Earlier quoted context omitted.
The idea would be to reduce the likelihood of a payout.
If this doesn't reduce the likelihood of ramsomware (because it's low effort to just send and see what happens) then it's only a problem for the victims
The push to ban ransom payments is gaining momentum
121–130 of 173 posts
Re: The push to ban ransom payments is gaining momentum
#122It's kind of crazy to me that large companies are even able to make large, anonymous, unbudgeted, essentially cash payments (with no paper trail) at all.
Re: The push to ban ransom payments is gaining momentum
#123What is the difference between a computer ransom and a human kidnapping and ransoming situation? If I’m not allowed to pay ransom to save my business, does it means I should be also not allowed to pay ransom to save my loved ones?
The rules are complex here. If your kid really is kidnapped ask the FBI (or local equivalent). Often they can pay a random on your behalf - with money they have means to trace. Sometimes if your life is in danger you can pay a bribe - but be sure to report to the FBI (or local equivalent) as soon as you are safe.
Re: The push to ban ransom payments is gaining momentum
#124I agree with the push for the ban to remove incentives but I do wonder about consistency. These days it seems the world is compromising and “negotiating with terrorists” all the time. For example look at how Hamas is being handled, for taking all those hostages and still holding onto them months later. Are these situations different?
Re: The push to ban ransom payments is gaining momentum
#125Earlier quoted context omitted.
> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly) It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for…
The IRS isn’t going through all tax filings with that level of detail. If I were to guess, 90% are accepted at face value, 10% are flagged for some irregularity and 1% are audited in detail.
Re: The push to ban ransom payments is gaining momentum
#126Earlier quoted context omitted.
> You could change that percentage to any amount and it wouldn't change a thing, So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more. If we assume the criminals do not generally do much research on each company's ability to pay, but…
> So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? Maybe, maybe not. Everyone has a different threshold of what they will pay. Everyone has different costs to recover. Nobody really knows the exact cost to recover until they are done, by the time you realize you underestimated the cost of recovery it is too late.
If so, why don't they?
Re: The push to ban ransom payments is gaining momentum
#127Earlier quoted context omitted.
Yep. Make it a crime to pay ransoms. No data is worth enabling and enriching criminals. Have tested backups stored offsite. If you fail at that, then you fail at business and deserve to go out of business.
For Ransomware, Backups need to be offline, not necessarily offsite. I.e. there needs to be no possibility of the hackers corrupting or deleting the backups too. If your data is in the cloud, it's probably good to have an offline backup onsite - sometimes cloud providers delete your account: https://news.ycombinator.com/item?id=40304666
...and tested on independent infrastructure.
I worked with a financial Customer in the late 90s who, quarterly, sent a backup to an independent party for restore of the data into a freshly created application environment. They verified the backup with reproduction of key reports and random spot checks of data. It was impressive.
Re: The push to ban ransom payments is gaining momentum
#128Earlier quoted context omitted.
Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…
My "lawful evil" approach to this would be to put the money thus collected in a special fund for counter-intelligence operations targeting people who produce and use ransomware. Collect 1M in ransom, someone else now has 3M to fight you with.
When I was a teenager and started playin D&D (1st ed), there was only Lawful/Neutral/Chaotic. No Good/Evil.
At the time, I tended to see the world primarily as Good vs Evil, so AD&D (2nd ed) seemed like an improvement.
As I got older, I came to realize that what people consider "Evil" is mostly used for people we're in some partisan conflict with.
Like in Israel/Palestine: Each side see the other side as "Evil" and themselves as the "Good Guys".
If anything, the main purpose of allowing ourselves to see some groups or individuals as "Evil" is to dehumanize them in ways that allow us to do "Evil" things to them.
Lawful vs Chaotic makes a lot more sense to me than back then, though. It's the yin/yang dualism that when in balance gives rise to most of the interesting dynamical phenomena.
Re: The push to ban ransom payments is gaining momentum
#129Earlier quoted context omitted.
How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…
They already must report breaches to the FTC and they must report their financials to the IRS. Most companies aren't going to cook their books over this.
A one-time under the table purchase from some dark web bitcoin broker doesn't seem like that big of a deal. It's not the sort of book-cooking that tends to get noticed.
Re: The push to ban ransom payments is gaining momentum
#130I thought ransomware was a crime already? What would banning a crime do?
What this means is it is legal for some people and they can target you. Which now leaves the problem of what should "western" countries do about this? The options are limited. Either it is CIA activities - but this assumes they have spies in place and risks given them up and so it is very limited; or it is a military invasion (of a major nuclear power!). There is diplomatic pressure of course, but there doesn't appear to be anything that can do about this. If you have a good idea I'm sure governments will be interested - but in general smart people have already been thinking about this so odds are you just don't understand why your idea is bad.