Earlier quoted context omitted.
> I think hackers should get $0 from the victim, possibly get caught by police The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go fo…
how come there is no USA and Israel in your list?
The push to ban ransom payments is gaining momentum
111–120 of 173 posts
Re: The push to ban ransom payments is gaining momentum
#112Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.
How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…
Most companies aren't going to cook their books over this.
Re: The push to ban ransom payments is gaining momentum
#113Earlier quoted context omitted.
> It's the victims that would now have two problems: damned if they pay, damned if they dont. The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security. They get hacked, pay out transom money and don't change a thing. I mean, just look at the poor victim British Airways https://www.bbc.com/news/technolog…
> The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security. Given that even top intelligence targets we read about being hacked, I seriously doubt it's just about getting some better security mentality.
Re: The push to ban ransom payments is gaining momentum
#114It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly), and not notifying law enforcement, software vendors, security researchers, or the customers. And then without any disclosure or collaboration, every company is on its own island, no collective learning, making it trivial for attackers to re-use th…
> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly) It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for…
If I were to guess, 90% are accepted at face value, 10% are flagged for some irregularity and 1% are audited in detail.
Re: The push to ban ransom payments is gaining momentum
#115Re: The push to ban ransom payments is gaining momentum
#116Earlier quoted context omitted.
> I think hackers should get $0 from the victim, possibly get caught by police The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go fo…
how come there is no USA and Israel in your list?
They do run intel campaigns against targets or sell the tools to run such campaigns, but so does every somewhat developed nation in this world. Intelligence operations are older than the Bible, they have been a part of civilizations ever since civilizations existed as a concept.
Re: The push to ban ransom payments is gaining momentum
#117Earlier quoted context omitted.
> It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. Create a shell company in some remote tax haven with lax disclosure laws, have them pay the ransom, and close the shell company afterwards. Companies are already good at dodging taxes this way.
> Create a shell company in some remote tax haven with lax disclosure laws, have them pay the ransom, and close the shell company afterwards. Companies are already good at dodging taxes this way. That only works for hiding income, not hiding expenses. You create a shell company in Malta (for example). Now how do you get $$$ into that company so that it can pay the ransom? Okay, so you assign your payment to $MALTA-CO…
Tax authorities already don't give a fuck about where a company shifts its money to. As long as there's a proper entry in the books, at least. There are schemes involving up to six different legal entities [1]. A measly million dollars or two is a minor rounding error for a multibillion dollar company.
> Think about it this way: if it was that easy to hide expenses from authorities, embezzlement schemes would be a lot simpler than they are now.
Embezzlement is easier the higher the embezzler is in the command chain. When the CFO orders something to happen - say, a monetary transfer or the creation of a shell company - it will usually be executed without question by the lower levels. Maybe, given the rise of impersonation attacks, the underlings will follow protocol and call the CFO back to verify that it is really the CFO ordering that thing, but that's it.
Re: The push to ban ransom payments is gaining momentum
#118The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…
Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…
Re: The push to ban ransom payments is gaining momentum
#119Earlier quoted context omitted.
I think that’s the point. Force the companies to improve their security practices.
I don't think the people drafting such laws have 2nd order thinking
Re: The push to ban ransom payments is gaining momentum
#120Earlier quoted context omitted.
Very often the cost of recovery would be much higher than 4 times the ransom. Just look at the British Library as discussed in the article, not paying the 500K ransom cost them more than 6M so far. And was much more damaging to the public (I know because I tried to register after the ransomware and they simply don't have online registration anymore). They are STILL basically offline more than 6 months after: > We're…
> You could change that percentage to any amount and it wouldn't change a thing, So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more. If we assume the criminals do not generally do much research on each company's ability to pay, but…
Maybe, maybe not. Everyone has a different threshold of what they will pay. Everyone has different costs to recover. Nobody really knows the exact cost to recover until they are done, by the time you realize you underestimated the cost of recovery it is too late.