Live data from Hacker News

Should we ban ransom payments?

techcrunch.com

21–27 of 27 posts

Re: Should we ban ransom payments?

#21
post #18

This would never work. The assumption is that the bad guys would stop doing ransoms because they think they won't ever get paid since the victim would face legal consequences if they paid. The problem is the assumption that finding a victim for a ransom request is a more expensive task than the potential payoff in the in the long-run. As long as the ransoms are still a net win for the bad guys in the end, it won't st…

The assumption is that victims will be less likely to payout, increasing the cost of attacks for criminals since they'll need to expend resources on an attack with a lower chance of payout.

Ransoms are not a net win when victims don't payout.

Re: Should we ban ransom payments?

#22
I feel the argument this article lays out fails to account for the fact that the data most likely has value for the attacker outside of the organization being ransomed. Banning ransomware payments will only force the attacker to utilize other revenue generating avenues instead. Maybe it’s selling PII to other people directly, maybe its selling trade secrets to a competitor or the highest bidder or maybe its just outright using the stolen data for personal gain (think stolen CC numbers) or maybe they just resort to straight up blackmail of each individual person. It maybe easy to get a quick lump sum payment from an organization, but I don’t think its much harder for them to target the individuals of the data they collected.

Re: Should we ban ransom payments?

#23
post #18

This would never work. The assumption is that the bad guys would stop doing ransoms because they think they won't ever get paid since the victim would face legal consequences if they paid. The problem is the assumption that finding a victim for a ransom request is a more expensive task than the potential payoff in the in the long-run. As long as the ransoms are still a net win for the bad guys in the end, it won't st…

The assumption is that victims will be less likely to payout, increasing the cost of attacks for criminals since they'll need to expend resources on an attack with a lower chance of payout. Ransoms are not a net win when victims don't payout.

Yes, it is all based on assumptions of the dynamics of the cost/benefit calculations of the ransoming-business which I am not familiar with.

I did not see anything in the article that took that into account. I fear the lawmakers may not familiar with those dynamics either.

My personal assumption is that the cost is very low for the bad guys.

This may make a dent in their profit margin. But is that really worth it for the position we'd be putting victims in?

If my assumption is correct, it just going to shift the ransoms to those victims more willing pay without being caught and I'm not sure that is the a desired outcome (or maybe it is). The big companies may be targeted less if they don't pay, but is that really solving the problem?

Re: Should we ban ransom payments?

#27
post #7

Earlier quoted context omitted.

I am not a lawyer and entirely just guessing. I am probably wrong but if people are paying money to organized crime then perhaps it could be interpreted as aiding and abetting organized criminals using corporate funds and thus maybe possibly the government could use the existing Racketeer Influenced and Corrupt Organizations Act (RICO) of 1970. Or maybe not. Maybe a question for lawyers that have litigated RICO cases…

Nothing like blaming the victim. What's next arresting people for handing over their wallet at gunpoint?

Nothing like blaming the victim.

The companies getting their customers data encrypted are NOT victims. At best they are incompetent and should never have been in business to begin with and most certainly should never have been anywhere near any of their customers data.

Companies have a fiduciary responsibility to protect their customers and investors. If a company is letting phishers trounce all over my data then in a way I am glad that my data became encrypted so that the company can no longer hide the fact they were negligent not only to keep the thugs out but also neglected to properly back up my data. I am more concerned about all the companies that were popped and were able to hide it because they only lost my data to the phishers. Ransomware is exposing the incompetent businesses and embarrassing their leadership as it should. Securing data in an ever growing and large company can be challenging due to internal politics especially if being security focused from day one was not their priority. Backing up data is easy.

Post reply on HN