If you scroll into a different article, they push the last article's URL into history and pop that until different domain is reached when pressing back.
IMO, it should be illegal to pay ransomware. Bad actors only deploy ransomware because enough people pay the ransom for it to be worthwhile. Raise the minimum risk-adjusted price (chance of getting caught paying * fine) by enough, and people will make the rational decision to not pay it.
Combine with an advertising campaign to make it common knowledge that paying ransomware gets you fined, and that you should have good backup-and-restore ability instead, and the problem should become much less intense.
(side note: paying ransomware has negative externalities, since it funds ransomware operations that hurt others. If criminalizing it offends your libertarian aesthetic, think of it as a Pigouvian tax instead.)
> Raise the minimum risk-adjusted price (chance of getting caught paying * fine) by enough, and people will make the rational decision to not pay it.
You don't need to make it illegal to pay ransomware to use this type of logic to stop ransomware. Here's an alternative version:
It should be illegal to deploy ransomware. Raise the minimum risk-adjusted price (chance of getting caught deploying * fine) by enough, and people will make the rational decision not to deploy it.
But it doesn't work. The chance of getting caught is (currently) so infinitesimal that it is ignored, and ransomware is rampant.
In your system, the chance of getting caught paying would be equally infinitesimal, with the added problem that anybody involved with prosecuting or convicting would fully understand that they are harming the victim rather than the perpetrator.
That definitely is not true. If a company has to pay $1m for ransomware, they would likely need to disclose it publicly, and at least privately to auditors. Making it illegal as in jail time would prevent any corporate employee from agreeing to do it so it would effectively stop it.
It has negative externalities? Don't make it illegal. Tax it to hell. $50k minimum plus 700% of the ransom paid ought to cover it. Dodging those taxes and trying to pay secretly, now that's illegal.
The taxes paid by the desperate and careless can be used for the expensive international cases against the scammers.
Unless the entire world adopts this legislature in lock-step, there will still be incentives for ransomware authors to infect systems.
So what if French, Spanish, and American victims are legally prohibited from paying, if there's still money to be made in India, Australia, and Ireland?
Because the marginal cost of vulnerability exploitation is very low, what will end up happening is ransomware distributors will remain in business, and French, Spanish, and American companies will now not be able to recover any lost data. While their Irish counterparts pay the extorters, fix their systems, and move on with their lives.
There's opportunity costs for engaging in ransomware rather than doing other activities. If you're good enough with computers to do ransomware, you're also probably good enough with computers to do legitimate work. We don't need to completely starve out the ransomware actors, we just need to make it less lucrative than their other alternatives.
There's still a problem - nothing's stopping India, Australia, and Ireland in your example from benefitting from the reduction in ransomware without paying the costs for disincentivizing it. Free riders are a problem for public goods, such as low-crime environments.
It's situations versus strategies. Making certain kinds of situations worse will make people choose better strategies. This is one solution to the Prisoner's Dilemma - if you defect, the mob boss puts a hit out on you, so nobody talks.
If something such as that were implemented, sure you'd stop a few, but it would just become an underreported metric. Making something illegal does not wholesale stop it from happening, it just pushes it out of view.
It'd at least put a significant dent in public corporation's spending on it. If they share it in their audits and reports to shareholders, they get nailed on paying ransomware. If they hide that they paid out significant amounts of money, that's accounting and/or securities fraud. The biggest sensible course of action is to put the IT infrastructure in place that mitigates ransomware attacks.
The natural response for the attacker is to discount the ransom amount to compensate for the expected cost of penalties (from breaking the law). This will deter attacks if the expected penalty is greater than than the ransom amount, but anywhere less than that, the government just becomes a co-conspirator in the ransom.
In Italy in the event of a kidnapping all the assets belonging to the kidnapped person and his/her family are immediately frozen by the law. As a consequence, paying the ransom effectively becomes a crime.
Kidnappings in Italy are now much rarer than they used to be (see: <https://en.wikipedia.org/wiki/Anonima_sarda>). I have no idea in what measure it depends on the asset-freezing law.
That means that if I want to pay the ransomware, I also have to pay the (ongoing?) blackmail fee so the ransomware installer doesn't tell anyone I paid the ransom?
> “The origin of the infection is not confirmed at the moment, but sources close to the company point out that it is being treated as an attack originating in China,” El Mundo writes.
It's amazing how any organization can get away with poor security and backup practices by blaming either Russia or China, without showing any evidence to back their claim.
To my mind, there's a difference between "blaming Russia or China" and saying the attacks originated in Russia or China. The former is a reference to the nation state itself (i.e. state sponsored cyber attacks), while the latter is broader and can also mean private individuals within those respective countries.
And, in fact, given that by now news reports are indicating that the greatest number of affected machines in this wave of attacks is in Russia itself, it's probably private criminal groups.
The issue being exploited in the ransomware attack was patched months ago (MS17-010).
The reason that it's successful is a) people don't apply patches quickly b) people us unsupported versions of the operating system and c) the NSA dropped a reliable exploit for it.
All software has bugs, from all vendors. Security patching is a fact of life.
The NHS one was posted on Slashdot earlier. A bunch of companies and governments seem to be affected and it's spreading across much of Europe. Whoever started this is probably going to make a killing.
The trouble is, it's not unreasonable to open en e-mail attachment if it looks like it comes from someone on your work network. You may be expecting spreadsheets or PDFs every day, and the most recent MS issue was due to the scanning process itself; you didn't even have to open that attachment.
I feel like several things need to happen here. Non-tech jobs need solid white listing. A lot of white listing software is crap and at B-sides 2016, there was a talk on how to bypass a lot of them. Solid white-listing based on application hashes and complete paths of the binary needs to become the defacto standard.
Many PCs need to stop being PCs. If it's order entry for a doctor or nurse and the software already has a web interface, a Chromebook or Linux box that just boots straight to Firefox/Chromium or something else that's very simple/kiosk is a much better and cheaper solution. You don't need a full blown Mac/Win laptop for most of the applications we use them for. (Maybe Win 10 S could even be an option in this situation, if you can connect it to a domain and offer only company apps instead of store apps?)
Large organisations need solid backup strategies, snap-shoting storage systems for staff, backup verification (would suck of that storage rack had a ransomware timebomb waiting to encrypt your backups) so they're never out more than 24 hours of date.
Even though a lot of this is a "less is better" approach, it does increase costs, it is a learning curve, it does add some limitations and, for public organisations like the NHS, it will be a burden on already taxes IT departments.
It sucks, but I wonder if we'll start to see better practices due to this and if these types of ideas will become common practice in the next decade.
Absolutely we need to decrease the attack surface. We can't expect for each of those doctors to make sure they always have the latest version of Windows, etc. I'd also go so far as saying that we can't even trust IT to always update the systems because large corporates loose track of boxes all the time.
I would like to read someone's educated guess on what is the % of bitcoin transactions that have a direct purpose of paying illegal activities (drugs, guns, black hat hacking, ransomware, etc).
I am not capable of giving such a guess. I would be happy to read even about the order of magnitude of said %.
Drugs are probably a big share of all btc value and maybe it's "gold standard" since it's one thing you can find people wanting to trade stuff for it anywhere in the world. The rest of the illegal activity would probably need to be calculated separatedly because I'm almost sure drugs would dwarf them.
49 comments
[ 3.3 ms ] story [ 95.0 ms ] threadIf you scroll into a different article, they push the last article's URL into history and pop that until different domain is reached when pressing back.
EDIT: nvm. Apparently they mean to imply they have about ~1759 infected machines.
300$ dollers per machine ≈ 300 Bitcoins ≈ 510,000€
Combine with an advertising campaign to make it common knowledge that paying ransomware gets you fined, and that you should have good backup-and-restore ability instead, and the problem should become much less intense.
(side note: paying ransomware has negative externalities, since it funds ransomware operations that hurt others. If criminalizing it offends your libertarian aesthetic, think of it as a Pigouvian tax instead.)
You don't need to make it illegal to pay ransomware to use this type of logic to stop ransomware. Here's an alternative version:
It should be illegal to deploy ransomware. Raise the minimum risk-adjusted price (chance of getting caught deploying * fine) by enough, and people will make the rational decision not to deploy it.
But it doesn't work. The chance of getting caught is (currently) so infinitesimal that it is ignored, and ransomware is rampant.
In your system, the chance of getting caught paying would be equally infinitesimal, with the added problem that anybody involved with prosecuting or convicting would fully understand that they are harming the victim rather than the perpetrator.
Legislate proper security more, enforce it, fund an electronic police to help combat it.
The taxes paid by the desperate and careless can be used for the expensive international cases against the scammers.
Unless the entire world adopts this legislature in lock-step, there will still be incentives for ransomware authors to infect systems.
So what if French, Spanish, and American victims are legally prohibited from paying, if there's still money to be made in India, Australia, and Ireland?
Because the marginal cost of vulnerability exploitation is very low, what will end up happening is ransomware distributors will remain in business, and French, Spanish, and American companies will now not be able to recover any lost data. While their Irish counterparts pay the extorters, fix their systems, and move on with their lives.
There's still a problem - nothing's stopping India, Australia, and Ireland in your example from benefitting from the reduction in ransomware without paying the costs for disincentivizing it. Free riders are a problem for public goods, such as low-crime environments.
Someone using a zero-day exploit gets in and encrypts everything that runs my company and demands a ransom in exchange for the key.
Using your logic, my government says I'm not allowed to take measures to get my company back in order.
Why should we further expand the power of the government to make an already shitty situation even more detrimental?
I know the current title is the actual title of the article, but it's misleading.
It's amazing how any organization can get away with poor security and backup practices by blaming either Russia or China, without showing any evidence to back their claim.
The reason that it's successful is a) people don't apply patches quickly b) people us unsupported versions of the operating system and c) the NSA dropped a reliable exploit for it.
All software has bugs, from all vendors. Security patching is a fact of life.
The trouble is, it's not unreasonable to open en e-mail attachment if it looks like it comes from someone on your work network. You may be expecting spreadsheets or PDFs every day, and the most recent MS issue was due to the scanning process itself; you didn't even have to open that attachment.
I feel like several things need to happen here. Non-tech jobs need solid white listing. A lot of white listing software is crap and at B-sides 2016, there was a talk on how to bypass a lot of them. Solid white-listing based on application hashes and complete paths of the binary needs to become the defacto standard.
Many PCs need to stop being PCs. If it's order entry for a doctor or nurse and the software already has a web interface, a Chromebook or Linux box that just boots straight to Firefox/Chromium or something else that's very simple/kiosk is a much better and cheaper solution. You don't need a full blown Mac/Win laptop for most of the applications we use them for. (Maybe Win 10 S could even be an option in this situation, if you can connect it to a domain and offer only company apps instead of store apps?)
Large organisations need solid backup strategies, snap-shoting storage systems for staff, backup verification (would suck of that storage rack had a ransomware timebomb waiting to encrypt your backups) so they're never out more than 24 hours of date.
Even though a lot of this is a "less is better" approach, it does increase costs, it is a learning curve, it does add some limitations and, for public organisations like the NHS, it will be a burden on already taxes IT departments.
It sucks, but I wonder if we'll start to see better practices due to this and if these types of ideas will become common practice in the next decade.
It's a worm, this isn't a targeted email virus.
I am not capable of giving such a guess. I would be happy to read even about the order of magnitude of said %.
On Telefonica: https://www.bleepingcomputer.com/news/security/telefonica-te...
Globally: https://www.bleepingcomputer.com/news/security/wana-decrypt0...