Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

41–50 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#41
post #6
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, a…

But even when paying the ransom, you still need to roll back a portion of your environment after you've assessed the intrusion. Can you really trust you've patched everything and removed all trace of persistence that was put by the attacker as a contingency to get back in the system?

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#42
post #8
post #7

Earlier quoted context omitted.

I was assuming that countries would make it illegal to pay these ransoms.

The article doesn't seem to suggest that anywhere.

You are right. It's kind of a toothless tiger without that part though.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#43
post #40
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

> is an acceptable price to pay

It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you.

It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate.

Despair is above reason. Laws are useless to stop desperate actions.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#46
post #40

Earlier quoted context omitted.

We should make it a criminal offense with severe penalties to pay any sort of ransom regardless of the consequences. Use the Foreign Corrupt Practices Act as a model. Even if it means hostages will die or businesses will be destroyed, that is an acceptable price to pay in order to cut off funding to terrorists and other criminals.

> is an acceptable price to pay It is acceptable for you, since you won't suffer the consequences, the burden of damage isn't on you. It is similar to consuming drugs: when people buy meth they're helping the drug dealers. But they just can't help it, they're desperate. Despair is above reason. Laws are useless to stop desperate actions.

We're not talking about desperate drug addicts here. The threat of criminal prosecution and being sent to federal prison is a pretty effective deterrent for most people. Especially the corporate officers who would ultimately have to authorize any ransomware payment. They won't take that risk to help their employer.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#47
post #25
post #2

>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero

Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address.

https://monerodocs.org/public-address/standard-address/

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#49
post #14

So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…

You should have pointed out that her view is self-serving. if you are a hostage negotiator (retired even or whatever), it's natural to argue that we will still negotiate with terrorists. Just like programmers argue about whether we'll still have a job even as ai gets better and better ;-)

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#50
post #47
post #25

Earlier quoted context omitted.

Could you expand why you believe an old hammer doesn’t work with current nails? As a metaphor it seems completely the opposite of your intended meaning since it’s a good example of an ancient technology which still works compatibly. Adding wallets to a black list is highly effective because while there was a lot of dishonest marketing around blockchains improving privacy they’re actually perfect for censorship since…

Ah yes, my Monero nails. https://en.wikipedia.org/wiki/Monero Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories, but im sure my old 14th century hammer will address this issue somehow even though subaddresses can be created that arent even remotely linked to my main address. https://monerodocs.org/public-address/standard-address/

You just ban Monero then. If something is a problem, and you want to ensure financial visibility then ban all transaction types that hide visiblity, like banning mixers. This is separate from whether it's a good idea or not.
Post reply on HN