomware gangs. That said, when crafting policy on ransomware attacks, it's worth keeping in mind that ransomware attackers may or may not be of the homo economicus species. At the very least as an assumption that you start with but are open to dropping as new evidence prevents itself.

[1] https://www.rand.org/content/dam/rand/pubs/perspectives/PE20...


Penalizing you for being blackmailed doesn’t force cooperation. Because an alternative is paying quietly and not informing the authorities. This is what this model encourages in practice. Less cooperation.


The government should fine the company either way for not properly securing their user's data. Security is serious business, it's time companies took it more seriously.


You say this as if a disgruntled employee can't compromise the security of literally any system at all.

Remember Snowden didn't hack the CIA. He just worked there. And has a user/pass.


Part of a good security posture is protecting yourself against insider threats. If you're not doing this, you're not taking cybersecurity seriously.


But _somebody_ has to have clearance to get to the data in some way. You can't protect yourself against that person. It's not possible.


> Part of a good security posture is protecting yourself against insider threats. If you're not doing this, you're not taking cybersecurity seriously.

How do you protect yourself? There are ways to mitigate, surely, but any failure can be a catastrophic incident, and it is literally impossible to protect against all internal threats (in the sense of guaranteeing that no such threat is ever acted upon). All else aside, it just shifts the responsibility one level up: now you have to worry about a compromise of the people responsible for protecting from internal threats.


Security is hard, and the difficulty of answering this question in any particular org probably takes up a lot of the time of any competent and properly staffed CISO office.

But, basically, the only mechanisms in play are some combination of limiting access and, where that's not possible, decreasing employees' ability/incentive to defect.


This is a bit like the question how to have a system that promotes honest, smart politicians. As you might guess, nobody has figured that out yet.

Ultimately the only way is an omniscient, omnipresent CEO who does all the important stuff alone. Which is probably the core reason why no one has leaked God's files on the Universe, yet.


Yes, it's EXACTLY like that.

Perfection is impossible, but that's also no argument for repealing sunshine laws or legalizing outright bribery.

You're letting perfect be the enemy of better.


Oh yeah let's talk about how perfect is the enemy of better, when discussing an idea to bury victims of ransomware into the ground with government penalties on top of ransom and leaks.

Here's another thought in the same vein: let's penalize rape victims for attracting male gaze and not fighting sufficiently to avert contact. Sure, some women will get raped still, but let's not let perfect be the enemy of better. That's how they deal with it in some countries actually. They blame the victim. It doesn't reduce rape at all. In fact it reduces reported rape, because women don't want to face the legal and family repercussions of getting raped.

Let me tell you what will happen in the case of ransomware.

1. You get hit by ransomware.

2. Previously you'd ponder contacting authorities. Nope. They're gonna close your options and fine you either way. Keep your mouth shut.

3. Pay as quickly as possible and hope the word never comes out you were blackmailed at all. As far as the world and the government know, your security is fine, nothing happened. No fines, no lawsuits.

4. Result: ransomware proliferates and grows into the biggest organized crime organizations of this century.

How's that about not letting perfect be the enemy of better?


We must protect ourselves against insiders. Let's hire some insiders to do it.

Ah, shit.


...In most cases, the CEO and probably a huge number of people in upper management can do any number of things to nuke a company from orbit. But this doesn't happen very often. The things that those people can do to nuke a company from orbit are typically tightly controlled functions, and the people with those responsibilities are carefully selected and extremely well-compensated.

Yes, some employees need to be absolutely trusted. No, you don't need to absolutely trust every employee (or even most employees).

Turning to your Snowden example, if you're a TLA and find yourself completely owned by an outside contractor making low six fiures, then you've utterly failed and managing insider risk.


If disgruntled employees were the main actors stealing user data I'd feel a lot better about the state of IT security.


Think carefully if you care how someone stole the data. Or you care more about how likely it is to steal the data. I can argue that penalizing companies for being blackmailed in fact encourages less cooperation with authorities, which encourages more people to blackmail them


The ransomers seem to perform this function rather effectively.


No necessary so as the company may just pay for insurance from future attacks. Granted insurance companies then will demand some compliance with security check lists, but this feedback loop is very slow.


Not anymore because latest business was, if you don't pay they will leak the data:

https://www.forbes.com/sites/thomasbrewster/2021/05/13/ranso...


Then the incentive is to avoid becoming a victim to ransomware in the first place by making it more cost effective to hire decent security than to take the risk and end up getting targeted.


Or to find more sneaky ways of completing the transaction...


> your data

I think it helps IT departments to go to upper management and put a dollar figure to information security.

Personally, I’d prefer the CEO and the board go to prison for a few years for paying ransom.


Or, you can think of it as increasing the incentive to take security seriously.

And it seems like they’d have to pay the fine for (2) regardless of if they pay to get the data back in this case.


It's also an incentive to pay immediately, and tell no one about it.


Sounds good to me. Why should companies be allowed to save money by exposing our personal data and then pay for it by funding terrorist organizations, organized crime, and totalitarian governments?


You imply as if there's a store where you can go and buy yourself 10 pounds of security for 20 money, and that's that, your data is safe for life.

Security is a heuristic based on millions of variables other than a simple price label. You can pay a lot and still get everything leaked.


Why do you assume that it is personal data that are at risk? Maybe it is your new super-duper tech that hackers will threaten to leak to the rest of the world?


That's the first-order effect. The second-order effect is companies paying less to ransomware creators, making it a worse business to be in. Over time this should result in less business pain.


This will ultimately just create a larger market for ransomware insurance. Insurance premiums are likely the lowest cost compared to 1) paying the fines or 2) actually improving security.

Most businesses already have some form of insurance covering their liability in these situations and those will just price in whatever fines might need to be paid.


> This will ultimately just create a larger market for ransomware insurance.

CEO of Swiss Re to said this[1]:

> He observed that the cyber insurance market is currently worth around $5.5 billion in premium, compared to “gigantic” yearly losses that extend into the hundreds of billions of dollars.

“There’s a cyber market that’s very tiny compared to the total exposure,” he told CNBC. “It’s going to grow but only a tiny minority of cyber is actually insured.”

“And I would actually argue that overall the problem is so big it’s not insurable,” Mumenthaler continued. It’s just too big. Because there are events that can happen at the same time everywhere that are much more worrying than what you just saw.”

[1] Pipeline cyber attack not surprising, says Swiss Re https://www.reinsurancene.ws/pipeline-cyber-attack-not-surpr...


This is the most likely outcome in my opinion. I won't be surprised if the insurance lobby has made this happen. :-)


Option: 3. Pay your IT/Security department or hire a consultant Pay for licenses and updates of software and hardware Don't expect job of 5 people to be done by 1 Don't let bunch of trainees run your infra

Government should make companies pay even more so other companies understand what the proper way to "not getting ransomed" is or spend money finding out. Instead of money going god knows where to finance god knows what.

SolarWinds was blaming some intern for a bad password, if it would be up to me, I would close down whole company for such utter bullshit. I understand at their scale it is still possible to have some loose ends but no one was doing any audits, no one was doing any security awareness? I bet you could blame at least 10 managers there for not even thinking about security and not some intern.


You may be presenting a false choice: Even if you pay hackers off, there was still a data breach.


Shouldn't you pay the fine for leaking user data either way?

Even if you square things with the blackmailer, there's no good way to ensure they don't sell the data to someone else as well.


What's wrong with this?

Secure your users data and your infrastructure


Am i the only one who think this sounds fine? If you're collecting user data, then yeah, you should be held to heightened level of responsibility.


Hopefully this leads to companies taking IT security seriously for once. Hit them where it hurts the most.


> if you're a victim of ransomware

ftfy:

if [corporation is] a [target] of ransomware

I don't feel sympathy for them the way I would a person.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: