Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

151–160 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#153
post #148

Earlier quoted context omitted.

Congratulations: you've just created a culture where people are afraid to report potential issues for fear of losing their jobs. Maybe there are some cases where you find that specific individuals end up acting irrationally more often than not, but on the whole, it is better to treat these acts as if they were good faith until proven otherwise.

It sounds like the person you're replying to has a future career in QA at Boeing.

I’m saddened the sarcasm flew over the heads here. A disappointing reflection of the number of companies that really do act like that now, which was my point.

Re: The push to ban ransom payments is gaining momentum

#154
post #148

Earlier quoted context omitted.

It sounds like the person you're replying to has a future career in QA at Boeing.

I’m saddened the sarcasm flew over the heads here. A disappointing reflection of the number of companies that really do act like that now, which was my point.

Don't be sad. I found out several times myself that irony without emotion hints, misses its goal. Otoh When you add the /s hint, it's more like explaining a joke to a listener.

Re: The push to ban ransom payments is gaining momentum

#155
post #45

Earlier quoted context omitted.

Well we start with say you, you trade some of your bitcoin holdings, the feds seize your winnings, fine you and toss you in prison.

How do they seize it? Say I’ve got a 256-bit number memorized and I live on a farm in El Salvador. Is the US sending seal team 6 to interrogate every person trading bitcoin on earth? Or, is that maybe a bit unrealistic?

If you're a foreigner you're not violating US laws by selling your fraudulent securities. If you sell to a US citizen you aught to stay away from places with extradition treaties.

None of this is new or invalidated by magic coins in my computer.

Re: The push to ban ransom payments is gaining momentum

#158
post #3

Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…

Fifty state insurance commissioners could make this more or less happen overnight, except to the extent firms are using something other than cyber coverage to pay ransoms.

In my eyes, this would do almost as much to improve cybersecurity as liability in tort for insecure software.

Re: The push to ban ransom payments is gaining momentum

#159
post #29

Earlier quoted context omitted.

How far do we take that? Adding layers and layers of security isn’t free, and it’s often at the expense of productivity, and if taken far enough, the profitability and viability of a business. What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?

An unreasonably vulnerable business shouldn’t be considered a viable business.

Define "unreasonable".

Re: The push to ban ransom payments is gaining momentum

#160
post #39

Make software companies liable if it's their bugs that lead to a compromise.

Who’s liable when a user is tricked into handing over a 2FA code? That’s the vast majority of the incidents I’ve seen over the years.

The software company would argue that the lawbreaking hacker was a supervening cause, while the consumer would argue the criminal was foreseeable. In the case of security software, the consumer might have a point. In practice such a claim is not usually successful.
Post reply on HN