Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

121–130 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#121
post #70

Earlier quoted context omitted.

The idea would be to reduce the likelihood of a payout.

If this doesn't reduce the likelihood of ramsomware (because it's low effort to just send and see what happens) then it's only a problem for the victims

Is that really the case? I was under the impression those organizations have specialized people, some write the software, some do the hacking, some the social engineering etc. Once there is much less money this kind of system would probably fall apart?

Re: The push to ban ransom payments is gaining momentum

#122
post #92

It's kind of crazy to me that large companies are even able to make large, anonymous, unbudgeted, essentially cash payments (with no paper trail) at all.

There is a paper trail in the large business - it just ends when the cash leaves the door as the payment is done by things like bitcoin. Though note the bitcoin isn't as anonymous as the the other side thinks and the FBI has managed to trace bitcoin at times, and they can mark some coins as tainted and so the evil actors have bitcoin that cannot be used, but this is still much more difficult that the large company which has careful records.

Re: The push to ban ransom payments is gaining momentum

#123

What is the difference between a computer ransom and a human kidnapping and ransoming situation? If I’m not allowed to pay ransom to save my business, does it means I should be also not allowed to pay ransom to save my loved ones?

Yes, and this was done a long time ago in places. While your kid might end up killed when the kidnapper realizes they can't get money from you, the criminals won't bother kidnapping again since there is no money in it and so overall society is much better - sorry that it was your kid that was killed.

The rules are complex here. If your kid really is kidnapped ask the FBI (or local equivalent). Often they can pay a random on your behalf - with money they have means to trace. Sometimes if your life is in danger you can pay a bribe - but be sure to report to the FBI (or local equivalent) as soon as you are safe.

Re: The push to ban ransom payments is gaining momentum

#124

I agree with the push for the ban to remove incentives but I do wonder about consistency. These days it seems the world is compromising and “negotiating with terrorists” all the time. For example look at how Hamas is being handled, for taking all those hostages and still holding onto them months later. Are these situations different?

Not really - there are no good options. Hamas kidnapped a bunch of people and Isreal's response to get back at Hamas is called a genocide for good reason - a lot of innocent people are dead as collateral damage. (or at least seemingly innocent, some of them support Hamas maybe). I have yet to see anyone suggest of a way to handle terrorists that doesn't result in more innocent victims in some form.

Re: The push to ban ransom payments is gaining momentum

#125
post #114

Earlier quoted context omitted.

> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly) It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for…

The IRS isn’t going through all tax filings with that level of detail. If I were to guess, 90% are accepted at face value, 10% are flagged for some irregularity and 1% are audited in detail.

It isn't just the IRS, every large company hires independent auditors to go through the books and report anything "funny", they generally are required to report illegal findings to the police along with reporting legal things that are against the companies interest.

Re: The push to ban ransom payments is gaining momentum

#126

Earlier quoted context omitted.

> You could change that percentage to any amount and it wouldn't change a thing, So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more. If we assume the criminals do not generally do much research on each company's ability to pay, but…

> So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? Maybe, maybe not. Everyone has a different threshold of what they will pay. Everyone has different costs to recover. Nobody really knows the exact cost to recover until they are done, by the time you realize you underestimated the cost of recovery it is too late.

Do you really think that if most companies were willing to pay 4x more, the criminals would not simply ask for 4x more?

If so, why don't they?

Re: The push to ban ransom payments is gaining momentum

#127
post #86

Earlier quoted context omitted.

Yep. Make it a crime to pay ransoms. No data is worth enabling and enriching criminals. Have tested backups stored offsite. If you fail at that, then you fail at business and deserve to go out of business.

For Ransomware, Backups need to be offline, not necessarily offsite. I.e. there needs to be no possibility of the hackers corrupting or deleting the backups too. If your data is in the cloud, it's probably good to have an offline backup onsite - sometimes cloud providers delete your account: https://news.ycombinator.com/item?id=40304666

> Backups need to be offline...

...and tested on independent infrastructure.

I worked with a financial Customer in the late 90s who, quarterly, sent a backup to an independent party for restore of the data into a freshly created application environment. They verified the backup with reproduction of key reports and random spot checks of data. It was impressive.

Re: The push to ban ransom payments is gaining momentum

#128

Earlier quoted context omitted.

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…

My "lawful evil" approach to this would be to put the money thus collected in a special fund for counter-intelligence operations targeting people who produce and use ransomware. Collect 1M in ransom, someone else now has 3M to fight you with.

Off topic:

When I was a teenager and started playin D&D (1st ed), there was only Lawful/Neutral/Chaotic. No Good/Evil.

At the time, I tended to see the world primarily as Good vs Evil, so AD&D (2nd ed) seemed like an improvement.

As I got older, I came to realize that what people consider "Evil" is mostly used for people we're in some partisan conflict with.

Like in Israel/Palestine: Each side see the other side as "Evil" and themselves as the "Good Guys".

If anything, the main purpose of allowing ourselves to see some groups or individuals as "Evil" is to dehumanize them in ways that allow us to do "Evil" things to them.

Lawful vs Chaotic makes a lot more sense to me than back then, though. It's the yin/yang dualism that when in balance gives rise to most of the interesting dynamical phenomena.

Re: The push to ban ransom payments is gaining momentum

#129

Earlier quoted context omitted.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…

They already must report breaches to the FTC and they must report their financials to the IRS. Most companies aren't going to cook their books over this.

Most companies aren't going to unfuck their entire IT infrastructure which was just encrypted and then turned off? I mean, sure, if the only computer affected is the cafeteria cash register system, they shrug it off and reinstall. But more than a few of these attacks have absolutely crippled the victims, to the point that it would take months/years to roll out a scrubbed system, and even then data is irrevocably lost.

A one-time under the table purchase from some dark web bitcoin broker doesn't seem like that big of a deal. It's not the sort of book-cooking that tends to get noticed.

Re: The push to ban ransom payments is gaining momentum

#130
post #5

I thought ransomware was a crime already? What would banning a crime do?

It is illegal in most countries, but if you live in Russia, or North Korea not only is it legal it is encouraged by the government if you target "western" countries. Iran, China and India have also been accused of allowing ransomware (and likely other countries would allow it - but we have strong evidence of Russia and North Korea).

What this means is it is legal for some people and they can target you. Which now leaves the problem of what should "western" countries do about this? The options are limited. Either it is CIA activities - but this assumes they have spies in place and risks given them up and so it is very limited; or it is a military invasion (of a major nuclear power!). There is diplomatic pressure of course, but there doesn't appear to be anything that can do about this. If you have a good idea I'm sure governments will be interested - but in general smart people have already been thinking about this so odds are you just don't understand why your idea is bad.

Post reply on HN