Live data from Hacker News

The push to ban ransom payments is gaining momentum

socket.dev

71–80 of 173 posts

Re: The push to ban ransom payments is gaining momentum

#71
We are a small but distributed organisation targeted by ransomware attack some weeks ago having poor luck that an employee noticed that something strange is underway just now in our system and pulled the plug without hesitation or waiting for instructions. Backups saved the day except a few days work of items easy to reproduce - memory is still fresh. We only had I guess less than 30 lost man days of work on efforts and a little downtime - in a mission noncritical period - while ensured (as far as possible) all is good, no malware remained, no spreading to local computers, reviewing practices, etc.

Do take this seriously, we operate on a few millions EUR budget yearly - tightly counted - and still we were worthy for attack in their eyes. Watch out all!

Re: The push to ban ransom payments is gaining momentum

#72
post #52

The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…

And you can get them on the way out. Blackmail them again once they've made the payment as it's a crime

True, in any case, it will give the victims a stronger incentive to not involve the police and to cover up the fact that they were being blackmailed in the first place... Once they've paid the ransom, there will be no incentive to pursue the blackmailer.

Re: The push to ban ransom payments is gaining momentum

#73

Earlier quoted context omitted.

It seems reasonable to suggest that the number of profit-driven ransomware endeavors and the number of for-fun ransomware endeavors can both be non-zero and contain some overlap and some non-overlap. Therefore it seems that to make it unprofitable would at least eliminate the former reason which under all by the worst case scenario where those numbers are perfectly equal and overlapping would result in fewer ransomwa…

Not only might X (= banning payments) not eliminate ransomware, it could make the problem worse! Those ransomware perpetrators who are motivated by profit could multiply their activities, if the yield is reduced: have more heists going on.

[deleted]

Re: The push to ban ransom payments is gaining momentum

#74

Good. as someone who works in cybersecurity, I think hackers should get $0 from the victim, possibly get caught by police, and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.

> I think hackers should get $0 from the victim, possibly get caught by police

The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go for it [1]. Other cybercriminals like scam callcenters in India and Turkey have been found to bribe local governments to turn a blind eye or to warn against enforcement by federal authorities.

The only way to hold them accountable is to cut the countries off from the global communications networks so they can't do any more damage until they show credible efforts and successes in being better netizens, but we don't want to do that for a variety of "realpolitik" reasons either.

> and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.

EU GDPR has made some effort there, but in the end all software has security-critical bugs and there is only so much one can do to prevent getting hacked.

[1] https://www.reuters.com/world/middle-east/explainer-how-clos...

Re: The push to ban ransom payments is gaining momentum

#75

It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly), and not notifying law enforcement, software vendors, security researchers, or the customers. And then without any disclosure or collaboration, every company is on its own island, no collective learning, making it trivial for attackers to re-use th…

> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly) It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for…

It depends on how illegal "illegal" it is, too. Illegal doesn't mean criminal, and even then, companies do plenty of things that are normally criminal and they get away with a small fine.

Re: The push to ban ransom payments is gaining momentum

#76

It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly), and not notifying law enforcement, software vendors, security researchers, or the customers. And then without any disclosure or collaboration, every company is on its own island, no collective learning, making it trivial for attackers to re-use th…

> It would seem the unintended consequences of such a policy would be to ensure every cyber breach is kept entirely secret (so that ransom payments could be made discreetly) It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash. And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for…

> It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash.

Create a shell company in some remote tax haven with lax disclosure laws, have them pay the ransom, and close the shell company afterwards. Companies are already good at dodging taxes this way.

Re: The push to ban ransom payments is gaining momentum

#77
post #71

We are a small but distributed organisation targeted by ransomware attack some weeks ago having poor luck that an employee noticed that something strange is underway just now in our system and pulled the plug without hesitation or waiting for instructions. Backups saved the day except a few days work of items easy to reproduce - memory is still fresh. We only had I guess less than 30 lost man days of work on efforts…

good on your employee who pulled the plug first and asked questions later-- that's the sign of an organization where people aren't afraid to do the right thing. very scary situation.

Re: The push to ban ransom payments is gaining momentum

#78
post #51

Banning ransoms worked, mostly, for terrorism. That has to be backed up by a sizable intelligence effort to find and fix the attackers, and a military effort to take them out.

That worked because the terrorism in question was Islamist - neither Russia, China nor Iran have any desire in having such groups grow powerful enough to be a threat to their interests, so it was in their interest to cooperate enough with the Western nations to quash the threat.

Re: The push to ban ransom payments is gaining momentum

#79
It shouldn't be banned. Just add a +300% tax to it, while keeping it legal. (Banning will just lead to under-the-table payments).

While this looks at face value like it's just making things worse, in fact it cuts the profits by 75% for any criminal trying to optimize the ransom demanded.

Then use the tax collected to fund IT security research or something.

Re: The push to ban ransom payments is gaining momentum

#80

> Ransomware is a profit-driven enterprise. If it is made unprofitable, most attacks will quickly stop. This is conjecture presented as fact. Here is an alternative conjecture: what if ransomware is mainly a sociopathically-driven enterprise, with a side interest in profit? Or what if a good chunk of it is? How many ransomware perpetrators have we captured, and subjected to psychological study, to be able to confiden…

Such kind of interest in profit (as in the majority of enterprises, executives etc) _is_ sociopathically driven in general.
Post reply on HN