Companies may be punished for paying ransoms to sanctioned hackers
reuters.com
reuters.com
It will be a long, long time before the marketplace evolves sufficient technological measures to guard against state-sanctioned/possibly-state-sponsored malicious actors operating with impunity in a lawless environment.
E.G. http://pulse.ncpolicywatch.org/2021/05/12/as-nc-lawmakers-fa...
Then they also don't need to pay the ransoms.
The important part is having the backup in some form. Having a well tested restore ability is a great idea, but not nearly as important as having the backups in the first place. Most backup programs are designed for restore, even if you screwed up, odds are you can get the data back later.
You will have a hard time to find a backup program that doesn't have a good and tested restore procedure. However that doesn't mean it works in your particular edge cases.
Even if the backups would work perfectly, this forced downtime might the best time to apply some change that your admins have known should be done for a while but couldn't afford the downtime. (you couldn't do a schema update, but there are some smaller config changes that still require taking the master database done for a bit)
Backups also ensure business continuity - which might be more important than past data for some workflows.
Regardless, backups are the first priority. Then a tested restore procedure.
Hum... Backups aren't normally "at the edge of failure", the procedure either works or doesn't work. One must test to ensure the procedure works and continue working after all the environment changes done today.
That is, except for proprietary formats, like Exchange. Those can fail at any time, retroactively.
You mean an average person will uninstall MicroSoft Windows?
Peope were telling of the inevitable downfall of MicroSoft since before I was born.
So the Internet could be like this if it was more regulated. Anonymous traffic could be prohibited...no more TOR nodes, no hands-off proxying of traffic, no "it's an open access point, I totally don't know who was creating that torrent traffic".
Would these sorts of laws be accepted, or would they simply result in more attempts to anonymize traffic?
I imagine that this is sort of what things are like in more authoritarian places like China. Is it effective there?
It's also not really a national security issue. The USA will continue to exist and function as the USA even without gas pipelines and power generation.
"National security" isn't some blanket term to mean "large infrastructure required for major industries", it has a specific, defined meaning. Just because the feds use it as a blanket justification for a bunch of stuff doesn't mean we should embrace that usage, otherwise when everything is a matter of "national security" than nothing is. It's just like the overuse of the term "terrorism" to mean "any big crime".
Temporary outages, maybe. Sustained outages (or destruction) of gas pipelines and power generation, if systemic, would almost certainly mean mass starvation.
They aren't? Has NORAD control been hacked? Any battleships or predator drones?
I admit it's a bad look when, for instance, a VA database is compromised and private information for millions of government employees are exposed, but I'd also be SHOCKED if the NSA were dedicating resources to protecting that data.
Outside of Snowden, what leaks of stuff "the US defense forces" are actually attempting to protect have been captured?
>yet we're expecting individual companies to go up against them?
The companies in question appear to not even be doing basic things like taking backups and making them immutable. I don't think anybody is expecting them to have perfect security, but it doesn't take a lot of effort to backup to a tape and stick it in iron mountain for 2 years, it just takes money.
Even a cup of water cannot function if it cannot maintain structural integrity.
If it was, how would we know?
(outside of, uh, kinetic consequences)
yes actually over ten years ago this happened already https://www.cnn.com/2009/US/12/17/drone.video.hacked/index.h...
Maybe security holes are just part and parcel to the whole enterprise. So you have to accept them and center your preparation around your response to such losses. How do you get back up and running? How do you operate without the asset that was compromised? And so on.
OTOH, this isn't just about bad actors raiding. This is also about terrible security practices that are easily avoidable with an ounce of expertise and giving a shit.
In addition to your idea (let's make believe for a moment...) how about the US govt itself sponsors these attacks, and then instead of demanding ransom, they just levy huge fines against the companies who have carelessly let this happen? Extending your analogy, this would be no different than fines or lawsuits for carelessness and failures in physical infrastructure.
Unfortunately, the marketplace -- at least certain segments of it -- are far beyond .mil/.gov in terms of capacity and sophistication. E.g., AWS's formal tools for code-level security is what DARPA's been yelling about doing for decades, but gov't contractors and the branches/agencies are unable/unwilling to catch.
I'm not sure how to fix gov or mil, but a good starting point within mil is to stop making career officers with theology and polisci degrees but zero CS training the first-line managers of cyber commands.
what tools?
Applied theology.
By the third time I had to seek out existential comfort.
What you got a degree in shouldn't be the make or break of your career.
You are an exception.
In the military and certain parts of the corporate world ("enterprise" companies mostly), there is a wide-spread and systemic problem with horrendously unqualified people managing software/IT groups. E.g., Susan Mauldin for a recent example.
We can allow space for self-taught people without opening the flood gates. No one should be in charge of IT security without first developing deep technical expertise at some point in their career.
For anyone as confused as I was, this is probably referring to the Equifax security officer. My local search engine mostly brought up a murder case.
Theology says something specific about how you process reality.
I will point out that one of the founders of a core CS discipline have written books [1] on what can be called theology.
[1]: https://en.wikipedia.org/wiki/Donald_Knuth#Works_regarding_h...
We all have musings that cross domains; why does this persons book hold significance to you for this thread?
Applied Theology is an American evangelist field of study that focuses on shaping your life and the world around you to operate according to the will and word of the Christian Evangelist god.
Oxford (UK): https://www.ox.ac.uk/admissions/graduate/courses/mth-applied...
California Baptist: https://calbaptist.edu/programs/bachelor-of-applied-theology...
"Everything from preaching to media technology, from helping with funerals to discipling [sic] unbelievers."
This is one of those very frustrating conversations to have online, not that different from people saying "but it's the People's Democratic Republic of whatever."
The Baptist thing called "applied theology" is a part of the Dominionist movement. Fundamentally it's a theocratic endeavor.
I agree that theology has been used in a thousand ways across two thousand years and I'm sad that if you have a degree in "Applied Theology" from a small religious college in the Midwest it's definitely not just "I was thinking of becoming a minister."
But dominionism is a real thing. People major in it, they drop out, they get other jobs, and then you have this record of their beliefs right there on their resumes. It'd be easier if they had no degree at all.
> Everything from preaching to media technology, from helping with funerals to discipling [sic] unbelievers
I don't see an issue with this, if discipling unbelievers means something similar to promoting the church, or missionary-esque behaviour (of the non-colonial form, obviously). If it means how to deal with atheists in a theocracy then I'm not a fan.
(And in part just an opportunity to play with language. I grew up in the Bible Belt. Gentle humor about religion/spirituality is something I am no stranger to.)
Is this true?
This can't be true. Surely they must have some CS experience?
I took my last bus off a USMC base so long ago I've raised a kid who's in med school since. Can someone with more recent experience chime in on whether or not this is hyperbole?
I suspect this bill will face significant lobbying against it by companies involved in secured backups along with the ransomware distributors themselves.
Most probably "state actors" are taking advantage of this asymmetry to extort money and bind resources. It's a hidden "war" going on out there.
Balance is different when you have and a company with understaffed IT and all which usually goes along with this: software which is not updated for months if not years despite known vulnerabilities in it, legacy systems which are kept "just in case" because no-one knows what will be broken if they will be decommissioned, poorly managed credentials to external systems, and so on.
Only because we, as a society, have decided that we don't care about information security, to the extent that we protect incompetent, ignorant, or uncaring individuals and organizations from any liability for their actions. How much better off would we be if we had fined Experian $1M for every user account they lost? Or for any of the other breaches in the preceding decades? How much more careful would your average bootcamp grad be writing the code that forms attack surfaces if they had to pay liability insurance?
By and large, we have had a good idea how to make technological measures much more resistant to attack since the '80s. It's always been considered too difficult and too expensive, something we have put exactly no resources towards fixing. Ten years of a quarter of the collective budget we spend on using ML to violate privacy would probably take everyone except state sanctioned actors out of the picture.
(All numbers pulled out of my flying monkeys.)
While banning such payments might remove the incentives, that also put a huge burden on the victim and the transition to better cybersecurity should be less disruptive than an outright ban.
Another solution that has no harms and only benefit is to require the reporting of every ransom payment. That would give the government the crypto transaction information to conduct taint and attribution analysis. It is currently illegal to knowingly use funds received from kidnapping or ransoms, and this reporting requirement would help the government enforce that.
They'd pretty obviously not; companies are already forced to pay a fine (or a ransom, but it's money spent) and it obviously does not incentivize them to properly secure their network. Adding a fine to pay to the government on top (or, more cynically, a tax) will not change much, except that stricken companies now get hit harder, as you said.
Make cyber insurance paying ransoms illegal and you'll see boards start funding IT security.
Boards will, generally, still not fund and support effective security culture without steep penalties for breaches (i am in infosec and speak to c suite folks as part of my gig; breach impact, in their current form, are "cost of business"). “Show me the incentive, and I will show you the outcome.” – Charlie Munger
https://www.insurancejournal.com/news/international/2021/05/... (Insurer AXA to Stop Paying for Ransomware Crime Payments in France)
Definitely a must have for now and on a international scale IMHO.
But a effective ban on ransom payments would still be the most effective measurement.
The problem is how do you effectively ban it?
For many countries such thing could never be enforced, so it wouldn't remove the sensitive for non-specific target ransomware attacks IMHO and as such won't work.
If a corporation pays, and ledger history can provide definitive proof, the corporation faces the same penalties as if they violated international sanctions. Corporations will need to onramp fiat to crypto somewhere, and FinCEN [1] will know based on SARs (Suspicious Activity Report)/CTRs (Currency Transaction Reports), or SWIFT if international monies transfers [2].
[1] https://www.fincen.gov/resources/statutes-regulations
[2] https://www.swift.com/our-solutions/compliance-and-shared-se...
so it follows that if a country bans ransoms payments criminals will just ingnore that country and focus on the next easiest target, putting pressure on every country to follow the example and ban it too.
I think this will be very effective at stopping the most sofisticated targeted attacks but won't have much effect on indiscriminate "viral" attacks because those attack indiscriminately and wrecking targets from banned countries at least would serve as detterrant for victims in countries that can.
Without a legal way to make payments, companies can no longer justify the tradeoff of paying up and fixing the leaks as they spring up. This incentivize them to give importance to security and actually overhauling their infrastructure properly.
If everybody agrees not to pay ransom and follows through, criminals won't try to hack companies to collect ransom.
But as an individual company, you can't coordinate with everybody else to prevent everybody from paying ransom, so not doing so puts you on disadvantage.
Philosophically, the usefulnes of government is to threaten violence to solve the coordination problems amongst individuals.
People rarely understand that the coordination solution is one of the most important powers the government offers over privatization.
They can tax/penalize undesired behavior. Individual companies may end up worse off, but as a whole the business community is better off with the rules in place.
This is why governments have to tackle pollution and climate change too. Companies are profit-motivated, and will only respond to what the economics demand. When governments start imposing demands with penalties attached, that's when companies actually start changing behaviors.
I think the transition to better security will go faster if companies know they can't buy their way out of the problem.
One issue is that if the costs of finding different vulnerabilities are distributed along a spectrum, this only lets you find the <$5k ones.
And the solution would be for this security firm to have Russian (allegedly ;-)) friends that deploy the ransomware and give them the decryption key. See, hacked company, you're not paying the hackers, you're paying IT security experts that are able to recover your data!
The proxy company can always say they are using their super crypto cracking skills to reverse the encryption. The hacked company would have no way to know they were paying the hackers, nor any way to find out.
Obviously the proxy company is breaking the law, but they might be in some untouchable jurisdiction.
The government's proposal:
1. If you pay the hacker, we want money because you paid a hacker.
2. If you don't pay the hacker, we want money because you leaked your users' data.
The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.
And it seems like they’d have to pay the fine for (2) regardless of if they pay to get the data back in this case.
https://www.forbes.com/sites/thomasbrewster/2021/05/13/ranso...
Remember Snowden didn't hack the CIA. He just worked there. And has a user/pass.
How do you protect yourself? There are ways to mitigate, surely, but any failure can be a catastrophic incident, and it is literally impossible to protect against all internal threats (in the sense of guaranteeing that no such threat is ever acted upon). All else aside, it just shifts the responsibility one level up: now you have to worry about a compromise of the people responsible for protecting from internal threats.
But, basically, the only mechanisms in play are some combination of limiting access and, where that's not possible, decreasing employees' ability/incentive to defect.
Ultimately the only way is an omniscient, omnipresent CEO who does all the important stuff alone. Which is probably the core reason why no one has leaked God's files on the Universe, yet.
Perfection is impossible, but that's also no argument for repealing sunshine laws or legalizing outright bribery.
You're letting perfect be the enemy of better.
Here's another thought in the same vein: let's penalize rape victims for attracting male gaze and not fighting sufficiently to avert contact. Sure, some women will get raped still, but let's not let perfect be the enemy of better. That's how they deal with it in some countries actually. They blame the victim. It doesn't reduce rape at all. In fact it reduces reported rape, because women don't want to face the legal and family repercussions of getting raped.
Let me tell you what will happen in the case of ransomware.
1. You get hit by ransomware.
2. Previously you'd ponder contacting authorities. Nope. They're gonna close your options and fine you either way. Keep your mouth shut.
3. Pay as quickly as possible and hope the word never comes out you were blackmailed at all. As far as the world and the government know, your security is fine, nothing happened. No fines, no lawsuits.
4. Result: ransomware proliferates and grows into the biggest organized crime organizations of this century.
How's that about not letting perfect be the enemy of better?
Ah, shit.
Yes, some employees need to be absolutely trusted. No, you don't need to absolutely trust every employee (or even most employees).
Turning to your Snowden example, if you're a TLA and find yourself completely owned by an outside contractor making low six fiures, then you've utterly failed and managing insider risk.
Security is a heuristic based on millions of variables other than a simple price label. You can pay a lot and still get everything leaked.
I think it helps IT departments to go to upper management and put a dollar figure to information security.
Personally, I’d prefer the CEO and the board go to prison for a few years for paying ransom.
Even if you square things with the blackmailer, there's no good way to ensure they don't sell the data to someone else as well.
Most businesses already have some form of insurance covering their liability in these situations and those will just price in whatever fines might need to be paid.
CEO of Swiss Re to said this[1]:
> He observed that the cyber insurance market is currently worth around $5.5 billion in premium, compared to “gigantic” yearly losses that extend into the hundreds of billions of dollars.
“There’s a cyber market that’s very tiny compared to the total exposure,” he told CNBC. “It’s going to grow but only a tiny minority of cyber is actually insured.”
“And I would actually argue that overall the problem is so big it’s not insurable,” Mumenthaler continued. It’s just too big. Because there are events that can happen at the same time everywhere that are much more worrying than what you just saw.”
[1] Pipeline cyber attack not surprising, says Swiss Re https://www.reinsurancene.ws/pipeline-cyber-attack-not-surpr...
Secure your users data and your infrastructure
ftfy:
if [corporation is] a [target] of ransomware
I don't feel sympathy for them the way I would a person.
The rationale for outlawing ransom payments is that it eliminates the incentive for ransomware attacks.
The real question is whether "no-concessions" policies reduce the incidence of ransomware attacks. The answer to that question isn't obvious. However, conditional on no-concessions working in the case of ransomware, "kicking corps while they're down" is not a relevant consideration. The cooperate-cooperate quadrant of the game has higher expected value than the defect quadrants, so you force cooperation by whatever means necessary, even if that means some actors don't get the best possible outcome from their own perspective.
NB: there's some evidence that no-concessions policies don't work particularly well in the case of kidnapping [1]... I'd take care extending this finding to ransomware gangs. If you read the whole PDF, it'll become clear why this behavior is interesting but might not transfer to today's ransomware gangs. That said, when crafting policy on ransomware attacks, it's worth keeping in mind that ransomware attackers may or may not be of the homo economicus species. At the very least as an assumption that you start with but are open to dropping as new evidence prevents itself.
[1] https://www.rand.org/content/dam/rand/pubs/perspectives/PE20...
Government should make companies pay even more so other companies understand what the proper way to "not getting ransomed" is or spend money finding out. Instead of money going god knows where to finance god knows what.
SolarWinds was blaming some intern for a bad password, if it would be up to me, I would close down whole company for such utter bullshit. I understand at their scale it is still possible to have some loose ends but no one was doing any audits, no one was doing any security awareness? I bet you could blame at least 10 managers there for not even thinking about security and not some intern.
Its like the head of Sbersbank and a few companies and a few individuals, and that's it.
There is practically no way for this to be a real rebuttal or conversation. Companies can pay ransoms, intermediaries can pay ransoms. There is no legal quagmire.
Why would you accept a pseudonymous cryptocurrency in a country you can't even get financial records from the fiat offramps, and use a pseudonym that matched your actual name on the OFAC list? Let alone just not being a person that is on the OFAC list. This is so improbable, the US Treasury can pound sand.
https://www.treasury.gov/ofac/downloads/sdnlist.txt
https://localmonero.co/blocks/search/5be5543ff73456ab9f2d207...
> Digital Currency Address - XMR 5be5543ff73456ab9f2d207887e2af87322c651ea1a873c5b25b7ffae456c320;
Kind of embarrassing...
for anyone passing by: it is impossible to tell from blockchain analysis if anybody sent a payment to a particular Monero address, as neither sender, recipient or amount is stored in transaction data or onchain anywhere. Even client side, the data is limited.
Even if the US Treasury seized the recipient's wallet and had it open to look at all transaction history, Monero protocol doesn't tell you what address payments were received from, so the US Treasury would not be able to use their wallet and then compare it to US exchanges or other covered persons to say those people violated sanctions.
On the contrary, I do think Monero wallets show what address you sent to, so if they seized an exchange or a covered person's wallet they could see if they sent to that sanctioned address. But of course, the person on the OFAC list has infinite subaddresses to rotate to.
All the governments around the world have only seized a handful of wallets, so to me it seems like an improbable risk. Most of those seizures were only possible via user-error and non-chalant storage of these kinds of assets.
You have to go to individuals and force them to give a password to derive a private key. Without use of force, many governments don't have a legal power to force people to open things. With hacking even on-premise, there are still extremely high barriers per wallet which makes it basically impossible. With use of force they will still have a challenge with too high of a crowd and will still lack the legal rationale to do so.
And everyone can own this asset without the state knowing of it.
Plus effectively all of Crimean-based Russian citizens and companies, but yeah, that's it.
However, some percentage of these firms definitely are basically part of the ransom racket and essentially act as intermediaries for ransomers. And of course, who knows if my gut feeling of legitimacy in that one particular case was correct or not.
People will get killed because of these actions, if it hasn't already happened.
Of course that works both ways: the countries on the other side of that divide would have to stop doing the same thing, to each other and to countries on the other side of the divide.
It's sort of an 'electronic curtain', the iron curtain of cold. China already erected one half of such a barrier, the GFW definitely reduces the chances of foreign hackers attacking Chinese infrastructure, it doesn't seem to do anything to keep attacks from China out of the rest of the world though.
So regardless of the origin of these hackers, I'm all for a bit more isolation until we've figured out how to deal with this problem, cross border digital crime is going to be (and already is) a real headache.
I'm torn as to this being a pro or con for humanity.
We may put you in jail for paying sanctioned criminals, but we will not tell you explicitly what constitutes a sanctioned crime, who those criminals are, or we can pull it right out of thin air
This way they evade the need to go to the legislature to institute a new class of ban list for them to run.
As an any "pull out of thin air" type privilege, it's a bad thing
A better analogy would be that this is like someone's business getting robbed, and being punished for paying the robber who flew overseas to ship it back to you. But still, this is different, more complex, and more nuanced.
We have an expectation of due diligence from firms. If you're a company that rents storage space and you keep your property unlocked and you lose all your customers stuff it's not just the thieves who are in trouble.
Insurance companies can then develop their own methods to better determine premiums for companies based on measures they take.
Companies can then decide how much risk to take in choosing not to invest in cyber security for their operations based on the cost of their premiums.
If this is an insurance option that currently exists, perhaps more companies will begin paying for it.
[1]: https://www.investopedia.com/terms/business-owners-policy.as...
[2]: https://www.thebalancesmb.com/insuring-against-ransomware-an...
[3]: https://www.robertsonryan.com/2021/05/18/ransomware-insuranc...
The problem is not that companies are paying ransoms. The problem is that companies who operate infrastructures of national importance and who collect sensitive data about us are loosing control of said infrastructures and data. If paying ransoms is part of the discussion, we're already in a very sorry state. Legal action should be focused first-and-foremost on preventing that loss of control.
First we need to decide what is important enough that we should legally require companies to protect it. Certain data or services may require special licenses, depending on scale and importance.
Then we need to decide on how to evaluate whether or not the company has provided sufficient protection and what the punishment should be for failing to provide sufficient protection.
Then we need to establish an government organization of white-hat hackers who are charged with evaluating the protection measures implemented by companies - much like how a health inspector goes around evaluating the conditions of food service companies.
Why is that sanctioned sometimes means allowed and sometimes means disallowed.
You can say, an action was sanctioned, meaning it was approved by someone in power. You can say an action was sanctioned, meaning it was punished, presumably because it wasn't approved. And you can say unsanctioned to mean it wasn't approved, or to say it wasn't punished. What the hell, English?
Maybe they're sanctioning vaccine sharing. Maybe they're sanctioning nuclear weapons testing.
Now if we say 'applying sanctions' it definitely means disapproval.
That said, if these laws can target the victims of ransomware, this sounds self-defeating. Not only will companies continue to get hacked (as nowhere do I see any meaningful help in preventing "cybercrimes" or shoring up cybersecurity), but now there will be incentive to not report that a crime took place at all.
Put another way, if I have been a victim of ransomware and the only way to recover the data is to pay the ransom - should I :
A) report the crime and hope I can recover the data some other way?
B) pay the ransom, and report the crime and then suffer more fines
C) pay the ransom and tell nobody, allowing the crime to go unreported, but forgoing the risk of further punishment from the government
There is probably a way to help companies and maybe a national cybersecurity initiative may be of use here, but blaming/punishing then victim is not the way. Maybe preventing the payments is reasonable, but even then, it seems that prevention of the crime itself is the best medicine (as it is in most cases).
And of course, the government coordinating with good companies a series of best practices and models, and working with MS, even Linux versions to help get the message out and implement good policy.
Like a 'tiered strategy' for home, small biz., mid biz. and 'high touch enterprise'.
Basically some kind of 'board' that exist to help train, coordinate and communicate the things that need to be done.
Not even the most die-hard freedom fighters will side with the dishonest and violent. Cryptocurrency will be the worst thing that ever happened to them.
The history of many nations has proven this to be untrue.
So this effectively makes paying ransomware an activity with very high legal risk.
It will be interesting to see how that all plays out. It's hard to imagine the regulators didn't think of this... I wonder what they are thinking exactly.
> In a pair of advisories, the Treasury’s Office of Foreign Assets Control and its Financial Crimes Enforcement Network warned that facilitators could be prosecuted even if they or the victims did not know that the hackers demanding the ransom were subject to U.S. sanctions.
Indeed, that means it is legally dangerous to pay anyone whose identity you don't know. That is what I'm saying, yes.
They've gambled, "successfully", for a long time. They embrace the risk.
[000] - https://en.wikipedia.org/wiki/Hazard_analysis_and_critical_c...
Not quite a ban, but a disincentive to make a deal, for sure.
Not every business deserves to be in business, either.
We should fight the rent seekers who believe they are entitled to their markets and use regulatory capture to maintain their position
> No business "deserves" to be in business.
The grandparent comment said:
> Not every business deserves to be in business, either.
The conversation moved on the word "business deserves to be in business"
The person I was replying to took a phrase out of context and used it as an opportunity to advance an unrelated political agenda.
The topic of conversation didn’t change.
I explained to you how the conversation migrated.
> Seems like just bullshit.
I'm sorry you think that.
> The person I was replying to took a phrase out of context
It wasn't out of context. That's just how you interpreted it.
> used it as an opportunity to advance an unrelated political agenda.
It's not unrelated. Here, let me enumerate the thread again and provide some context:
> > @zepto: Insure against the losses associated with an unpaid ransom.
You offered a suggestion to businesses to help protect against ransoms.
> > @thisisnico: A lot of times the losses result in the loss of the business entirely.
Someone suggested that the insurance can't cover all of the losses.
> > @piptastic: Not every business deserves to be in business
Someone else suggested that being "in business" isn't a right.
> > @ryan_j_naughton: No business "deserves" to be in business.
Indeed, another person agreed. They then offered an corollary opinion.
> > We should fight the rent seekers who believe they are entitled to their markets and use regulatory capture to maintain their position
Here's where you started throwing a hissy-fit about politics. The conversation has moved on from what you first talked about. There's nothing wrong with offering an opinion, nor about it being political, and it's very much in-context with the movement of the conversation; first from "businesses should insure themselves" to "businesses can lose everything" followed by "businesses don't have a right to exist" and finally an opinion: "we should fight businesses".
Why are you are reading emotion into this?
> Someone else suggested that being "in business" isn't a right.
Yes, in the context of ransomware attacks. I.e. if you can’t protect your data, then perhaps you don’t have the right to be in business.
> > @ryan_j_naughton: No business "deserves" to be in business.
> Indeed, another person agreed. They then offered an corollary opinion.
No. They didn’t agree. They added a decontextualized statement a bit like the one they were following.
> > We should fight the rent seekers who believe they are entitled to their markets and use regulatory capture to maintain their position
And then added a political statement that was a complete non-sequitur to the conversation.
> There's nothing wrong with offering an opinion, nor about it being political.
Why do you feel the need to defend these statements?
I'm reading that you're upset that the conversation has moved on because you're complaining that someone made a comment "out of context" and I disagree.
> if you can’t protect your data, then perhaps you don’t have the right to be in business
I fully agree.
> They didn’t agree. They added a decontextualized statement a bit like the one they were following
I read it as an agreement. I see you don't. You're clearly think it's an out-of-context opinion and I disagree about that.
> And then added a political statement that was a complete non-sequitur to the conversation.
It is, for sure, a political statement. But it's not a non-sequitur. Businesses that are uninsurable are arguably rent-seeking to stay in business.
> Why do you feel the need to defend these statements?
Different people have some very different opinions.
Because I can. Because I'm bored. Because I want to. Because it's not against any rule. Because I think you're wrong. Take your pick. Ultimately, your question here is rather out-of-context, unimportant, and doesn't add anything to the conversation.
Why do you feel the need to attack these statements? Why do you feel it's necessary to claim that an opinion is made out of context and doesn't contribute to the conversation? Why do you continue a long reply chain denying someone who disagrees with you? That's effectively what you've asked me.
> I'm reading that you're upset that the conversation has moved on because you're complaining that someone made a comment "out of context" and I disagree.
That’s you reading something in that isn’t there. There is no complaint.
>> They didn’t agree. They added a decontextualized statement a bit like the one they were following
> I read it as an agreement. I see you don't. You're clearly think it's an out-of-context opinion and I disagree about that.
Ok, but nothing supports this. It’s not a statement of agreement. You are welcome to read that into it if you like though.
> Businesses that are uninsurable are arguably rent-seeking to stay in business.
No. That clearly doesn’t follow.
>> Why do you feel the need to defend these statements? Different people have some very different opinions.
> Because I can. Because I'm bored. Because I want to. Because it's not against any rule. Because I think you're wrong. Take your pick.
> Why do you feel the need to attack these statements?
There is no attack. I think you are imagining that there is one. That is why I asked why you felt the need to defend the statements.
> Why do you feel it's necessary to claim that an opinion is made out of context and doesn't contribute to the conversation? Why do you continue a long reply chain denying someone who disagrees with you? That's effectively what you've asked me.
Because I was curious about why you were defending the statements, a question you haven’t answered.
I have. You're ignoring it. Have a good day, sir.
That’s not an answer. Perhaps you really don’t know your own motivation.
Ignore at your own peril.
I'd rather the feds just make it flat-out illegal, so that there was no way the criminals could hope to successfully extort anybody.
IMHO, reducing it to "stop using windows!" is a crude reduction of the forces behind this.
Maybe handling data at scale is unaffordable for most businesses, who rely on those shortcuts, and wouldn’t be profitable if they had to hire competent infosec staff.