Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

41–50 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#41

Earlier quoted context omitted.

Does that extend to makers of buggy software, rather than those who often have little choice in what they use.

It’s not always buggy software; ransomware affiliates have been known to bribe company insiders to install malicious software on the network. The insider gets some cut of the eventual ransom. Works great on disgruntled employees or entry-level people. Fundamentally the financial incentive needs to be stopped in order to curb ransomware activities.

The financial incentive to continue business operations will always be larger. Unless that’s the financial incentive you’re referring to.

Re: The push to ban ransom payments is gaining momentum

#42
For my MSc in Cyber Risk strategy & governance my final dissertation was built on the parallelism of Italy's ban on payment of ransoms for kindnappings and the current ransomware trend. It's difficult to take solid conclusions, the measure could be effective in disrupting some financially motivated attackers but, given the current landscape, I guess the threat actors could shift more towards extorting end users where the ban will be more difficult to enforce. Ransomware rely heavly on financial incentives, for a company it comes down to cost but the same holds as well for threat actors, they try to go after the bigest whales they can get away with. Insurances may be loopholes, in Italy at the time they were banned as well.

Re: The push to ban ransom payments is gaining momentum

#43
post #3

Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…

> How could it realistically be enforced?

By the tax authorities, who are already looking at every payment a business ever makes anyway!

> This is unenforceable.

Only for amounts that come from petty cash, at which point you have effectively reduced the major financial motivation for such crimes anyway.

Re: The push to ban ransom payments is gaining momentum

#44

It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly), and not notifying law enforcement, software vendors, security researchers, or the customers. And then without any disclosure or collaboration, every company is on its own island, no collective learning, making it trivial for attackers to re-use th…

> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly)

It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash.

And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for the clear majority of victims.

Re: The push to ban ransom payments is gaining momentum

#45
post #36

[flagged]

Are the world police implementing this ban? And are they starting a world war to enforce it? Or how does this ban go into effect in your view?

Well we start with say you, you trade some of your bitcoin holdings, the feds seize your winnings, fine you and toss you in prison.

Re: The push to ban ransom payments is gaining momentum

#46

Earlier quoted context omitted.

It seems reasonable to suggest that the number of profit-driven ransomware endeavors and the number of for-fun ransomware endeavors can both be non-zero and contain some overlap and some non-overlap. Therefore it seems that to make it unprofitable would at least eliminate the former reason which under all by the worst case scenario where those numbers are perfectly equal and overlapping would result in fewer ransomwa…

Not only might X (= banning payments) not eliminate ransomware, it could make the problem worse! Those ransomware perpetrators who are motivated by profit could multiply their activities, if the yield is reduced: have more heists going on.

I don't see how banning payments would inherently create more opportunity for ransomware attacks. Assuming that the operators are already attacking as much as they can (why wouldn't they be - its more profit that way since its business after all) the only way to maintain profitability with lower per-attack yields would be to ask for more ransom per-attack which would likely drive the yields down even further.

Reminds me of https://youtu.be/9pOiOhxujsE?si=GG6X16c8efr0I3Ey&t=213

Re: The push to ban ransom payments is gaining momentum

#47
post #3

Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…

In the corporate sphere, this is way easier to investigate than most other forms of corporate crime.

Investigating price fixing or discrimination is hard, because it happens over a protracted period, and you have to show a pattern, and everything is open to interpretation, etc. But this? There are two distinctive events that are basically impossible to hide: The disruption and the payment.

Attacks on individuals are another matter, yes that's hard to enforce. But then, on the average, I don't think individuals actually benefit from paying this kind of ransom. It just tags you as a mark for further abuse. So maybe most people will accept that paying ransoms is just not something you do.

Re: The push to ban ransom payments is gaining momentum

#48
post #24

Earlier quoted context omitted.

There is likely an element of sociopathy involved as it requires a particular lack of empathy towards secondary victims. But the same can be said for most career criminals, and most crimes do indeed stop when you remove the profit motivation. Your own conjecture that ransomware authors are somehow a special breed is the one that needs backing.

> special breed Vandals are real.

Sure, that’s how viruses used to work. They would just delete / corrupt your data. It was a small-time operation, some pissed off mid with an axe to grind. Now it’s either a nation-state with a political agenda or organised criminals doing it for the money.

Re: The push to ban ransom payments is gaining momentum

#49
post #29

Earlier quoted context omitted.

Bing Bing Bing!!! We have a winner! Legalized them, the FBI has to pay them for you, you have to give them 3x the cost of the payment. 1x to payment. 1x to finding people who committed the crime 1x to pay off everyone impacted. Increasing the cost of not being secure is the only way the problem will be addressed.

How far do we take that? Adding layers and layers of security isn’t free, and it’s often at the expense of productivity, and if taken far enough, the profitability and viability of a business. What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?

Most ransomware don't need that much layers of security to be stopped. And even without them, backups go a long way to mitigate the damages.

Re: The push to ban ransom payments is gaining momentum

#50
post #29

Earlier quoted context omitted.

Bing Bing Bing!!! We have a winner! Legalized them, the FBI has to pay them for you, you have to give them 3x the cost of the payment. 1x to payment. 1x to finding people who committed the crime 1x to pay off everyone impacted. Increasing the cost of not being secure is the only way the problem will be addressed.

How far do we take that? Adding layers and layers of security isn’t free, and it’s often at the expense of productivity, and if taken far enough, the profitability and viability of a business. What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?

Just balance it with the risk of ransomware.
Post reply on HN