Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was shocked when I heard a ransomware expert at a security conference tell everybody to just pay the ransom. Shocked.


But it's the right answer for an individual org in that situation.

Of course the correct answer for everyone, in the long term, is to have backups and not pay.


In my opinion, even then the cost of not paying may still be far, far higher than paying. A reply to the parent: https://news.ycombinator.com/item?id=27102599


If your options are 1) company is ruined and has to shut down temporarily or permanently, with much higher total costs than the ransom payment, or 2) pay the ransom, of course you're going to pick option 2.

Backups aren't necessarily enough. Sure, a lot of companies don't backup. And sure, a lot of companies backup but keep the backups on network shares that the ransomware can reach and encrypt. And sure, a lot of companies keep isolated backups which aren't encrypted, but which are missing the past few days of production data.

But even if you have a perfect backup solution up to the minute before the attack occurred, you'll still be coerced to pay. These ransomware operators are general extortionists - they manually target specific companies and come up with the most impactful threats to pressure you to pay.

They screenshot all of the sensitive documents, emails, IMs, trade secrets, and PII they've gathered and say they'll post it online and mail it to every local, regional, and national press outlet, every company you partner with, and every customer email they've harvested. (And they do indeed make good on this threat if you don't pay by a deadline.) They call all your executives every hour of every day and target their personal devices. They might SWAT your executives' houses.

If you don't have backups, the overall, reputational, and financial cost is probably way higher than the ransom payment. But even if you do, it still might be higher than the ransom payment. Even if you really want to take the moral high ground and inform your customers, partners, and the media of your choice and that you won't negotiate with terrorists or whatever, all of the damage (especially to your reputation and trust) may still be so extreme that you have to shutter your company.

I don't think you can fault someone for paying the ransom when they're being explicitly targeted by sophisticated attackers and when so much is at stake.


I totally understand the logic, but from a standpoint of "paying just encourages more of it" it shocked me to hear it from a security researcher.

If people like him are telling you to pay, then people are going to pay, which will just create more and more and more attacks.


I'm not an expert, but I do work in information security and I personally would tell people to pay, too. I strongly believe there needs to be a way to reduce the frequency of and counter these attacks, but I don't think banning ransom payment is the way.


Maybe he/she has an alter ego who does ‘research’ into ransomware in the middle of the night </conspiracy>


What else do you do? If you don’t have a backup and need the stuff, you’re out of options.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: