Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
reuters.com
reuters.com
I strongly suspect this too will end up mostly a jurisdiction/accounting nuance rather than a substantial change.
Travel.gov has an advisory for hostage taking in your country. I can assure you there are well spoken negotiators in your nation to deal with that.
I'm afraid, YOU are wrong. My opinion wasn't idle thought but derived from research on Nigeria rather than some weird borderline racist baseless rhetoric that Nigerians don't have this level of organization.
>Didn’t vice catch a bunch of flack for over sensationalizing their “reporting?”
Awesome ad hominem against the people recording actual Nigerians testimony.
>Regardless I’d be more inclined to believe an actual Nigerian than a YouTube video
And I provide video with actual Nigerians yet it's crickets from you when some guy just flippantly says I'm wrong with no supporting facts. Unless by actual Nigerians you want one to jump through the screen and talk to us... we're going to have to settle for electronic communication. It's what worth noting the Nigerian commenter above denied ransomware related activities but never denied the rest.
>That person didn’t say there were zero people doing this, they said it wasn’t likely Nigeria had a widespread and systemic issue with organized crime doing this.
They said what they said, not what you've retranslated them to say. I never said the issue was systemic, but if they really said that then their flippant dismissal was just as invalid as they'd be addressing a strawman.
No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers.
To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.
You are vastly overestimating the federal government’s coherence and coördination. Yes, we use black hats. Yes, we still jail and sanction them.
The first thing you do after conquering the throne is to bundle up all your pending atrocities in one and eliminate competition. The second thing you do is slaughter the mercenaries you had hired to win your war of ascension.
No reason to leave them around and let the next usurper hire them to dethrone you.
Also, there have been some enforcement actions on intermediaries for facilitating such payments - e.g. https://home.treasury.gov/news/press-releases/jy0471
Yet they still complied with U.S. sanctions. (Or were arrested abroad for defying them.)
You seem to misunderstand that sanctions are not a treaty obligation. If your country deals with a sanctioned entity, it gets sanctioned as well. That enforces compliance indirectly. America and and does unilaterally extend sanctions.
We don’t sanction money launderers generally. And no, terrorism finance isn’t a solved problem either. Hence why I said one would need to keep company with that category of people were such a measure enacted. But again, your K&R retiree cum schoolteacher was describing a political constraint. Not a functional one.
Otherwise ransomware payments are just a collective action problem, paying them builds this harmful ransomware industry, but might be cheaper than losing or restoring your data. Making it costlier to pay the ransomware groups is a great strategy, in the sense that even if it isn’t perfect it might bump some cases from “pay” to “don’t pay,” damaging the industry.
I've heard this as well. A professor was flying into a less than stable area or Afghanistan and for some reason they were descending just like a normal commercial flight.
"What are you doing, we're going to get shot down!". He was used to a steep descent or a spiral to the runway to minimize the risk of getting hit.
They then explained they had a deal with the local warlord. The military provided barrels of used oil from all their ground vehicles, and in exchange they don't fire on the airplanes as they takeoff or land. The warlord burns the oil for heating, and the military doesn't need to deal with (hopefully correctly) disposing of large quantities of used oil.
Background: the student vent to visit his family back in Iraq as his town was under an ISIS attack, which is how he ended up getting stuck there.
0. https://www.nbcnews.com/news/world/how-swedish-professor-hel...
There were no “Zero Dark Thirty” style extractions.
It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you.
It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate.
Despair is above reason. Laws are useless to stop desperate actions.
The only way to actually have a "hostages will die" policy is to ensure you destroy whoever took them, despite the deaths of hostages.
Upwards. Second order effects of schemes like prohibition are much worse than the original problems.
It's also not quite analogous to the ransomware prohibition, because it's more akin to a prisoner's dilemma, and there's no inherent desire to pay ransomware criminals in the human psyche like there is to alter consciousness.
There are loads of countries that have illegalized alcohol and not devolved into levels of organized crime that the US did. Specifically, nearly every Muslim nation on earth. I feel this one example is way overplayed by advocates of legalization
For drugs, there’s some inherent desire for some people to consume them. Maybe they harm society a bit (in the sense that they might destroy the people that take them), but the main cost for the rest of us is that they fund criminal enterprises because they are illegal. People want drugs, if they could buy them at CVS I suspect they would.
Ransomware is already illegal, we don’t create a new criminal enterprise by making it illegal to do business with them, we just make it harder.
Also, lots go the biggest ransomware gets have been big institutional entities where everything is documented. People just buy drugs in small amounts and consume them, two parties, neither of whom wants to get caught, minimal paper trail. Basically impossible to ban.
For physical hostages—people are desperate to get their friends and family back, and so they’ll go to desperate measures to pay. For ransomware, it is usually an economic decision, nobody’s life is at risk (other than when, like, a hospital is hit). Increasing the cost increases the chance the decision will go the other way. And increases the incentives to keep IT defenses up to date. (I know you didn’t bring up the hostage analogy, I think it is worth noting that the desperation you point to here is really an artifact of the tangent we’re on from the analogy leading us astray).
Or even worse, like shareholder or regulator action, see SolarWinds
https://news.ycombinator.com/item?id=38076636
Note that in the EU under GDRP companies are still liable for privacy violations and related fines if ransomware attackers gain access to your personal details, random or no random (a hack is enough).
It's sounds nice in the abstract; in practice it's political suicide.
Depends on how you spin it. I suspect it would be quite easy to spin the narrative on this one. "So you knowingly funded a terrorist group that's likely going to use the money to commit further crimes against US citizens?" or something of the sort. Have some experts testify on that too, preferably ones in officers uniform.
Becoming as inhuman as your opponent is not the answer.
The gov will pat themselves on the back telling everyone how they've caused a drop in the number of incidents.
You're offering to increase the stick, what's the carrot for the people/corporation losing everything ?
Making the punishment bigger also means victims have stronger incentives to work closely with the terrorists so the whole thing never gets public or never gets labelled as a ransom.
https://www.youtube.com/watch?v=gm4hb5yNxyE
The policy has been widely misreported as "we don't negotiate with terrorists", which is wrong. The actual policy is we won't make concessions to terrorists.
>The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said.
pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st century nail.
C'mon, anything to make the cyberpunk future less lame than it's turned out to be.
That said, cyber-privateering is actually a good idea. Cyberwarfare is in the same space as naval warfare was in the 17th century: it's not really an overt act of war, it's mostly committed by criminal organizations with the occasional big news state actor action, and there's a lot of money to be made.
Precisely! These would be! This is the kind of innovation the blockchain enables! /s
Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since a public ledger allows you to transitively taint every transaction downstream, significantly reducing the value of certain tokens and removing the ability of people to say they didn’t know the funds they are receiving were connected to a crime.
Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address.
I don't think you can ban people doing crypto entirely, but you can make the financial exchange points where cash goes in and out ever more difficult.
It’s in the process of being grey listed. Similar to running an all-cash lifestyle, it’s possible. But you’ll have your money frozen and seized and stolen from time to time. And you will hit intentional roadblocks any time you attempt a major financial move.
You just ban encryption, then!
You just ban liquor/drugs, then!
Monero making law enforcement investigation more difficult due to privacy algorithms does not make it legal to ban.
You cannot ask ransoms in a currency the victim cannot access.
At $3bn “market cap,” Monero is not a serious problem.
The tech and established network are unlikely to go back in the box.
Sure. If it gets bigger, it can be addressed then. As it stands, it isn’t a problem.
https://www.britishmuseum.org/collection/object/H_1982-0103-... https://www.britishmuseum.org/collection/object/H_1956-0403-...
Now, back on topic. Monero's claims have been lightly tested but never against a nation-state level adversary, so I'd be hesitant putting anything onto a blockchain which would be problematic if a flaw is discovered since there is, of course, no way to remove it. That said, let's assume that everything works exactly as planned and they've perfectly nailed the implementation. Do you ever wonder why cryptocurrency people call what they're building cash? That's because while a 14th century treasury officer wouldn't known a thing about hash functions, they were already very familiar with the problems caused by a truly anonymous means of exchanging value: actual cash.
If you've ever read old novels where people had to show explain their source of wealth, maintain accounts at specific banks with good reputations, visiting traders were required to store funds at state sanctioned banks, etc. that's because while it's impossible to tell where someone's coins came from you can make crime, especially tax evasion, considerably harder by requiring people to show positive proof of income and adding points where other people would have to collaborate with you. That certainly doesn't prevent fraud but it can reduce it considerably by increasing the cost and likelihood of being caught.
Obviously we have a big shift in the technology, but that same basic approach works well now: you don't need to control every blockchain transaction if the gateways into the real financial system are required to follow money laundering laws like everyone else. That's one of the reasons why almost no businesses used Tornado Cash, Monero, etc. because they didn't have a need to and when your accountants ask “how will we avoid the drug cartels using us to launder money?” and you say “we can't, that's a feature!”, they're going to start asking questions like who's going to go to prison.
If you use a mixer, that expands to cover all of your transactions. Any legitimate business has to worry about complying with local laws and they’re going to stop using options which don’t allow that or cost too much.
Watch out, people still using last year's favourite buzzword, we'll sic this year's favourite on you.
Global security meaning: Perhaps, if the rich found that the cost of supporting poor hospitals was high, they'd determine that they would prefer to invest in cybersecurity in poor hospitals. (Not likely, considering how few wealthy organizations care about cybersecurity in their own organizations.)
If they had to pay the ransom there would be a price set on security complacency, and that becomes the yardstick to use on further investments to harden their systems.
In contrast, losing all patient data is now associated with a malicious attack, so they can hide behind the victim status, the actual damage isn't directly on their bottom line but on the quality of the care to their patient, and they can keep underinvesting in security as long as they have plausible deniability of wrongdoing in the next attack.
In practice, this is the same as wishing that other people get hit with ransomware attacks.
I think that "I wish my health provider paid the ransom" and "Health organizations should be responsible for protecting my data" are completely compatible views to hold.
There is some game theory, sure (a prisoner's dilemma, really). If nobody ever paid ransoms, there would be very little incentive for ransomware (though still not zero, some people just want to create chaos).
But I don't think in a world-sized game with billions of actors that you can ascribe causality to the actions of a single actor. Wishing that you had driven to work instead of taking public transit (perhaps you missed an important meeting as a result) is not equivalent to wishing for public transit to be defunded (there is an equivalent feedback loop - decreasing ridership corresponds to reduced funding for public transit programs).
Then consider that ransomware is only possible because of cybersecurity failings, and investing money into reasonable (some might even call them "common sense") security measures would also reduce these incidence rates to nearly zero.
To be clear, I'm not advocating for paying ransomware ransoms, generally. I think this coalition is a good thing. But if a healthcare provider loses years of customer health data, that could lead to measurably worse health outcomes, and even excess mortality, for real people. An institution getting financially punished for not investing adequately in security seems like a better outcome than jeopardizing the health of real patients in the name of 'solidarity'. Meanwhile, a dozen other institutions pay the ransom and business continues as usual.
To be clear, I'm not saying that anyone is obligated to "take one for the team", or that anyone is bad for not being willing to. I'm just saying that if everyone was willing to, far less harm would be done in the longer term.
To me, a ransomware attack is little different than if someone just physically blew up the computers (or, with medical records, the hospital). It's a huge, costly disaster, but the damage is done. If we as a society thought of it like that and perhaps provided support (financial and otherwise) for people who get harmed like we do with any other large disaster, we could be in a better place for everyone except the criminals. Maybe we'd even put systems into place for the greater redundancy of medical records, to mitigate against actual health consequences of such attacks.
We'd also have greater interest in providing support for implementation, education & investigation in terms of hardening against such attacks.
If your records have been encrypted and taken, you have already taken a reputational hit to sensitive information. If you can recover your operations then you shouldn't even think about paying the ransom. However, if your systems have been encrypted AND you can't recover them AND not having your systems is catastrophic to your business continuing then you may consider paying the ransom. Hopefully with a renewed understanding of how important it is to have appropriate information security controls in place.
The only way not paying ransoms will happen, is if it is made illegal or there are significant penalties as a result of doing so. Otherwise, for some businesses not paying the ransom when their systems are offline is too risky.
https://www.whitehouse.gov/briefing-room/statements-releases...
Nice to see smaller countries taking the initiative and also being trusted for projects like this.
Maybe it's also time that companies take cybersecurity more seriously, and maybe not just companies, but governments too.
If insurance companies would cover ransomware damage, you can be certain those insurance companies would IMMEDIATELY lobby the government to enforce cyber security standards, audits, pentesting etc.
It's not happening as long as the NSA is on top of the race of cyberweapons, but once that changes, you can be certain that software is going to be more secure.
From what I've heard, insurance companies are actually kinda souring on the business because it's incredibly bad from an actuarial perspective: many of those targeted are SMBs (i.e. they're not paying the kind of premiums that would make it worthwhile), but even for large corps as time passes the odds of a ransom event approach 1. I mean, can anyone think of a large non-tech enterprise that doesn't have that doesn't have that one load-bearing Windows Server 2008 machine in a closet?
So to an extent, this seemingly represents the industry collectively declaring that even massive monthly insurance premiums are insufficient for companies to get their security posture together, and so they're trying to cut it off at the source by making ransomware as an endeavor unprofitable.
Hah, that is literally how an old employer of mine got hacked and ransomwared big time.
This is not about making ransom payments illegal, as many commenters have assumed. They are setting up an international information-sharing system to help track cryptocurrency wallets that are receiving ransom payments.
Most of the action on this is on the receiving end of the payment process -- making it difficult for criminals to cash out, freezing their assets, or finding them.
The US hasn't sanctioned any of these addresses yet. They could, and if they did, the OFAC would be how they'd do it... if they decide to.
The only thing they announced that they're going to do so far is share information about them.
Many types of attack don't actually know where they're breaking into at the time they break in. And once you're in, you might as well try running a ransom attack.
Those who do ransoming and racketeering are participating in a subset of trade more specifically called "illicit trade".
If your records have been encrypted and taken, you have already taken a reputational hit to sensitive information. If you can recover your operations then you shouldn't even think about paying the ransom.
However, if your systems have been encrypted AND you can't recover them in a reasonable way AND not having your systems is catastrophic to your business continuing then this is where companies consider paying. Hopefully with a renewed understanding of how important it is to have appropriate information security controls in place.
The only way not paying ransoms will happen, is if it is made illegal or there are significant penalties as a result of doing so. Otherwise, for some businesses not paying the ransom when their systems are offline is just too risky.
Our backups were the data, not code or systems (which were IaC and rebuilt as needed).
When I do remediation I usually recommend restoring only business state but installing and configuring all OSes and applications from scratch with latest freshly downloaded versions. You can't trust any executable or dll that has been laying around.
That is not the restore dream that the backup provider sold them but reinfection is common. Once the bad guy has a privileged credential it is trivial for them to investigate for other vulns to use in the reinfection phase and nobody has just one critical vuln. If a business is susceptible to ntlm relay it's also going to have unsigned smb and non encrypted ldap traffic for the same root cause -- it was the default in 2005 and never got modernized.
Oh well turns out it is not like that
This is easy. It requires you to hire a lot of human clerks, but since the customers are large businesses that means there aren't a whole lot of customers in the first place. And if you can't get enough typewriters, there's no reason the clerk work couldn't be done on computers connected to printers, with all document storage still being done on paper. If the computers get pwned, throw them out and buy new ones; it doesn't matter because the documents weren't being stored on those computers.
They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head).
Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, and several people suggested paying the ransom but we ultimate decided not to and it ended up costing more than the ransom if you factor in payroll and lost revenue.
I still think out of principle you shouldn't pay the ransom, ever. Assume whatever the ransom would cost is already gone, if you can rebuild for less than that (you probably can't) it's a win.
There may have been a time when a company would act on principle, but I think it's very rare today. You hardly even expect people to do that. It's the world we have made.
Obviously none of these make it impossible, but the goal needs to be to tip the value proposition the other way.
I don't think they realize how easy it is to generate new wallet. Nobody is going to use their home wallet address to demand ransom
If companies could get back on line within 24 hours, they wouldn't pay the ransomware.
That's a scam, right?
"I have encrypted your files. Send (amount) and I'll decrypt them for you."
Not a scam?
Encryption viruses are probably some of the best QA'ed code in the world.
https://www.whitehouse.gov/briefing-room/statements-releases...
1) There's no way to enforce this to private companies in the US without passing some sort of Federal law. I'm pretty certain no states have passed anything like this either.
2) So, we can assume the alliance is government agencies not paying ransomware. For the US, it's only the Federal government agreeing to this. If the County Court of Middle of Nowhere Nebraska gets ransomwared. The Feds can put all the pressure they want on them not to pay, but at the end of the day, they can't stop them from paying.
So far only the central bank of Sambia had a backup and could just ignore the ransom.