Earlier quoted context omitted.
Apart from leaks harming the privacy of customers, paying ransoms does social harm by providing an income and incentive to criminals. I found leaked details of Royal Mail's negotiations with their attackers fascinating [0]. I'm not sure it's practical to outlaw the payment of ransoms, but it should at least be heavily taxed (say, 100%). Naively, I would expect this to cut by half the amount that can be extorted throu…
It’s been tried. Laws against paying just make people not report to the police at all.
Ring LLC home security company ransomed by ALPHV ransomware
41–50 of 124 posts
Re: Ring LLC home security company ransomed by ALPHV ransomware
#42I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
I am very much with you on this but I think the biggest hurdle in this theory is that introducing such regulation would create a de-facto hostile innovation environment in that jurisdiction. And no regulator will lightheartedly put themselves into the position of being the guy that “drove away all the innovators/startups/research/business”
Re: Ring LLC home security company ransomed by ALPHV ransomware
#43I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
> I've said it before and I'll say it again Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.
Absofuckinglutely. Never talk to a politician without remembering that if they don't get a cut...
Re: Ring LLC home security company ransomed by ALPHV ransomware
#44Earlier quoted context omitted.
Definitely some tradeoffs there. I recall going back and forth in my head "I'm paranoid, I don't need to enable this" to "what if there was a breach..". and well.. here we are.
E2E encryption only protects the data while it is in transmission. If there is a breach, all of your data is accessible because it is decrypted at the endpoint.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#45Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.
So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#46Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.
>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.
Also, I find your "but you have to think about the children^WJobs" argument pretty hollow. Nothing can be changed, because some gay lesbian from a foreign country might loose their already precarious job. Come on, is this really an argument for something?
Re: Ring LLC home security company ransomed by ALPHV ransomware
#47Earlier quoted context omitted.
It’s been tried. Laws against paying just make people not report to the police at all.
well, i guess laws against murder, makes murder no report them self...
One of these is more universally repulsive than the other. Were it illegal, I'm not sure I could be bothered to blow a whistle on a company paying a cyberransom. That's obviously different for murder.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#48Earlier quoted context omitted.
> I've said it before and I'll say it again Don't tell us, tell your legislators. Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. If the security industry got together and lobbied for this as both a jobs program (security companies offering services to tech companies) and as a means of protecting Americans/constituents, then it might get somewhere.
>Ideally with some kind of narrative that ties to a financial incentive for the lawmaker and his or her constituents. Absofuckinglutely. Never talk to a politician without remembering that if they don't get a cut...
Most voters don't care about digital security. That means most politicians, reasonably, don't care either. Most voters do care about their economies. So linking what you're talking about to talking points the political can use is helpful. Not because they're going to get a cut.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#49I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…
This is zealous. If consumers don't care, and nobody can show tangible damages, "massive fines" and "criminal charges" are closer to moral outrage than prudent lawmaking.
Re: Ring LLC home security company ransomed by ALPHV ransomware
#50Leaking user data isn't really penalized enough. First two incidents, high monetary penalty, third incident, company is closed permanently in the interest of public security.
>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.
The same argument is made for why breadwinners shouldn't get jail time when they commit a felony.