Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

21–30 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#21

> Ransomware is a profit-driven enterprise. If it is made unprofitable, most attacks will quickly stop. This is conjecture presented as fact. Here is an alternative conjecture: what if ransomware is mainly a sociopathically-driven enterprise, with a side interest in profit? Or what if a good chunk of it is? How many ransomware perpetrators have we captured, and subjected to psychological study, to be able to confiden…

It seems reasonable to suggest that the number of profit-driven ransomware endeavors and the number of for-fun ransomware endeavors can both be non-zero and contain some overlap and some non-overlap. Therefore it seems that to make it unprofitable would at least eliminate the former reason which under all by the worst case scenario where those numbers are perfectly equal and overlapping would result in fewer ransomware endeavors.

To say we shouldn't do X because it doesn't perfectly eliminate/solve Y is akin to saying we should do nothing because by that standard, we'll never do anything about Y.

Re: The push to ban ransom payments is gaining momentum

#22
It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly), and not notifying law enforcement, software vendors, security researchers, or the customers. And then without any disclosure or collaboration, every company is on its own island, no collective learning, making it trivial for attackers to re-use the same exploit again and again.

Re: The push to ban ransom payments is gaining momentum

#23
post #6

Earlier quoted context omitted.

How would holding companies accountable look? If you pay x amount as ransom, you must also pay x * some_multiplier as a fine, something like that?

50 years in jail for everyone involved in approving the payment.

Let’s be realistic about this. A company can’t pay a ransom if they don’t have customers. Life sentences for all customers of businesses is the only effective path.

Re: The push to ban ransom payments is gaining momentum

#24

> Ransomware is a profit-driven enterprise. If it is made unprofitable, most attacks will quickly stop. This is conjecture presented as fact. Here is an alternative conjecture: what if ransomware is mainly a sociopathically-driven enterprise, with a side interest in profit? Or what if a good chunk of it is? How many ransomware perpetrators have we captured, and subjected to psychological study, to be able to confiden…

There is likely an element of sociopathy involved as it requires a particular lack of empathy towards secondary victims. But the same can be said for most career criminals, and most crimes do indeed stop when you remove the profit motivation.

Your own conjecture that ransomware authors are somehow a special breed is the one that needs backing.

Re: The push to ban ransom payments is gaining momentum

#25
post #3

Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.

How could it realistically be enforced? Never mind whether it does what we want, can we even perform the action?

Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United States. How many people are executed? 15? 600? Unless the government's doing ransom audits monthly, how the hell will they ever catch such people? Whistleblowers are safe even if they don't whistleblow, they're not on the hook for punishment. And they're not seeing something so unethical they feel morally compelled to act. Just coworkers who are trying to keep the company from falling apart (potentially even saving the whistleblower's job too).

The criminals might try to leverage this by using it as further blackmail material, but that doesn't work in game theory. The individuals are relatively poor, so they can't be milked individually, and the business can't afford ongoing, indefinite ransom... changes the equation into the "definitely not worth it" category. If the individuals could afford it (in the strict sense), then they will refuse orders to covertly make payment, because then they are on the hook personally... so the criminals are going after the small fish and losing the big.

This is unenforceable.

Re: The push to ban ransom payments is gaining momentum

#26

Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.

Does that extend to makers of buggy software, rather than those who often have little choice in what they use.

It’s not always buggy software; ransomware affiliates have been known to bribe company insiders to install malicious software on the network. The insider gets some cut of the eventual ransom. Works great on disgruntled employees or entry-level people.

Fundamentally the financial incentive needs to be stopped in order to curb ransomware activities.

Re: The push to ban ransom payments is gaining momentum

#28
post #20
post #2

Once companies are held accountable for the weapons and whatever else the money they paid in ransom gets spent on, things will finally change. Until then, we use the word "victim" with too much lenience. The secondary victims, the ones getting bombed, or the ones that will be targeted and threatened with the nukes that just got paid for with the ransom money, shouldn't be left out of the equation as they have been th…

Why not hold tax payers responsible as well?

At that point, the government is holding taxpayers ransom until they fix the ransomware problem. "Stop this or pay more taxes...er, fines."

Re: The push to ban ransom payments is gaining momentum

#29
post #3

Does banning ransom payments really work? It just seems to create a service industry to pay on ransomed’s behalf.

Bing Bing Bing!!! We have a winner! Legalized them, the FBI has to pay them for you, you have to give them 3x the cost of the payment. 1x to payment. 1x to finding people who committed the crime 1x to pay off everyone impacted. Increasing the cost of not being secure is the only way the problem will be addressed.

How far do we take that? Adding layers and layers of security isn’t free, and it’s often at the expense of productivity, and if taken far enough, the profitability and viability of a business.

What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?

Post reply on HN