Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

101–110 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#101

Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.

> I think hackers should get $0 from the victim, possibly get caught by police The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go fo…

how come there is no USA and Israel in your list?

Re: The push to ban ransom payments is gaining momentum

#103
Does anybody wonder if these attacks aren't performing a public good in the long run by hardening our tech infrastructure in the West? It seems like hostilities with Russia, China, et al are likely to just get worse over time, and the long term high threat environment that these gangs have created for Western companies and utilities could give them a comparative advantage over time. That is assuming the same attacks aren't happening in China, Russia, North Korea, Iran, etc.

Re: The push to ban ransom payments is gaining momentum

#104
post #70

Earlier quoted context omitted.

The idea would be to reduce the likelihood of a payout.

If this doesn't reduce the likelihood of ramsomware (because it's low effort to just send and see what happens) then it's only a problem for the victims

I think that’s the point. Force the companies to improve their security practices.

Re: The push to ban ransom payments is gaining momentum

#105
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

> It's the victims that would now have two problems: damned if they pay, damned if they dont.

The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security. They get hacked, pay out transom money and don't change a thing.

I mean, just look at the poor victim British Airways https://www.bbc.com/news/technology-54568784

--- start quote ---

A subsequent investigation concluded that sufficient security measures, such as multi-factor authentication, were not in place at the time.

The ICO noted that some of these measures were available on the Microsoft operating system that BA was using at the time.

--- end quote ---

Or the poor victim Microsoft: https://edition.cnn.com/2024/04/02/tech/us-government-micros...

--- start quote ---

The hack “was preventable and should never have occurred,” says a report released Tuesday by the US Cyber Safety Review Board (CSRB), a group of government and private cybersecurity experts led by the Department of Homeland Security.

--- end quote ---

Re: The push to ban ransom payments is gaining momentum

#106
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

And you can get them on the way out. Blackmail them again once they've made the payment as it's a crime

Maybe a good one-off tactic - but at scale, the obvious moral would be "never pay the ransom, because they'll endlessly blackmail you for more".

Re: The push to ban ransom payments is gaining momentum

#107
post #56
post #54

I'm ignorant but I've never understood why people actually pay the ransom. Aren't the attackers anonymous? What stops them from asking for another $Y after they get their $X, and not actually removing the ransomware? There's not much incentive for the attackers to actually do what they say after you pay them, right?

These attackers have made it clear they will release your data. They have done that many many times exactly because they know the target needs to believe they will release it. They even have customer support to help the targets recover everything.

It's not really hard, but they reportedly have better customer support than e.g. Google.

Re: The push to ban ransom payments is gaining momentum

#108
post #70

Earlier quoted context omitted.

If this doesn't reduce the likelihood of ramsomware (because it's low effort to just send and see what happens) then it's only a problem for the victims

I think that’s the point. Force the companies to improve their security practices.

I don't think the people drafting such laws have 2nd order thinking

Re: The push to ban ransom payments is gaining momentum

#109
post #105
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

> It's the victims that would now have two problems: damned if they pay, damned if they dont. The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security. They get hacked, pay out transom money and don't change a thing. I mean, just look at the poor victim British Airways https://www.bbc.com/news/technolog…

>The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security.

Given that even top intelligence targets we read about being hacked, I seriously doubt it's just about getting some better security mentality.

Re: The push to ban ransom payments is gaining momentum

#110

Earlier quoted context omitted.

And you can get them on the way out. Blackmail them again once they've made the payment as it's a crime

True, in any case, it will give the victims a stronger incentive to not involve the police and to cover up the fact that they were being blackmailed in the first place... Once they've paid the ransom, there will be no incentive to pursue the blackmailer.

The ransoms then needs to be hid from shareholders and independant auditors. Both have reason to look and some do.
Post reply on HN