Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

111–120 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#111

Earlier quoted context omitted.

I don't think that's quite fair. Each organization, especially ones that possess sensitive customer data, have a custodial duty to secure that data. Most of these attacks are very preventable by following well documented best practices and industry recommendations. I think that "I wish my health provider paid the ransom" and "Health organizations should be responsible for protecting my data" are completely compatible…

If nobody paid the ransom, ransomware attacks would be reduced to nearly zero. Paying the ransom means that other people will get ransomware attacks. So, effectively speaking, wishing someone paid the ransom means that you're also wishing that other will get hit with attacks because that's a direct consequence of paying.

I follow your logic, I just think your conclusion is vastly oversimplified. Not paying the ransom also means that other people will get ransomware attacks. There is not direct causality here.

There is some game theory, sure (a prisoner's dilemma, really). If nobody ever paid ransoms, there would be very little incentive for ransomware (though still not zero, some people just want to create chaos).

But I don't think in a world-sized game with billions of actors that you can ascribe causality to the actions of a single actor. Wishing that you had driven to work instead of taking public transit (perhaps you missed an important meeting as a result) is not equivalent to wishing for public transit to be defunded (there is an equivalent feedback loop - decreasing ridership corresponds to reduced funding for public transit programs).

Then consider that ransomware is only possible because of cybersecurity failings, and investing money into reasonable (some might even call them "common sense") security measures would also reduce these incidence rates to nearly zero.

To be clear, I'm not advocating for paying ransomware ransoms, generally. I think this coalition is a good thing. But if a healthcare provider loses years of customer health data, that could lead to measurably worse health outcomes, and even excess mortality, for real people. An institution getting financially punished for not investing adequately in security seems like a better outcome than jeopardizing the health of real patients in the name of 'solidarity'. Meanwhile, a dozen other institutions pay the ransom and business continues as usual.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#112
post #9

First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

[dead]

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#113
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

One, this article is not about banning crypto ransom. Two, if you wanted to do that, you’d criminalise it with the threat of sanctions. At that point your K&R retiree and anyone who signed off on paying them would be fugitives in almost anywhere in the world.

The only case in which ransomware seems actually similar to hostage taking is when a hospital or something is hit. And I think that is actually a morally complicated situation, because lives are actually at risk.

Otherwise ransomware payments are just a collective action problem, paying them builds this harmful ransomware industry, but might be cheaper than losing or restoring your data. Making it costlier to pay the ransomware groups is a great strategy, in the sense that even if it isn’t perfect it might bump some cases from “pay” to “don’t pay,” damaging the industry.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#114

Earlier quoted context omitted.

I responded to a comment on hostage and ransom negotiation business. Hostages aren't normally considered ransomware, although said negotiators would have excellent overlapping skill set. Travel.gov has an advisory for hostage taking in your country. I can assure you there are well spoken negotiators in your nation to deal with that.

I'm afraid, you are wrong, criminal gangs or masterminds are not that organized in Nigeria

Cool here's a documentary with an English speaking hostage negotiator in Nigeria with family in the other side of the business (talks start around 4:30).

I'm afraid, YOU are wrong. My opinion wasn't idle thought but derived from research on Nigeria rather than some weird borderline racist baseless rhetoric that Nigerians don't have this level of organization.

https://youtube.com/watch?v=nG09Bo3uvAw

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#115
post #50
post #47

Earlier quoted context omitted.

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.

> You just ban Monero then.

You just ban encryption, then!

You just ban liquor/drugs, then!

Monero making law enforcement investigation more difficult due to privacy algorithms does not make it legal to ban.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#117
post #47

Earlier quoted context omitted.

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

> yes, my Monero nails At $3bn “market cap,” Monero is not a serious problem.

Its max supply is uncapped.

The tech and established network are unlikely to go back in the box.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#118

The HN title matches the article headline, but the article headline is horribly inaccurate. This is not about making ransom payments illegal, as many commenters have assumed. They are setting up an international information-sharing system to help track cryptocurrency wallets that are receiving ransom payments.

(The submitted headline was "US-led coalition of nations agrees to end ransomware payments to hackers". We since changed the URL - more at https://news.ycombinator.com/item?id=38088780.)

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#119
post #49
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

You should have pointed out that her view is self-serving. if you are a hostage negotiator (retired even or whatever), it's natural to argue that we will still negotiate with terrorists. Just like programmers argue about whether we'll still have a job even as ai gets better and better ;-)

Everybody makes exceptions. There's nothing self-serving in pointing out the obvious.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#120
post #11
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

I'm fairly sure the 14th century hammer works just fine in hammering the 21st century nail.

There have also been centuries of advancement on the idea of a hammer. The US and friendly countries have just a hammer, in the same way that a forge with a power hammer has just a hammer, or a wrecking ball could be seen as a complicated sledgehammer.
Post reply on HN