Live data from Hacker News

Should we ban ransom payments?

techcrunch.com

11–20 of 27 posts

Re: Should we ban ransom payments?

#11
post #10
post #7

Earlier quoted context omitted.

Nothing like blaming the victim. What's next arresting people for handing over their wallet at gunpoint?

Seems like a matter of game theory strategy vs. tactics. If everyone were to fight back against muggers, it seems like there would be fewer muggings. But tactically, it might be best for an individual to hand over the wallet.

Sure. And it would be nuts to start trying to incentivize fighting back by prosecuting people who don't.

Re: Should we ban ransom payments?

#12
post #8
post #7

Earlier quoted context omitted.

Nothing like blaming the victim. What's next arresting people for handing over their wallet at gunpoint?

The victim fails to be just a victim when they actively contribute funds to a criminal enterprise. The gunpoint analogy is a poor one; being coerced by physical violence is one thing, being coerced because you lost your files (and don’t have backups) is another. It’s a horse of a different color.

What if people die and lose everything or groups of people get hurt because of the Ransomware? You could also say the person handing a wallet to a criminal is actively contributing and should of kept his money in the bank. The point is that its not always as simple as "backup your files".

Re: Should we ban ransom payments?

#13
post #9

How in the world would we enforce this?

How do we enforce every other law? If the authorities get wind of someone paying a ransom, they could investigate and then decide to prosecute if they discover that it was highly likely that a ransom payment was made. For the specifics of ransomware payments, for public companies, which line items does that amount get attributed to on the quarterly reports?

And even if you expect that some payments will continue to happen under the table, the payouts would have to be much lower, as there is a limit to how much a business can hide on their balance sheets.

That means less potential profit for ransomware makers, less incentive to make ransomware, and less money to fund ransomware development.

Re: Should we ban ransom payments?

#14
post #7

Earlier quoted context omitted.

I am not a lawyer and entirely just guessing. I am probably wrong but if people are paying money to organized crime then perhaps it could be interpreted as aiding and abetting organized criminals using corporate funds and thus maybe possibly the government could use the existing Racketeer Influenced and Corrupt Organizations Act (RICO) of 1970. Or maybe not. Maybe a question for lawyers that have litigated RICO cases…

Nothing like blaming the victim. What's next arresting people for handing over their wallet at gunpoint?

[deleted]

Re: Should we ban ransom payments?

#15

LLike they would care about their victims facing legal consequences. If they don't pay, nuts to them. If they pay, I get money.

Yes, obviously they don't care about the legal consequences for the victim. The goal is to make them think they won't ever get paid due to the threat of legal consequences on victim, and therefore they wouldn't bother doing ransom in the first place (which is pretty unrealistic imo).

Re: Should we ban ransom payments?

#17
post #15

LLike they would care about their victims facing legal consequences. If they don't pay, nuts to them. If they pay, I get money.

Yes, obviously they don't care about the legal consequences for the victim. The goal is to make them think they won't ever get paid due to the threat of legal consequences on victim, and therefore they wouldn't bother doing ransom in the first place (which is pretty unrealistic imo).

Why is this unrealistic?

The victims won't pay because they don't want to go to jail. If no one pays—or even if people pay much smaller amounts that are possible to hide—there isn't an incentive to launch ransomware.

Re: Should we ban ransom payments?

#18
This would never work. The assumption is that the bad guys would stop doing ransoms because they think they won't ever get paid since the victim would face legal consequences if they paid. The problem is the assumption that finding a victim for a ransom request is a more expensive task than the potential payoff in the in the long-run. As long as the ransoms are still a net win for the bad guys in the end, it won't stop.

Re: Should we ban ransom payments?

#19
post #15

Earlier quoted context omitted.

Yes, obviously they don't care about the legal consequences for the victim. The goal is to make them think they won't ever get paid due to the threat of legal consequences on victim, and therefore they wouldn't bother doing ransom in the first place (which is pretty unrealistic imo).

Why is this unrealistic? The victims won't pay because they don't want to go to jail. If no one pays—or even if people pay much smaller amounts that are possible to hide—there isn't an incentive to launch ransomware.

It is unrealistic because as long as just enough victims pay to make it worthwhile, the bad guys will keep doing it.

My assumption is that the cost to find victims and make the request is low enough and that number folks that will still pay regardless of the law is high enough to make it it worthwhile for the bad guys.

Best case, it lowers the profit margin for the bad guys. Meanwhile, the victims face being punished even worse.

Re: Should we ban ransom payments?

#20

LLike they would care about their victims facing legal consequences. If they don't pay, nuts to them. If they pay, I get money.

Businesses won't pay if their executives think it may cause them to go to jail.

It just comes down to the cost-benefit for the bad guys. As long as it is profitable it won't stop.

Yes, many big businesses may stop paying since the executives don't want to go to jail. Realistically if they are that big they can probably come up with a legal argument to justify the payment though within the mess of exceptions that would have to exist if this became a thing.

In the end the bad guys are just going to adjust to target smaller companies that would be under the radar for being caught paying.

In the end it doesn't really matter what the dynamics of it end up being. If it pays off to ransom, it will still happen, and I think there will always be a way to make it pay off for quite a while.

The only real solution is better security that makes it unprofitable to even attempt to breach a company that makes a random possible.

Threatening legal consequences for the victim is a very sideways way to go about achieving the goal of deterring the bad guys.

Post reply on HN