This will not solve the problem of ransomware alone, but is a step in the right direction.
This will not solve the problem of ransomware alone, but is a step in the right direction.
Lets say you haven't learn the lesson of backup importance.
Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work.
Now, what do you do?
The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of the side that is held as hostage.
Why should insurers pay, when businesses have no incentive to do this?
Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.
https://en.wikipedia.org/wiki/Infrastructure_as_code
https://en.wikipedia.org/wiki/Virtual_machine
https://en.wikipedia.org/wiki/Disk_image
https://en.wikipedia.org/wiki/Shadow_IT
https://en.wikipedia.org/wiki/Von_Neumann_architecture
Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.
> "definition files"
Not executable. Text. Readable by humans. Inspectable by humans so you can root out rootkits. Not even the valuable data that cyber criminals go for anyway - they go for personal and financial data, not k8s config files.
> https://en.wikipedia.org/wiki/Virtual_machine
> https://en.wikipedia.org/wiki/Disk_image
Neither of those are relevant. You don't back up virtual machines or image disks - you take afore-mentioned plain-text, audited config files and spin up new instance from scratch.
> https://en.wikipedia.org/wiki/Shadow_IT
If those are actually shadow IT, they won't be in the backups anyway.
> https://en.wikipedia.org/wiki/Von_Neumann_architecture
This is irrelevant snark. If you back up a data file, it doesn't matter that it's stored in the memory of a Von Neumann architecture - it's only going to be used as a data file.
> Separation of code and executables is a nice idea that approximately 0% of organisations fully adhere to.
Citation needed. Also, you just said:
> If the ransomware operators follow best practices
...so are we considering the ideal case, or not?
> I'm really not sure that has a serious answer.
Being snide is bad by itself, but it's even worse when you're wrong on top of it.
> If those are actually shadow IT, they won't be in the backups anyway.
Okay whatever then. I really don't have the energy. I'm just depressed people might believe you.
Just saying that paying the ransom may be the only way out of trouble.
The ransomware campaigns are pretty good on support. You will get a key for a sample of your data as a proof. You can sometimes pay progressively to get more trust. Getting your data back is just as important for the criminals as encrypting it in the first place - otherwise their business goes down.
And encryption your data doesn't help if you don't have backups.
Edit: Here is the story: https://www.theverge.com/2017/6/27/15881110/petya-notpetya-p...
So email provider blocked their email...
Actually, it does. "We'll delete your data." is not the only ransomware threat - the other one that's not quite as big, but growing, is "We'll leak your data."
Backups prevent denial. Encryption prevents dissemination.
Over time, companies start taking security more seriously. When it affects the users, they can just ignore, business as usual. But now, they can't just go on with their days, so that's the real accountability in my opinion.
I was not comfortable skateboarding again until I had good insurance as I do now. I don’t go crazy, but it is definitely a weight off my shoulders knowing that if I break a bone I’ll be able to get help without wrecking my finances. On the other hand, my brother doesn’t currently have insurance, and in the past he was super advanced at skateboarding. He is very hesitant to skate with me because of his fear of getting hurt. It’s pretty wild to see that play out in my own life, and it has made even more empathetic to the decisions other people make and the sorts of high-level factors that come into play there.
this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping.
I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be loopholes for shell / shelf companies to hide activities. The ransomware gangs themselves already today encourage you to reach out from private emails and promise smoother negotiation if you do.
Communication will be done by lawyers and subject to strong confidentiality protection, no one will ever know.
Basically, exactly how it happens with kidnappings today.
It's literally illegal to pay certain sanctioned organizations today for kidnappings - because they are designated terrorist orgs.
Who negotiates the ransom? Lawyers and security firms, been going on for a long long time.
Amusingly enough, this has even gone through courts in some places, you might wanna look up caselaw. They just decided to classify kidnappers as "criminals" for the ransom purposes, or some other such wordsmithing.
In the US these laws are simply ignored outright.
"The United States Code prohibits funding terrorist organizations, which includes the payment of ransom monies to terrorist organizations.2 However, the outlook in the United States on ransom payments being made to terrorist groups has softened. In June 2015, President Obama announced that private parties may negotiate with and pay ransoms to terrorist groups without fear of criminal prosecution, which has been the informal practice for years. In fact, nobody has ever been prosecuted for paying a ransom in the United States."
Just imagine your election prospects after jailing a mother who paid a ransom to save her child.
Imagine defending a claim that such law is constitutional, moral and just.
If your company is too big to fail, maybe it shouldn't be controlled by profit-optimizing external shareholders and reckless directors. If it isn't too big to fail and can't get a loan the usual way to pay for the ransom (or better: data recovery), just let it go bankrupt like any other company making a costly mistake.
You quit and go do something else. It's not like your life ends when a company ends.
In a less sarcastic tone: this is where your DRP and BCP get involved, and if you don't have those at that scale, then you were doomed from the start anyway and your existence as a company was on a short lifespan to begin with.
If your backups do not already include the above, then it is not a viable backup strategy.
For the business they do not care about the greater good, the greater good is not paying the ransom, for the business paying the ransom and then taking measures so it doesn't happen to them again personally is still likely to be the better option and that is the problem.
It's a solved thing in the West for example, because the criminals know they will not get away with it. It's easier to get away with murder, because it doesn't create such social commotion, which in turn bring in the government focus.
More often than not “don’t negociate with terrorists” [0] facades are just a message sent to the world, only enforced when the stakes are low enough and the ‘terrorist’ party has nothing actually valuable.
[0] https://en.wikipedia.org/wiki/Government_negotiation_with_te...