Earlier quoted context omitted.
Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.
The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.
Governments turn tables on ransomware gang REvil by pushing it offline
21–30 of 94 posts
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#22Earlier quoted context omitted.
The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.
I assume they mean make it illegal for corporations to pay the ransom. It's obviously unjust and ineffective to punish private individuals for paying ransoms, but that's not where the money is. OTOH, corporations have budgets and can be prosecuted if X millions dollars disappears out of it.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#23Any real, as in flesh and blood, person(s) arrested? Otherwise this is only a small delay.
No one has actually stopped REvil hacking operations. There's been a lot of drama with their affiliate programs that are probably not government related. This Reuters article is giving the government a tiny little more credit than it deserves.
Here is an article with some more information: https://www.zdnet.com/article/revil-ransomware-operators-cla...
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#24Any real, as in flesh and blood, person(s) arrested? Otherwise this is only a small delay.
They had the opportunity to search within unlocked computer and devices. Found money.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#25Earlier quoted context omitted.
Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.
That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#26Earlier quoted context omitted.
Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.
Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.
It's high comedy to me that 90+% of ransomware is targeted at Windows, and yet beyond the year 2020 you can still find corporate-speak in the wild that all basically boils down to a hare-brained assumption that the corporate vendor will in some way be liable if the customer suffers a breach.
When in fact the largest of software vendors sits in plain sight, obviously liable for poor designs that invite these breaches, and no one has held them to account for it.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#27Earlier quoted context omitted.
The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.
If you make it a felony to pay ransoms (which I strongly support), there will be far fewer ransom demands. Yes, some of it will go underground, but in my view it’s the only way to actually decrease the demand side of the equation.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#28Earlier quoted context omitted.
Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.
Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.
Even a perfectly patched Windows instance can't be reasonably protected against an user executing an attachment of an email that then goes ahead and encrypts all files writable by the user. The only option is to ban the user from anything executable and interpreters as Apple does on their iDevices, but we all rightfully and regularly complain about that one.
As for vulnerable software: I agree, some pressure on Microsoft to open-source or at least provably audit their software would be nice - but it's rare to have a definitive attribution on how a piece of malware entered your organization, at least not in places where record-keeping and retention is restricted by laws like the GDPR.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#29I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.
Re: Governments turn tables on ransomware gang REvil by pushing it offline
#30Earlier quoted context omitted.
I don't agree with this. It's about incentives. If you make it too painful to conduct this type of crime, perpetrators will give up.
The prospective of spending 30 years in jail is a disincentive.