Experts suggest AXA’s plan to shun ransomware payouts will set a precedent
cyberscoop.com
cyberscoop.com
Wow.
Having insurance just means you're a more attractive target now.
So being cyber-insured:
- likely to have money to pay the ransom
- probably not really implementing strong security policies
- management more important than reality, so engineering buy-in unlikely which also means backups and redundancies unlikely to be effective at the target
This makes you wonder who ends up paying for all of this (with time, energy, money, mental health).
> the insurers don't require you to actually make your security better
Dumb insurers it seems. Money going from dumb actor to smarter actors. This is capitalism.
The employees who are force-fed "security" crapware that some clueless CTO or other high level manager got sold at a golfing course (or got bribed to do such as Netskope did, see https://news.ycombinator.com/item?id=27047474), evaluated it on the specsheet as "fulfills the requirement of the insurance" and passed the can of turds down the line, for one.
In that interview, the hacker also talks about liking working with insurance companies because they understand how this situation works. They don't try to negotiate down to 10%; there's an understood negotiation window. They know how to get the bitcoins and send them, and probably know how to do bookkeeping for all of that.
I think it's closer to ransom insurance. The insurance company paying the ransom is a benefit, but not the primary reason to pay them. You pay them because they know what to do in that situation, and paying for ransom insurance looks slightly less ridiculous than paying a retainer to a Hostage Rescue Team. Most of the ransoms for hacks I've seen seemed well within the ability of the victim to pay. It's more about the negotiator that comes along with it, the bookkeeping, ensuring you get proof, ensuring they actually follow through, etc, etc.
I suppose having an efficient resolution to any 'problem' would be a net benefit for all parties involved, even if we would think all sorts of negative thoughts about it from a technical perspective. The same goes for botched negotiations or indeed people who don't even know how to deal with cryptocurrency.
It does make me wonder when thinking about hostage negotiations if that parallel insurance concept has different requirements on the company in question. Say you ship expensive employees to a facility in a country where they are likely to be captured for ransom, you'd expect some training for the employees to deal with 'being held hostage', or 'reducing the likelyhood of being taken'. If that is the case, something similar would be sensible in the ransomware scenario, right?
With money? The cost gets passed on to the customers. In a few decades, the invisible hand of the market might push those customers to firms taking this issue seriously... But I think that to be quite unlikely.
By targeting the insurers themselves (their cyber isn't magically better....), and getting a customer list.
- Charles Cotesworth Pinckney when asked for tribute by the Barbary Pirates
Maybe we need to start treating ransonware attacks more like this. Spend money on hardening targets. Also pursue an policy of economic sanctions against countries that tolerate these types of activities in their borders. Maybe we need to make it possible to quarantine countries from the rest of the Internet who abuse the commons.
Cyber insurance is not generally public information.
Moreover, there are different flavors of cyber insurance. Some of which cover ransom pay and some do not.
Having knowledge at such a thing means only 1 thing: Someone in the hacker group has access to insider information. Only select people have access to such policies.
Call me a skeptic but i would assume 1 of 100 such hacks don't actually know the cyber coverage that the target has. The ratio of 1:100 may be larger if you expanded the question to Hackers knowing which companies have Cyber coverage... but not which flavor. I still think this is a limited number anyway.
AXA here is just taking the easy route out. A lot of unsuspecting customers (startups) will buy this and get surprised 10 years from now, because their CEO did not bother to read the fine print of a 30 page document.
Lots of lawsuits in the horizon.
Insurance is literally protecting yourself from long tail events. This is such a thing.
It might not be required to be, but it might still be disclosed anyway for various reasons in public market filings, on investor calls, employees talking in social media, and so forth.
So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).
https://features.propublica.org/ransomware/ransomware-attack...
This will not solve the problem of ransomware alone, but is a step in the right direction.
Lets say you haven't learn the lesson of backup importance.
Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work.
Now, what do you do?
The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of the side that is held as hostage.
Why should insurers pay, when businesses have no incentive to do this?
Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.
https://en.wikipedia.org/wiki/Infrastructure_as_code
https://en.wikipedia.org/wiki/Virtual_machine
https://en.wikipedia.org/wiki/Disk_image
https://en.wikipedia.org/wiki/Shadow_IT
https://en.wikipedia.org/wiki/Von_Neumann_architecture
Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.
> "definition files"
Not executable. Text. Readable by humans. Inspectable by humans so you can root out rootkits. Not even the valuable data that cyber criminals go for anyway - they go for personal and financial data, not k8s config files.
> https://en.wikipedia.org/wiki/Virtual_machine
> https://en.wikipedia.org/wiki/Disk_image
Neither of those are relevant. You don't back up virtual machines or image disks - you take afore-mentioned plain-text, audited config files and spin up new instance from scratch.
> https://en.wikipedia.org/wiki/Shadow_IT
If those are actually shadow IT, they won't be in the backups anyway.
> https://en.wikipedia.org/wiki/Von_Neumann_architecture
This is irrelevant snark. If you back up a data file, it doesn't matter that it's stored in the memory of a Von Neumann architecture - it's only going to be used as a data file.
> Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.
Citation needed. Also, you just said:
> If the ransomware operators follow best practices
...so are we considering the ideal case, or not?
> I'm really not sure that has a serious answer.
Being snide is bad by itself, but it's even worse when you're wrong on top of it.
> If those are actually shadow IT, they won't be in the backups anyway.
Okay whatever then. I really don't have the energy. I'm just depressed people might believe you.
Just saying that paying the ransom may be the only way out of trouble.
The ransomware campaigns are pretty good on support. You will get a key for a sample of your data as a proof. You can sometimes pay progressively to get more trust. Getting your data back is just as important for the criminals as encrypting it in the first place - otherwise their business goes down.
And encryption your data doesn't help if you don't have backups.
Edit: Here is the story: https://www.theverge.com/2017/6/27/15881110/petya-notpetya-p...
So email provider blocked their email...
Actually, it does. "We'll delete your data." is not the only ransomware threat - the other one that's not quite as big, but growing, is "We'll leak your data."
Backups prevent denial. Encryption prevents dissemination.
Over time, companies start taking security more seriously. When it affects the users, they can just ignore, business as usual. But now, they can't just go on with their days, so that's the real accountability in my opinion.
I was not comfortable skateboarding again until I had good insurance as I do now. I don’t go crazy, but it is definitely a weight off my shoulders knowing that if I break a bone I’ll be able to get help without wrecking my finances. On the other hand, my brother doesn’t currently have insurance, and in the past he was super advanced at skateboarding. He is very hesitant to skate with me because of his fear of getting hurt. It’s pretty wild to see that play out in my own life, and it has made even more empathetic to the decisions other people make and the sorts of high-level factors that come into play there.
this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping.
I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be loopholes for shell / shelf companies to hide activities. The ransomware gangs themselves already today encourage you to reach out from private emails and promise smoother negotiation if you do.
Communication will be done by lawyers and subject to strong confidentiality protection, no one will ever know.
Basically, exactly how it happens with kidnappings today.
It's literally illegal to pay certain sanctioned organizations today for kidnappings - because they are designated terrorist orgs.
Who negotiates the ransom? Lawyers and security firms, been going on for a long long time.
Amusingly enough, this has even gone through courts in some places, you might wanna look up caselaw. They just decided to classify kidnappers as "criminals" for the ransom purposes, or some other such wordsmithing.
In the US these laws are simply ignored outright.
"The United States Code prohibits funding terrorist organizations, which includes the payment of ransom monies to terrorist organizations.2 However, the outlook in the United States on ransom payments being made to terrorist groups has softened. In June 2015, President Obama announced that private parties may negotiate with and pay ransoms to terrorist groups without fear of criminal prosecution, which has been the informal practice for years. In fact, nobody has ever been prosecuted for paying a ransom in the United States."
Just imagine your election prospects after jailing a mother who paid a ransom to save her child.
Imagine defending a claim that such law is constitutional, moral and just.
If your company is too big to fail, maybe it shouldn't be controlled by profit-optimizing external shareholders and reckless directors. If it isn't too big to fail and can't get a loan the usual way to pay for the ransom (or better: data recovery), just let it go bankrupt like any other company making a costly mistake.
You quit and go do something else. It's not like your life ends when a company ends.
In a less sarcastic tone: this is where your DRP and BCP get involved, and if you don't have those at that scale, then you were doomed from the start anyway and your existence as a company was on a short lifespan to begin with.
If your backups do not already include the above, then it is not a viable backup strategy.
It's a solved thing in the West for example, because the criminals know they will not get away with it. It's easier to get away with murder, because it doesn't create such social commotion, which in turn bring in the government focus.
More often than not “don’t negociate with terrorists” [0] facades are just a message sent to the world, only enforced when the stakes are low enough and the ‘terrorist’ party has nothing actually valuable.
[0] https://en.wikipedia.org/wiki/Government_negotiation_with_te...
For the business they do not care about the greater good, the greater good is not paying the ransom, for the business paying the ransom and then taking measures so it doesn't happen to them again personally is still likely to be the better option and that is the problem.
It wouldn't work well for many employees though. For example, try signing up for a legitimate service and guessing what email address the confirmation link will be sent from.
I know how bad it sucks to have to ask permission for every little thing, but if the alternative means risking ransomware attacks, then the case should be laid out transparently to everyone in the org so they understand why the rule is in place.
In this specific case, I imagine the reason for the announcement wasn't moral or financial – the company likely decided it did not want the legal liability of potentially funding international terrorism.
Regardless, in this specific instance I'm all for it. This will hopefully wake enterprises up so that they invest in good IT practices, which will have lasting effect on other parts of IT within firms.
Everyone on the Internet always acts like this is some great revelation: "they're only stopping it because it doesn't provide enough utility to them"
Duh, that's what utility is. Honestly, it's so repetitive and each time it's presented as some insight when it's so trivial it provides no new value.
They'll will string you along for _years_ correcting their own mistakes and then you're stuck with a bunch of useless cheques. I think half a dozen former colleagues and friends tried to help me out too, including someones grandma, to no avail whatsoever.
Really, the worst.
Up until about 2017(!), they were reimbursing people for treatment which was claimed back (as opposed to billed to the insurance company directly) by cheque exclusively, and there were rumours from the finance department that this was because lots of people never bothered to cash in their cheques because of the hassle compared to receiving a direct debit.
In NL, cheques went out of fashion in the 80ies, and banks haven't had the infrastructure to process them for decades now.
I think the best way to stop this "business" would be to make it as costly as possible for the "bad boys"... the course of AXA may be hard on some of their customers, but in the end it may be better for the net-society at whole.