Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

51–60 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#51
post #40

Earlier quoted context omitted.

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

They are not useless, they bend the curve. Micro harms are everywhere.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#52

It's about dang time. Years ago I attended a security conference where an FBI guy was actually advising people to pay the ransom. I was shocked.

I wish my health provider had paid the ransom. They screwed up and got hacked and wouldn’t or couldn’t pay the ransom, now the entire clinic has no health records for their patients. My doctor can’t see any health info older than a few years. I couldn’t believe what she was telling me.

It hurts, but it’s the only way we can get the wealthy to take security seriously. Otherwise, to take an exaggerated example, only rich hospitals will be able to pay ransoms and poor people /hospitals will have no records (globally).

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#53
post #34
post #24

Earlier quoted context omitted.

Hey, but I can sell you a 21st century e-hammer with AuthentiCode licensing. Swing power savings of up to 2% can be achieved. (Requires constant internet connection).

Sell?! Where’s your recurring? It’s a subscription model (paid yearly up front), with mandatory upgrades and a brutal depreciation policy

[deleted]

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#54
post #46

Earlier quoted context omitted.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

We're not talking about desperate drug addicts here. The threat of criminal prosecution and being sent to federal prison is a pretty effective deterrent for most people. Especially the corporate officers who would ultimately have to authorize any ransomware payment. They won't take that risk to help their employer.

You just said "hostages will die" in your first comment. Saving human life is a pretty desperate.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#55
post #37

Earlier quoted context omitted.

As long as you have a non-signatory among otherwise first world nations (and there's always a handful on any treaty) there absolutely will be a legal way that you can't do much about.

> there absolutely will be a legal way that you can't do much about No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers. To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.

DC doesn't go after these "security consulting firms located in non-signatory states" just precisely because they want to be able to use them if the need arises.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#56
post #54
post #46

Earlier quoted context omitted.

We're not talking about desperate drug addicts here. The threat of criminal prosecution and being sent to federal prison is a pretty effective deterrent for most people. Especially the corporate officers who would ultimately have to authorize any ransomware payment. They won't take that risk to help their employer.

You just said "hostages will die" in your first comment. Saving human life is a pretty desperate.

And in those cases, there will likely be a relative willing to do the illegal step to save their relative.

The only way to actually have a "hostages will die" policy is to ensure you destroy whoever took them, despite the deaths of hostages.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#59

Sorry for my cynicism but it seems that any cryptocurrency that is able to solve the traceability problem has now one more business opportunity.

Except that if this gains any teeth, it's likely to receive the Tornado Cash treatment: ban its use and (possibly illegally) jail its developers.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#60
post #50
post #47

Earlier quoted context omitted.

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.

And then you mix in DeFi. Or into and out of L2/HTLCs. Or via atomic swaps, which went live but are buggy, and won’t show the monero interaction. Or cross-chain. And on and on. Let’s ban it all?
Post reply on HN