Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

81–90 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#81
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies).

If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their demands to get paid, then the profitability goes down.

Use the money collected to fund IT security programs (research, awareness and assistance to companies in need of improving security.

Re: The push to ban ransom payments is gaining momentum

#82
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…

Very often the cost of recovery would be much higher than 4 times the ransom.

Just look at the British Library as discussed in the article, not paying the 500K ransom cost them more than 6M so far. And was much more damaging to the public (I know because I tried to register after the ransomware and they simply don't have online registration anymore). They are STILL basically offline more than 6 months after:

> We're continuing to experience a major technology outage as a result of a cyber-attack. Our buildings are open as usual, however, the outage is still affecting our website, online systems and services, as well as some onsite services. This is a temporary website, with limited content outlining the services that are currently available, as well as what's on at the Library.

You could change that percentage to any amount and it wouldn't change a thing, it will still be cheaper to pay in most cases, and ransomware attackers will just lower the price if it's not. Change the British Library to any privately owned company, and no matter the price it will ALWAYS be better to pay than to be literally out of business for more than half a year (dead at that point).

Re: The push to ban ransom payments is gaining momentum

#83
post #71

We are a small but distributed organisation targeted by ransomware attack some weeks ago having poor luck that an employee noticed that something strange is underway just now in our system and pulled the plug without hesitation or waiting for instructions. Backups saved the day except a few days work of items easy to reproduce - memory is still fresh. We only had I guess less than 30 lost man days of work on efforts…

good on your employee who pulled the plug first and asked questions later-- that's the sign of an organization where people aren't afraid to do the right thing. very scary situation.

It's always easy to say good on the employee who acted and stopped the problem

The question is what happens with an employee who acted when there wasn't a problem?

Re: The push to ban ransom payments is gaining momentum

#85
post #57
post #54

I'm ignorant but I've never understood why people actually pay the ransom. Aren't the attackers anonymous? What stops them from asking for another $Y after they get their $X, and not actually removing the ransomware? There's not much incentive for the attackers to actually do what they say after you pay them, right?

As crazy as it sounds, having a reputation to honor the unlocking of data is a great way to get other victims to pay. However, I'd be more suspicious of promises of data deletion.

This is exactly it. And it's a much broader principle than just ransoms. Any organization/group that live outside of an established legal system depends on being seen as honorable if they want to have any relationships with other organizations/groups.

This applies to criminal groups (and individuals), clans in places like Afghanistan or Somalia and even to whole countries when dealing with each other.

Essentially, such groups are playing repeated games of Prisoner's Dilemma. They need to be seen as playing a tit-for-tat strategy. If they are known for playing always-defect (or always-cooperate), other "players" will (if rational) play always-defect against them.

This means they need to be honorable in that they keep their promises. But if someone disrespects them, they also must be predictable vengeful.

Re: The push to ban ransom payments is gaining momentum

#86

Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.

Yep. Make it a crime to pay ransoms. No data is worth enabling and enriching criminals. Have tested backups stored offsite. If you fail at that, then you fail at business and deserve to go out of business.

For Ransomware, Backups need to be offline, not necessarily offsite. I.e. there needs to be no possibility of the hackers corrupting or deleting the backups too.

If your data is in the cloud, it's probably good to have an offline backup onsite - sometimes cloud providers delete your account: https://news.ycombinator.com/item?id=40304666

Re: The push to ban ransom payments is gaining momentum

#87

Earlier quoted context omitted.

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…

Very often the cost of recovery would be much higher than 4 times the ransom. Just look at the British Library as discussed in the article, not paying the 500K ransom cost them more than 6M so far. And was much more damaging to the public (I know because I tried to register after the ransomware and they simply don't have online registration anymore). They are STILL basically offline more than 6 months after: > We're…

> You could change that percentage to any amount and it wouldn't change a thing,

So what you're saying is that the criminals could quadruple their demands, and everyone would still pay?

I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more.

If we assume the criminals do not generally do much research on each company's ability to pay, but just have a more or less even price for everyone, I think it's rather safe to assume that they've tuned the ransoms to a level that more or less optimizes the total payment they receive.

If it's made 4x more expensive to pay, fewer organizations would pay. And those who still pay will provide a lot of funding for efforts to battle this kind of crime.

> and ransomware attackers will just lower the price if it's not

This is at least half the purpose of adding the tax. If the price is lowered significantly, the economic loss for the non-criminal part of society is reduced.

Also, lower revenues means that it will get harder for ransomware groups to "attract talent", meaning there will be fewer threats out there.

Making payments illegal, on the other hand, just pushes the payments under ground. It's going to be about as successful as when they tried to ban alcohol.

Re: The push to ban ransom payments is gaining momentum

#88
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

The idea would be to reduce the likelihood of a payout.

And just to spell it out: Fewer payout means fewer resources to spend on further operations. So I would absolutely think that the criminals care if there is an actual ban.

Re: The push to ban ransom payments is gaining momentum

#89
post #51

Banning ransoms worked, mostly, for terrorism. That has to be backed up by a sizable intelligence effort to find and fix the attackers, and a military effort to take them out.

That worked because the terrorism in question was Islamist - neither Russia, China nor Iran have any desire in having such groups grow powerful enough to be a threat to their interests, so it was in their interest to cooperate enough with the Western nations to quash the threat.

I think kidnapping for ransom is not a only a terrorism activity. Yes there are many cases of that but the majority will be related more with organized crime which usually enrich in weak and unstable government. There is correlation between terrorists activity and unstable countries but that is not always cause and effect relation. I.e you will find high statistics of kidnapping for ransom in Latin amaerica and even Mexico due to organized crime networks.

There are variety of ways kidnapping for ransom works (including cyper attacks here but also something like human trafficking activities...etc [1])

So there are many actions taken to address those. They are not just confined into the islamists category.

[1] https://www.nationalcrimeagency.gov.uk/what-we-do/crime-thre...

Post reply on HN