TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

FBI’s Advice on Ransomware? Just Pay the Ransom

72 pointsby rubikscubeover 9 years ago

13 comments

pdkl95over 9 years ago
<p><pre><code> And that is called paying the Dane-geld; But we&#x27;ve proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane. </code></pre> <a href="http:&#x2F;&#x2F;www.poetryloverspage.com&#x2F;poets&#x2F;kipling&#x2F;dane_geld.html" rel="nofollow">http:&#x2F;&#x2F;www.poetryloverspage.com&#x2F;poets&#x2F;kipling&#x2F;dane_geld.html</a><p>Paying ransom merely teaches the criminal that you&#x27;re an easy mark that they should demand more ransom from in the future.
评论 #10483052 未加载
评论 #10483034 未加载
评论 #10482633 未加载
评论 #10482587 未加载
评论 #10488716 未加载
评论 #10482985 未加载
评论 #10483005 未加载
devitover 9 years ago
Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups.<p>One also wonders what&#x27;s the point of all NSA&#x27;s &quot;SIGINT&quot; efforts if they can&#x27;t or won&#x27;t use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.
评论 #10482498 未加载
评论 #10482451 未加载
评论 #10482682 未加载
评论 #10482971 未加载
评论 #10483745 未加载
评论 #10482458 未加载
评论 #10482465 未加载
评论 #10482525 未加载
jvdhover 9 years ago
Note that this is not an official statement, this is something that an agent at a conference:<p><a href="https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2015&#x2F;10&#x2F;28&#x2F;did-the-fbi-really-say-pay-up-for-ransomware-heres-what-to-do&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2015&#x2F;10&#x2F;28&#x2F;did-the-fbi-real...</a> has the official statement:<p><pre><code> The FBI doesn&#x27;t make recommendations to companies; instead, the Bureau explains what the options are for businesses that are affected and how it&#x27;s up to individual companies to decide for themselves the best way to proceed. That is, either revert to back up systems, contact a security professional, or pay.</code></pre>
joostersover 9 years ago
It&#x27;s probably good advice for any individual person &#x2F; company who gets infected. Unfortunately, it&#x27;s terrible advice for society in general, because the blackmailers profit from their crime and will go on to target more people.<p>I&#x27;d guess that the malware users are being quite clever in keeping the ransom demands (relatively) small, to make it easy to choose to pay. They then profit in scale because targetting thousands of people is simple.<p>Since the ransom payments are in Bit-coin, it&#x27;s possible to track the payments and work out how much money the scammers are making. Some estimates put it as high as $325 million: <a href="http:&#x2F;&#x2F;www.coindesk.com&#x2F;cryptowall-325-million-bitcoin-ransom&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.coindesk.com&#x2F;cryptowall-325-million-bitcoin-ranso...</a>
评论 #10482598 未加载
blisterpeanutsover 9 years ago
The FBI should always advise companies <i>never</i> to pay ransoms. It&#x27;s the only way to stop it. The Bureau doesn&#x27;t care if a company or individual loses data. They do care about crime, and the only logical way to stop a class of crime is to remove all financial incentive.<p>Whoever is advising people to &quot;just pay the ransom&quot; is a fool.
评论 #10482793 未加载
评论 #10482794 未加载
speakeronover 9 years ago
Surely more sensible advice would have been: make sure you have offline backups; but if you don&#x27;t, pay the ransom.
评论 #10482580 未加载
dogma1138over 9 years ago
The sad part is that quite a few of the ransomware cases aren&#x27;t actually recoverable, as the malware could be just dumb AES implementation which doesn&#x27;t send the key to some C&amp;C server some where, in some cases the key is hardcoded into the malware or is just generated at random so even if you pay the ransom you might not get your data back.<p>The other important thing to consider is that you data is already tainted so the cost of the ransom are meaningless compared to the cost of re-evaluating all the data once you manage to decrypt it, as well as the cost of the decryption it self it&#x27;s not like you&#x27;ll get an easy tool do it.<p>But considering that recovering data from backups also costs a small fortune it might be a reasonable gamble after all.
marzeover 9 years ago
Um, isn&#x27;t the reason we have an FBI is to shut down operations such as these? Can&#x27;t they track payments and have the ransomware operators apprehended, with cooperation from authorities in other countries?<p>Maybe we should defund the FBI if this is the best advice they can think of.
spdustinover 9 years ago
For the record, it&#x27;s the FBI&#x27;s advice on cryptowall, cryptolocker and their ilk that it&#x27;s easier to pay the ransom because it&#x27;s largely automated to the point that no human is directly involved in processing your ransom and returning the keys to your files - the web site you&#x27;re directed to even gives you one single file recovered for free. Isn&#x27;t technology grand? Aren&#x27;t the disenfranchised youth of Eastern Europe (the primary agents responsible for crypto-ransomware) generous? So unless you had backups from before you were infected, pay the automated system its Bitcoin. It&#x27;s a shame that so many people have <i>this</i> as their introduction to cryptocurrency.
xxdesmusover 9 years ago
This is 100% BS.<p>The FBI has already confirmed this &quot;just pay the ransom&quot; was completely misquoted and taken out of context.<p>Stop spreading this clickbait FUD.
tim333over 9 years ago
I guess the ransomware will stop unless they throw a few of the crooks in to jail. I presume the NSA or someone like that could probably figure who they are but they are probably in Russia or similar where the courts won&#x27;t do much. Hence a fix might be to do a deal with Putin or some such? - We&#x27;ll drop some sanctions if you throw a couple of dozen cybercrooks in jail say.
评论 #10483078 未加载
Bjorkbatover 9 years ago
So much for not negotiating with terrorists.
xdinomodeover 9 years ago
Has anyone heard of the ransomware that encrypts your whole hard drive and makes you pay to unencrypt it? LOL.