Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

161–170 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#161

Why ban? Force insurance companies to work -- actually insure -- and they'll have to start doing proactive work to keep in business. Are we trying to get a free working market or what??

The insurance company-driven model for industry specific safety improvement that worked so well for fire safety and auto safety has proven impossible because of three factors:

1. Cryptocurrency allows for unimaginably huge untraceable ransom payments that Amazon gift cards did not support,

2. No liability in tort for insecure software, and

3. Lack of computer security regulation (e.g., your car must have a seatbelt and ABS but your software can be arbitrarily bad without being prohibited).

Insurance. Is not going to fix cybersecurity.

Re: The push to ban ransom payments is gaining momentum

#162

Earlier quoted context omitted.

Very often the cost of recovery would be much higher than 4 times the ransom. Just look at the British Library as discussed in the article, not paying the 500K ransom cost them more than 6M so far. And was much more damaging to the public (I know because I tried to register after the ransomware and they simply don't have online registration anymore). They are STILL basically offline more than 6 months after: > We're…

> You could change that percentage to any amount and it wouldn't change a thing, So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more. If we assume the criminals do not generally do much research on each company's ability to pay, but…

> So what you're saying is that the criminals could quadruple their demands, and everyone would still pay?

No. There's a major psychological difference between paying 1M to criminals to recover your data and 3M to the government, and paying 4M to criminals.

Re: The push to ban ransom payments is gaining momentum

#163
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

You are dead wrong from a dynamic game-theoretic perspective:

A credible commitment to ban ransom-paying means that future ransomware attacks will get zero value for the attackers (beyond whatever they can get out of stolen data I guess).

The optimal short term response of the ransomware attackers is to push as hard as possible to make such a ban non-credible, through appeals to emotion like this one.

The optimal long term response for the rest of us is to pass a law banning ransomware payments, make a few high profile examples of those who violate it, and then watch the ransomware epidemic die off, much the same way that kidnapping for ransom died off 50 years ago.

Re: The push to ban ransom payments is gaining momentum

#164

Earlier quoted context omitted.

> So what you're saying is that the criminals could quadruple their demands, and everyone would still pay? Maybe, maybe not. Everyone has a different threshold of what they will pay. Everyone has different costs to recover. Nobody really knows the exact cost to recover until they are done, by the time you realize you underestimated the cost of recovery it is too late.

Do you really think that if most companies were willing to pay 4x more, the criminals would not simply ask for 4x more? If so, why don't they?

What is someone willing to pay is not known and different for different combanies. also too much invites action so they need to pe careful.

Re: The push to ban ransom payments is gaining momentum

#165
post #83

Earlier quoted context omitted.

good on your employee who pulled the plug first and asked questions later-- that's the sign of an organization where people aren't afraid to do the right thing. very scary situation.

It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?

This is just unnecessary contrarianism.

Re: The push to ban ransom payments is gaining momentum

#167
post #147

Earlier quoted context omitted.

Banning it directly is a bad idea. Much of the same effect can be achieved by punishing companies that pay ransoms (or pay criminals or criminal organizations for similar reasons) by slapping a +300% tax on top of the payment (at least for companies). If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their de…

Banning ransoms directly is a good idea. Even if that results in massive losses or even bankruptcies by victims, that is an acceptable consequence to prevent money from flowing to criminal organizations and hostile foreign governments. Sometimes you have to amputate a damaged limb to save the body. Paying a ransom in any circumstance should be a criminal offense.

Plus if companies are less likely to pay the ransom, ransoming companies becomes less profitable.

Re: The push to ban ransom payments is gaining momentum

#168
having worked in a large company hit by the first wave of wannacry ransomware (https://news.ycombinator.com/item?id=14326555), i am doubtful that most companies can just ignore the disruption in business during an attack. not every company can go analogue while dealing with an attack like mgm.

in a balance sheet, paying the ransom is just catching up to inadequate budgeting for systematic security efforts. while the person at the end will always be the weakest link, so much more can be done to avoid most attacks.

maybe everyone going back to thin client like windows 365 would finally put this to end.

Re: The push to ban ransom payments is gaining momentum

#169
post #114

Earlier quoted context omitted.

The IRS isn’t going through all tax filings with that level of detail. If I were to guess, 90% are accepted at face value, 10% are flagged for some irregularity and 1% are audited in detail.

It isn't just the IRS, every large company hires independent auditors to go through the books and report anything "funny", they generally are required to report illegal findings to the police along with reporting legal things that are against the companies interest.

That's not how it works.

Independent auditors check to see if a company's accounting is following GAAP accounting standards (so that a statement can be put in the SEC filings). They don't comb through each payment in detail (corporations can have millions of them each year). And if they find things, they tell the company to fix it or report any deviation from GAAP standards.

But much of it is dependent on good faith of the company along with some spot checking to see if their accounting processes line up with what they said they do.

And plenty of companies who have been found to commit fraud have gotten the "thumbs up" during their "independent audit". It gives you a sense as to how cursory their audits are.

Re: The push to ban ransom payments is gaining momentum

#170

Earlier quoted context omitted.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action? Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United State…

In the corporate sphere, this is way easier to investigate than most other forms of corporate crime. Investigating price fixing or discrimination is hard, because it happens over a protracted period, and you have to show a pattern, and everything is open to interpretation, etc. But this? There are two distinctive events that are basically impossible to hide: The disruption and the payment. Attacks on individuals are…

> There are two distinctive events that are basically impossible to hide: The disruption and the payment.

These seem easy to hide. Sure, it incentivizes quick payment, rather than dragging it out for a week. But for 99.9% of employees, this is "the computer network was down, but IT fixed it quickly". For the 0.1% of employees who understand or suspect it was ransomware... thank god corporate got it fixed before 80% of employees were laid off.

The economic losses from thoroughly investigating all widespread network outages (including many not ransomware), seems to outweigh any benefit this could have in (eventually) discouraging ransomware. Just the other day they were talking about how Pixar lost a whole movie but for a copy on some remote worker's machine... in a world where ransomware payments were criminalized, that sounds an awful lot to me as if it might've been one. How many months would they spend combing through log files trying to rule it out? How much does that cost a company like Pixar when they're trying to meet deadlines?

I'm hesitant to point this out, but I've seen shit like this my entire career (thankfully, none of them ransomware). I still have a career, thankfully, which indicates I was only tangentially associated with such incidents. But they're common. There have been big Atlassian, Amazon, and Google incidents as HN headlines within the last 2 years... and whatever explanations they gave, clearly those were just coverups for ransomware payments (or at least people could reasonably suspect that, were it criminalized).

This still seems unenforceable to me in any practical way. But I guess if we're going the totalitarian police state which ruins the economy route, there is some slight wiggle room.

Post reply on HN