I kinda disagree with this.

Not disagree as in "He's wrong, this is complete bollocks" but as in "He's right about some things, wrong bout others, missing yet others and the things are much more nuanced and discretion must be applied".

I was asked to elaborate, so here it is.

The whole article is based on the premise "ransomware contains data that's private for you, once you upload it, everyone can get it from VirusTotal". This is wrong and incomplete in several ways.
To begin with, by far not all ransomware is hand-crafted for the victim and even when it is, by far not all of it contains personal information.
Furthermore, the author is confusing the ransomware executable (which is what you normally upload to VirusTotal, so that the scanners there can tell you what it is) with the ransom note. The note contains victim-specific data much more often than the executable.
Next, VirusTotal, while hugely popular, is not the only such service. I very much like id-ransomware for ransomware identification - and you never upload the executable there anyway; only encrypted files (and ransom note, if available; often it's not).
id-ransomware does not make the uploads available to the public.

There are also services like hybrid-analysis where you can specify that a sample should not be shared publicly.
Next, many ransomwares delete the executable once it has finished encrypting, so you don't have an executable to upload anyway.
In fact, by the article's logic, you shouldn't upload *any* malware you come across to any place on the Internet, on the off-chance that it might contain information specific to you - and this is plain ridiculous.
Furthermore, your response to the incident (even if it consists of just consulting nomoreransom for the availability of a decryptor) depends very much on identifying the ransomware that has hit you. How are you going to do this?
Scanners like those that VT uses are pretty much useless, because they rarely bother with exact identification these days and often disagree in their naming. You need something better and more accurate, like id-ransomware.
Finally, don't forget that these days many ransomware gangs leak the information they have stolen before encrypting it, so your info is likely to become public anyway.
And at least if you are in Europe, when you discover a likely data breach, you have 72 hours to notify. If you try to hide that fact instead, you're likely to be slapped with fines far exceeding the ransom demands.
Basically, "never upload ransomware to the internet" is wrong. The correct position is "be aware of the possible pros and cons and exercise proper discretion".

/end

More from For later read

Wow, Morgan McSweeney again, Rachel Riley, SFFN, Center for Countering Digital Hate, Imran Ahmed, JLM, BoD, Angela Eagle, Tracy-Ann Oberman, Lisa Nandy, Steve Reed, Jon Cruddas, Trevor Chinn, Martin Taylor, Lord Ian Austin and Mark Lewis. #LabourLeaks #StarmerOut 24 tweet🧵

Morgan McSweeney, Keir Starmer’s chief of staff, launched the organisation that now runs SFFN.
The CEO Imran Ahmed worked closely with a number of Labour figures involved in the campaign to remove Jeremy as leader.

Rachel Riley is listed as patron.
https://t.co/nGY5QrwBD0


SFFN claims that it has been “a project of the Center For Countering Digital Hate” since 4 May 2020. The relationship between the two organisations, however, appears to date back far longer. And crucially, CCDH is linked to a number of figures on the Labour right. #LabourLeaks

Center for Countering Digital Hate registered at Companies House on 19 Oct 2018, the organisation’s only director was Morgan McSweeney – Labour leader Keir Starmer’s chief of staff. McSweeney was also the campaign manager for Liz Kendall’s leadership bid. #LabourLeaks #StarmerOut

Sir Keir - along with his chief of staff, Morgan McSweeney - held his first meeting with the Jewish Labour Movement (JLM). Deliberately used the “anti-Semitism” crisis as a pretext to vilify and then expel a leading pro-Corbyn activist in Brighton and Hove

You May Also Like