Fujifilm becomes the latest victim of a network-crippling ransomware attack
techcrunch.com
techcrunch.com
Unauthorized Access to Fujifilm Servers - https://news.ycombinator.com/item?id=27384084 - June 2021 (26 comments)
Ransomware – Unauthorized access to Fujifilm servers - https://news.ycombinator.com/item?id=27375401 - June 2021 (46 comments)
Fujifilm shuts down network after suspected ransomware attack - https://news.ycombinator.com/item?id=27373455 - June 2021 (52 comments)
With more and more folks wanting to work from home, this further complicates the extant balancing act of how to securely give systems access to remote employees.
The fundamental problem is that you put blame on the victim and force them to "try harder". Trying harder in this case, against literally anyone in the world discovering one flaw in their system (and systems are never flawless).
A more successful approach would be eliminating the ability for anyone in the world to extort money anonymously from companies. Because without the motivation, the blackmailers have no reason to blackmail you.
In other words: attempting to ban cryptocurrencies?
While I agree in principal, that is quite a lofty goal. What are some of the ways you would suggest eliminating that ability?
Ransom requires a response to incentivize further crime. You don't get paid, it's not an option.
Unless you don't need the funds, and it's used to terrorize desirable targets. Then you have a much better case.
So the question is, which are we facing?
For the record, I think this would be a bad idea, but it’s exactly the sort of governmental overreaction I’ve come to expect. I’ve sold off most of my cryptocurrency as a result of this latest spate of ransomware attacks, waiting for this shoe to drop.
But let's assume that this law would be effective. Would it do a net good to the world? Maybe, if ransomware attacks stop. But in the meantime, we'd probably see some innocent people's data being released, and the downstream societal effects from the destruction that occurs.
If a company that holds my private information is hit by a ransomware attack that threatens to release my data, I'd rather they pay it.