Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

141–150 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#141
I remember how surprised I was when ransomware really took off, that victims would pay and actually get their data back. Sure, it makes sense, that criminals benefit in the long run if they truly return the data, but I was surprised that the criminals were actually that farsighted.

To me that suggests that rational economic forces really are at work and as a result, banning payments would cut back on ransomware attacks.

This is very similar to having a "we don't negotiate with bad guys" policy, which is common at least as rhetoric if not in fact.

Re: The push to ban ransom payments is gaining momentum

#142

Earlier quoted context omitted.

And just to spell it out: Fewer payout means fewer resources to spend on further operations. So I would absolutely think that the criminals care if there is an actual ban.

Except, this assumes that the cost of an operation being ran is beyond marginal. The actual cost of launching an attack like this is basically nothing - initial access, etc, is largely automated and performed at scale. The “costly” part is the hands on keyboard part, but even that can be largely automated, and even manually doesn’t take long.

Of course the cost of an operation is beyond marginal. The cost of maintaining a team capable of executing sophiasticated ransomware attacks is far from trivial. Especially since the operation is illegal, money need to be laundered, interpersonal tensions in cybercrime happen. Less payouts mean less money for the criminals and is absolutely a problem for them.

This is not a company where you automate people out of job and CEO gets all the profit. Organised crime groups share profits among themselves, and the profit is by far the main motivator for all of them.

Re: The push to ban ransom payments is gaining momentum

#143
post #6

Earlier quoted context omitted.

How would holding companies accountable look? If you pay x amount as ransom, you must also pay x * some_multiplier as a fine, something like that?

50 years in jail for everyone involved in approving the payment.

And the death penalty for the engineer who didn’t patch a vulnerability or the software developer who wrote the buggy code. That will teach them! Judge Hindsight is ready to punish the victims.

Hacks happen. Where starts or ends someone’s responsibility? Where stops the buck? Can we really expect that every layer in an organization is always fully aware of security and security risks, even unknown vulnerabilities? Security practices change over time. Not so long ago 12 character passwords were considered safe, 2FA didn’t exist, …

I don’t think that harsher punishments and victim blaming is the way to go.

Re: The push to ban ransom payments is gaining momentum

#144

Earlier quoted context omitted.

> I think hackers should get $0 from the victim, possibly get caught by police The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go fo…

how come there is no USA and Israel in your list?

Which specific ransomware attacks by the US and Israeli governments are you referring to?

Re: The push to ban ransom payments is gaining momentum

#145

Earlier quoted context omitted.

And just to spell it out: Fewer payout means fewer resources to spend on further operations. So I would absolutely think that the criminals care if there is an actual ban.

Except, this assumes that the cost of an operation being ran is beyond marginal. The actual cost of launching an attack like this is basically nothing - initial access, etc, is largely automated and performed at scale. The “costly” part is the hands on keyboard part, but even that can be largely automated, and even manually doesn’t take long.

You're not competing against the hackers doing nothing, you're competing against them targeting some other country or just changing jobs. You don't have to get the payouts to $0, just low enough that it's not worth doing.

This would basically remove the prospect of million dollar payouts; it probably removes the prospect of payouts in the hundreds of thousands. Any company with the money to make those kinds of payouts is likely to have reporting requirements that make it very hard or impossible to hide.

Payments in the tens of thousands could maybe be hidden or targeted at small enough businesses that they don't have to report what happened to their money, but is it even worth it at that point? We're talking people with at least some level of technical ability; do they really want to piss off the FBI/NSA/European equivalents for tens of thousands of dollars? I sure wouldn't.

Re: The push to ban ransom payments is gaining momentum

#146

Earlier quoted context omitted.

My "lawful evil" approach to this would be to put the money thus collected in a special fund for counter-intelligence operations targeting people who produce and use ransomware. Collect 1M in ransom, someone else now has 3M to fight you with.

Off topic: When I was a teenager and started playin D&D (1st ed), there was only Lawful/Neutral/Chaotic. No Good/Evil. At the time, I tended to see the world primarily as Good vs Evil, so AD&D (2nd ed) seemed like an improvement. As I got older, I came to realize that what people consider "Evil" is mostly used for people we're in some partisan conflict with. Like in Israel/Palestine: Each side see the other side as "…

The lead prosecutor at Nuremberg described evil as “lack of empathy” which I think is just about the best possible definition available to human beings.

Re: The push to ban ransom payments is gaining momentum

#147
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…

Banning ransoms directly is a good idea. Even if that results in massive losses or even bankruptcies by victims, that is an acceptable consequence to prevent money from flowing to criminal organizations and hostile foreign governments. Sometimes you have to amputate a damaged limb to save the body. Paying a ransom in any circumstance should be a criminal offense.

Re: The push to ban ransom payments is gaining momentum

#148

Earlier quoted context omitted.

Layoff. They were costing the company money for irrelevant problems.

Congratulations: you've just created a culture where people are afraid to report potential issues for fear of losing their jobs. Maybe there are some cases where you find that specific individuals end up acting irrationally more often than not, but on the whole, it is better to treat these acts as if they were good faith until proven otherwise.

It sounds like the person you're replying to has a future career in QA at Boeing.

Re: The push to ban ransom payments is gaining momentum

#149
post #41

Earlier quoted context omitted.

It’s not always buggy software; ransomware affiliates have been known to bribe company insiders to install malicious software on the network. The insider gets some cut of the eventual ransom. Works great on disgruntled employees or entry-level people. Fundamentally the financial incentive needs to be stopped in order to curb ransomware activities.

The financial incentive to continue business operations will always be larger. Unless that’s the financial incentive you’re referring to.

Making it a criminal offense for a corporate officer to authorize a ransom payment would mostly eliminate the financial incentive. Very few employees will risk going to federal prison to protect their employer. Especially for publicly traded companies, large expenses are audited and difficult to hide.
Post reply on HN