Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

71–80 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#72
post #47
post #25

Earlier quoted context omitted.

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

> yes, my Monero nails

At $3bn “market cap,” Monero is not a serious problem.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#73
post #50

Earlier quoted context omitted.

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.

And then you mix in DeFi. Or into and out of L2/HTLCs. Or via atomic swaps, which went live but are buggy, and won’t show the monero interaction. Or cross-chain. And on and on. Let’s ban it all?

Yes, that's where I think financial regulators are heading. And anyone who thinks for one second of course sees that these are also problems with cash that drug cartels deal with by sending bales of $100 bills around. And so we added kyc and discourage cash.

I don't think you can ban people doing crypto entirely, but you can make the financial exchange points where cash goes in and out ever more difficult.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#74
post #37

Earlier quoted context omitted.

As long as you have a non-signatory among otherwise first world nations (and there's always a handful on any treaty) there absolutely will be a legal way that you can't do much about.

> there absolutely will be a legal way that you can't do much about No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers. To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.

It took what, over two decades to convince Switzerland and Austria to get on board for (part of) money laundering treaties? And ransom(ware) is not anywhere as pressing.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#75
post #50

Earlier quoted context omitted.

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.

And then you mix in DeFi. Or into and out of L2/HTLCs. Or via atomic swaps, which went live but are buggy, and won’t show the monero interaction. Or cross-chain. And on and on. Let’s ban it all?

> Let’s ban it all?

It’s in the process of being grey listed. Similar to running an all-cash lifestyle, it’s possible. But you’ll have your money frozen and seized and stolen from time to time. And you will hit intentional roadblocks any time you attempt a major financial move.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#76
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.

No reason such an insurance company couldn't be run in the early/mid 20th century manner, entirely with paper records. Send carbon copies of all documents to two remote locations to eliminate the threat of a fire wiping out the records.

This is easy. It requires you to hire a lot of human clerks, but since the customers are large businesses that means there aren't a whole lot of customers in the first place. And if you can't get enough typewriters, there's no reason the clerk work couldn't be done on computers connected to printers, with all document storage still being done on paper. If the computers get pwned, throw them out and buy new ones; it doesn't matter because the documents weren't being stored on those computers.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#77
post #49
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

You should have pointed out that her view is self-serving. if you are a hostage negotiator (retired even or whatever), it's natural to argue that we will still negotiate with terrorists. Just like programmers argue about whether we'll still have a job even as ai gets better and better ;-)

She's now an elementary school teacher so really doubt she has anything to sell.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#78
post #74

Earlier quoted context omitted.

> there absolutely will be a legal way that you can't do much about No, that’s what the sanctions threat is for. It may be possible. But now you’re in the company of money launderers and terrorism financiers. To be clear, I don’t think this is necessary. But it’s naïve to imagine it’s beyond D.C.’s capacity.

It took what, over two decades to convince Switzerland and Austria to get on board for (part of) money laundering treaties? And ransom(ware) is not anywhere as pressing.

> took what, over two decades to convince Switzerland and Austria to get on board for (part of) money laundering treaties

Yet they still complied with U.S. sanctions. (Or were arrested abroad for defying them.)

You seem to misunderstand that sanctions are not a treaty obligation. If your country deals with a sanctioned entity, it gets sanctioned as well. That enforces compliance indirectly. America and and does unilaterally extend sanctions.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#79
post #40
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

Yeah what's the point of extorting a company that can't pay. You're just risking getting stuffed in the trunk of a car and driven to some place with an extradition treaty.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#80

Earlier quoted context omitted.

Nigeria (my country) is pretty bad, but we don't do ransomware, lol.

I responded to a comment on hostage and ransom negotiation business. Hostages aren't normally considered ransomware, although said negotiators would have excellent overlapping skill set. Travel.gov has an advisory for hostage taking in your country. I can assure you there are well spoken negotiators in your nation to deal with that.

I'm afraid, you are wrong, criminal gangs or masterminds are not that organized in Nigeria
Post reply on HN