Live data from Hacker News

Governments turn tables on ransomware gang REvil by pushing it offline

reuters.com

21–30 of 94 posts

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#21

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.

If you make it a felony to pay ransoms (which I strongly support), there will be far fewer ransom demands. Yes, some of it will go underground, but in my view it’s the only way to actually decrease the demand side of the equation.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#22

Earlier quoted context omitted.

The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.

I assume they mean make it illegal for corporations to pay the ransom. It's obviously unjust and ineffective to punish private individuals for paying ransoms, but that's not where the money is. OTOH, corporations have budgets and can be prosecuted if X millions dollars disappears out of it.

I don’t view it as obviously unjust as applied to individuals. That may suck for that person, but turning off the revenue demands substantially reduces the odds others are subject to ransoms. If all you do is focus on the individual case, you never actually address the root cause.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#23

Any real, as in flesh and blood, person(s) arrested? Otherwise this is only a small delay.

Exactly. Until people are arrested, the government just basically shutdown a REvil billboard. They'll just pop up with a new one.

No one has actually stopped REvil hacking operations. There's been a lot of drama with their affiliate programs that are probably not government related. This Reuters article is giving the government a tiny little more credit than it deserves.

Here is an article with some more information: https://www.zdnet.com/article/revil-ransomware-operators-cla...

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#24

Any real, as in flesh and blood, person(s) arrested? Otherwise this is only a small delay.

Yes. Watch a stream from arrest: https://therecord.media/two-members-of-a-ransomware-gang-wer...

They had the opportunity to search within unlocked computer and devices. Found money.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#25

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.

Also, there are middle-man "security companies" that you can pay to "help you decrypt your files" and what they do is simply pay the ransom under the table for you... So you can't really tell if a company paid the ransom or not.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#26
post #13

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.

Bingo.

It's high comedy to me that 90+% of ransomware is targeted at Windows, and yet beyond the year 2020 you can still find corporate-speak in the wild that all basically boils down to a hare-brained assumption that the corporate vendor will in some way be liable if the customer suffers a breach.

When in fact the largest of software vendors sits in plain sight, obviously liable for poor designs that invite these breaches, and no one has held them to account for it.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#27

Earlier quoted context omitted.

The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.

If you make it a felony to pay ransoms (which I strongly support), there will be far fewer ransom demands. Yes, some of it will go underground, but in my view it’s the only way to actually decrease the demand side of the equation.

How will you know if the total amount of ransom payments goes down? How will you know how much is under the table vs over the table? This argument seems to be "the over the table stuff goes down therefore the total goes down" which is faulty logic.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#28
post #13

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.

Even the most secure piece of software - assuming such a thing even exists! - can't do a thing against incompetent users.

Even a perfectly patched Windows instance can't be reasonably protected against an user executing an attachment of an email that then goes ahead and encrypts all files writable by the user. The only option is to ban the user from anything executable and interpreters as Apple does on their iDevices, but we all rightfully and regularly complain about that one.

As for vulnerable software: I agree, some pressure on Microsoft to open-source or at least provably audit their software would be nice - but it's rare to have a definitive attribution on how a piece of malware entered your organization, at least not in places where record-keeping and retention is restricted by laws like the GDPR.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#29

I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.

When a lot of culprits are state actors, stepping up enforcement is a naive and useless endeavour

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#30

Earlier quoted context omitted.

I don't agree with this. It's about incentives. If you make it too painful to conduct this type of crime, perpetrators will give up.

The prospective of spending 30 years in jail is a disincentive.

This is only a disincentive to people who normally don't commit crimes. If you're part of a crime ring, this ins't something you are concerned with on a daily basis.
Post reply on HN