5 ms·
I feel this is actually a decent service for a few reasons: - Many average users don't want to understand cryptocurrencies, how to safely and securely buy and
by shittyadmin 7y ago
I feel this is actually a decent service for a few reasons:
- Many average users don't want to understand cryptocurrencies, how to safely and securely buy and use it is a challenge in and of itself.
- They're on the hook and the client pays nothing if the ransomer fails to provide a working key.
- They'll also manage the ransom decryption software - if there's problems with it there are 3rd party tools that can often do a better job of decryption than the original decryption tool, again, this is something that's going to be complicated for average users to deal with.
- For some ransomware there are decryption processes available without the need to pay the ransom, figuring out which of these applies can be challenging
- Certain institutions may be unable or unwilling to work with the attacker directly - introducing a middle man to broker can help solve this.
Overall the piece seems somewhat hyperbolic.
- el_benhameen 7y agoAnd all of that would be a fine service if they were honest about it.
- acct1771 7y agoPlausible deniability for a CTO that doesn't want to be known for negotiating with terrorists As A Service?
- infogulch 7y agoTNaaS: Terrorist Negotiation as a Service. It's the biggest new craze since blockchain.
- TeMPOraL 7y agoThere already exists ransom insurance (the real-life kind of ransom), and private ransom negotiators, so TNaaS isn't such a stretch at this point.
- taneq 7y agoProfessional negotiator is a well respected role and they're used all the time by police etc. This seems like a fairly direct analogue, so...? (Full disclosure since someone else was asking for it: I have nothing to do with any of this stuff.)
- Retr0spectrum 7y agoOther than the fact that they are directly facilitating crime...
- stOneskull 7y agoIt would be a crime to put hospital patients in danger
- jplayer01 7y agoYeah, seems like a great service to a certain degree. But it's not the service they're selling and they're lying to their customers. Their service incentivizes ransomware authors, so this absolutely needs transparency. I assume most people go to them because they want the problem solved but they feel they shouldn't be paying the hostage takers. "we don't negotiate with terrorists" comes to mind. So if this service is doing exactly this and making the situation worse for everybody else, this is something that needs to be consciously weighed off and decided by the people considering their services.
- londons_explore 7y agoI wonder how many of these "white hat middlemen" are also the ransomware owners... Obviously the two companies collaborating would give benefits to eachother, and it might just be a convenient way to seperate the illegal from the legal...
- elliekelly 7y agoThis was my first thought as well. What’s the biggest risk when you’re paying the ransom? That the thief will run off with the bitcoin without providing the key. The easiest way to mitigate that risk is to either collaborate with the thieves or become the thieves.
- TheOperator 7y agoBet they run the Antivirus companies too! It's all a racket!
- Scoundreller 7y agoIt can be better to know, but ignore the truth, to avoid unsavoury corporate discussions like: “Are we paying a bribe? I’ll have to create a new line item in SAP for that” asks Alice from accounting, and “I need them to sign this form saying they haven’t tortured anyone in the past 5 years”, Bob from procurement auditing. Or “Please have one of their senior directors sign this form declaring that none of their funds employees are based in any of these embargoed countries. I’ve attached the list.” Charlie from legal
- dearrifling 7y agoAnd surely there is nothing wrong with the alignment of ransomware authors' and this friendly service's incentives.
- UweSchmidt 7y agoWow, is the world drowning in cynicism? I want a service that breaks the ransomware encryption and researches into that direction to ultimately make the incredibly hurtful extortion of vulnerable computer users not viable. To me these companies are criminals if they facilitate the extortion.
- teekert 7y agoExactly at this point the "decrypter" companies are just partners of the cyber-criminals, they have the same incentives, share the same profits and both are unethical.
- lozenge 7y agoNot quite the same incentive - one needs to stay anonymous as they are breaking the law, and the other is legal and can operate in plain sight.
- teekert 7y agoIt's legal to lie about paying the extortioners?
- Scoundreller 7y agoAt worst, it’s breach of contract. At best, it makes the accounting and legal checks on your supplier very easy. $10k to Bob’s IT consultancy within the same state is a lot easier than $10k that ultimately leads to a country that may be embargoed.
- usrusr 7y ago> easier than $10k that ultimately leads to a country that may be embargoed In which case the middleman/coconspirator would add one more, completely unrelated crime to their list.
- peteradio 7y ago
- Haga 7y agoFull disclosure?
- smsm42 7y agoIt would be decent if it openly advertised as middleman broker service for paying the ransom to the criminals. False advertising is always a bad sign - if you need to hide what you're doing from your client, you know the client wouldn't like it, and are setting up to deceive them.
- Sir_Substance 7y agoI'd throw two more hats into that ring: - It looks bad to the public if companies directly pay the ransomware creator. Decryption companies can act as a PR "buffer" in that respect. - By funneling the western worlds contact with ransomware creators through a small number of companies, we create an incentive for ransomware creators to follow through with providing the decryption keys and not play games with the price. If they fail to hold up their end of the bargain, their reputation will immediately be ruined within the small number of companies that do this.