Live data from Hacker News

Governments turn tables on ransomware gang REvil by pushing it offline

reuters.com

31–40 of 94 posts

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#31

Earlier quoted context omitted.

If you make it a felony to pay ransoms (which I strongly support), there will be far fewer ransom demands. Yes, some of it will go underground, but in my view it’s the only way to actually decrease the demand side of the equation.

How will you know if the total amount of ransom payments goes down? How will you know how much is under the table vs over the table? This argument seems to be "the over the table stuff goes down therefore the total goes down" which is faulty logic.

It would follow logically that it'd go down. It's like saying making murder illegal would only push murder under the table.

A company currently performs a simple mathematical equation when deciding to pay a ransom. Does the reputational and financial cost of not paying the ransom outweigh the price of the ransom? In a world where ransom payments were illegal, then those same companies would also have to include the legal penalties and probability of being caught as part of that equation.

Obviously, some companies would still see a net benefit in paying the ransom, but fewer would, so less ransoms would be paid.

It seems to me like you're trying to use 'war on drugs' logic on ransoms. The key difference is that companies don't want to pay ransoms, but do so out of necessity.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#32

Earlier quoted context omitted.

That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.

Also, there are middle-man "security companies" that you can pay to "help you decrypt your files" and what they do is simply pay the ransom under the table for you... So you can't really tell if a company paid the ransom or not.

Yep. It's like governments that forbid use of things like facial recognition software by its police departments. Sure, the police department doesn't use facial recognition, but they commonly work around this by using a vendor that may or may not use facial recognition. This model is actually commonly employed by both companies and that are forbidden to do something.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#33

I hope this is a sign of things to come. Train robberies and privateering were common because the culprits were rarely caught. I feel ransomware has been so successful because it operated in an environment where you never get caught. The solution is always the same, step up the enforcement.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

I would have loved to have seen what would have happened to the East Coast of the US if Colonial wasn't allowed to pay ransomware, or the various beef suppliers in the Americas if they weren't allowed to pay.

Making it illegal to pay just isn't feasible for practical business purposes.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#34

Earlier quoted context omitted.

That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.

Also, there are middle-man "security companies" that you can pay to "help you decrypt your files" and what they do is simply pay the ransom under the table for you... So you can't really tell if a company paid the ransom or not.

You can also make it illegal to seek assistance from an out-of-jurisdiction middle-man. Thus, any middle men are going to be subject to the same regulations.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#35

Earlier quoted context omitted.

If you make it a felony to pay ransoms (which I strongly support), there will be far fewer ransom demands. Yes, some of it will go underground, but in my view it’s the only way to actually decrease the demand side of the equation.

How will you know if the total amount of ransom payments goes down? How will you know how much is under the table vs over the table? This argument seems to be "the over the table stuff goes down therefore the total goes down" which is faulty logic.

Reducing the growth rate of a subset of a total does reduce the growth rate of that total.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#36

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.

No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed.

If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops.

Cracking down on perps would be nice, but is not feasible.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#37
post #26
post #13

Earlier quoted context omitted.

Make insecure software the problem of its producer, so that except for gross negligence by the user, the software vendor is on the hook (reimbursing customers) and will want to prevent ransomware from being a thing in the first place.

Bingo. It's high comedy to me that 90+% of ransomware is targeted at Windows, and yet beyond the year 2020 you can still find corporate-speak in the wild that all basically boils down to a hare-brained assumption that the corporate vendor will in some way be liable if the customer suffers a breach. When in fact the largest of software vendors sits in plain sight, obviously liable for poor designs that invite these br…

What percent of ransomware on windows is driven by software vulnerabilities rather than careless users?

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#38

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

Punish the victim not the perpetrator, nice.

Nobody is even suggesting that the perpetrator shouldn't continue to be punished (when caught).

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#39

Earlier quoted context omitted.

Stepping up enforcement fails all the time. If you want ransomware to stop being effective, make it illegal to pay the ransom.

The main argument against making ransom payments illegal is that it simply drives ransom payments underground. Legislating something, similar to vices like drugs, alcohol or gambling, doesn't make it go away.

Make hiding ransomware attacks a criminal offense mandatory and offer whistleblower programs to companies that try to conceal it. This is an issue of national security. Individual alcohol problems are irrelevant and not comparable to large corporations.

Re: Governments turn tables on ransomware gang REvil by pushing it offline

#40

Earlier quoted context omitted.

That's like saying "make it illegal to get robbed". If I have a robber with a gun to my head asking for my wallet, I would comply. I wouldn't tell them sorry it is illegal to give you my wallet. You should not penalize the victim. Crack down on perps, not victims please.

No those are not similar cases. Yours is urgent, violent, tiny scale, and individual level. The individual doesn't have any agency in this situation. The alternative is get shot and robbed. If a corporation is unable to pay a ransom then the incentive to do the ransomware attack immediately drops. Cracking down on perps would be nice, but is not feasible.

No. I can’t believe this needs to be explained, but the two situations are remarkably alike. If all of a corporations data is being held to ransom, there is no choice in the matter, they must pay. You’re talking like losing all their customers or IP or shutting down the corporation wouldn’t hurt anyone but it would hurt all their employees at the least.

What such an idiotic, short sighted policy would do is to encourage corporations to pay the ransom in secret. This only strengthens the hackers because now law enforcement has no idea who is being hit, when, and with what malware.

Post reply on HN