6 ms·
Great, now with the same logic the US Treasury Department should impose fines on parents who want to pay the ransom for their kidnapped children, because obviou
by Avtomatk 6y ago
Great, now with the same logic the US Treasury Department should impose fines on parents who want to pay the ransom for their kidnapped children, because obviously (paying the ransom) benefits and promotes the illicit objectives of the kidnappers... Jesus Christ.
Anyone have any reasonable explanation for this? Wouldn't it be better to fine companies that don't have a security standard for their data?
edit: An example with apples:
Jhon is a guy who does not care about the security of his company and does not create backups, suddenly he receives a ransomware attack and all his data is now encrypted, he has no option but to pay the ransom or all his intellectual property will be unusable , so he pays, and since he paid the criminals, he also pays a fine for incentivizing ransomware ... At the end of the day nothing was fixed and the ransomware groups are happier than ever.
In a parallel universe we have an improved system, here it is regulated that all companies have either a backup of their information or a very robust system without back doors. Here Jhon also does not care about the security of his company, then it is discovered that Jhon does not have a backup copy and he is fined, Jhon pays and is forced to improve the security of his company, then he does it, then he receives an attack of ransomware, but Jhon refuses to pay because his company already has better security ... At the end of the day Jhon paid a fine, but the ransomware teams didn't get what they wanted, the problem was fixed here.
- viraptor 6y agoNot the same logic. At least not until we can recover kids from backups.
- NeutronStar 6y agoWhy haven't you produced a DNA backup of your kids yet?
- Avtomatk 6y agoOh yes, all companies have backups. I think you didn't understand the point.
- viraptor 6y agoNot all companies have backups, but it's not possible to check this at scale. You can't verify everyone's software environment and verify that the DR plans actually work. Also some cases don't care about data loss - there are areas where you can repave everything and ignore the incident happened. Where it's actually required, we already have checks like PCI-DSS, data retention laws, government policies, etc. and you'll be audited. But again - this is very selective to make it realistic. Can you imagine there's a government entity which can come to your independent company at any point and say "show us your recent backups, how you restore it, and validate it's complete"? There's no way anyone would agree to this, or fund it. What we know is that backups are the lowest barrier and if you don't have them for data you're prepared to pay for, you are pretty much sponsoring the ransomware business.
- xoa 6y ago>Oh yes, all companies have backups. I think you didn't understand the point. I assume you're using sarcasm in the first part there, but that in turn it's you who aren't getting the point. All companies may not have backups, but all companies could have backups. And the industry as a whole could be taking far more measures to mitigate ransomware, it's not some impossible problem. As well as prevention measures, ransomware is quite detectable actively because it necessarily changes the entropy of stored data in extremely obvious ways that a watchdog could detect. Or there could just be automated systems that constantly sample backups and verify they're restorable. If companies don't do that and choose to externalize some of the costs onto society (by funding criminals who will go on to hurt others in this case) it's completely appropriate for government to step in and stop them. There are lots of situations where people and organizations are expected to exercise reasonable diligence or face the consequences. In contrast, at least for now backing up humans is not in fact an option. People aren't being lazy or failing to make reasonable efforts by failing to back themselves or their dependents up because that just doesn't exist. It's not the "same logic" at all, and how you made the mental leap of equating perfectly reproducible digital data with children is a real question.
- Avtomatk 6y agoLook, an example with apples: Jhon is a guy who does not care about the security of his company and does not create backups, suddenly he receives a ransomware attack and all his data is now encrypted, he has no option but to pay the ransom or all his intellectual property will be unusable , so he pays, and since he paid the criminals, he also pays a fine for incentivizing ransomware ... At the end of the day nothing was fixed and the ransomware groups are happier than ever. In a parallel universe we have an improved system, here it is regulated that all companies have either a backup of their information or a very robust system without back doors. Here Jhon also does not care about the security of his company, then it is discovered that Jhon does not have a backup copy and he is fined, Jhon pays and is forced to improve the security of his company, then he does it, then he receives an attack of ransomware, but Jhon refuses to pay because his company already has better security ... At the end of the day Jhon paid a fine, but the ransomware teams didn't get what they wanted, the problem was fixed here.
- TP4Cornholio 6y agoHuman life and children in particular are also much more valuable than data.
- viraptor 6y agoYes. Exactly. But if we could recover them from backups, they would be just about the same.
- labster 6y agoThat depends on what the kidnappers do with their copy of the brain. I wouldn’t be happy if there was a copy of me forced to listen to Coldplay 24/7.
- Avtomatk 6y agoIt is an example, I am not comparing children with data.
- desdiv 6y ago>the US Treasury Department should impose fines on parents who want to pay the ransom for their kidnapped children Some countries does actually criminalize paying ransom for kidnapped children. The logic being that if society make it harder to pay ransoms (both via criminalization and strong currency controls at the bank), then less kidnappers will get paid, which leads to less kidnapped children (hopefully). The vast majority of people in this thread probably disagree with such a law. I certainly do. But on the other hand I realize that if I had been born in one of these countries and lived there my whole life, I would probably be a fervent defender of such a law.
- ClumsyPilot 6y agoFrom my cursory reading of the topic, three is basically no precedent for jailing such ransom-paying parent, and securing a conviction with a jury is very unlikely
- desdiv 6y agoYes, I should probably clarify: the point of such a law is to _discourage_ the behavior, but not to actually _punish_ the ransom payer, since no jury is going to vote on putting grieving parents in jail. So you end up deterring ransom payments without actually introducing negative externalities.
- jart 6y agoThe Hacker News vocal minority gives off this vibe that they'd rather have something like the fda stop by at your office each week with an inspector who logs into the backup system and checks off boxes if your local tech union is complying with the regulations. I feel like I'm going to gag.
- bigbubba 6y agoI believe paying ransoms for people already is illegal, at least in circumstances where the payment would be going to terrorist organizations. I'm under the impression this is the case in both the US and UK.
- csense 6y ago> with the same logic the US Treasury Department should impose fines on parents who want to pay the ransom for their kidnapped children, because obviously (paying the ransom) benefits and promotes the illicit objectives of the kidnappers This is actually sound logic. If 90% of parents pay ransom, kidnappers will kidnap a hundred kids a year. 90 will come home whole, 10 will have their fingers, toes, eyeballs, and various other body parts mailed home one per week in plastic baggies, or whatever unpleasant fate awaits kidnap victims who can't come up with their ransom. Then what happens if we make ransom illegal, and we have the police watching the bank accounts of kidnapped kids' families like hawks so usually even if parents try to flout the law, the police can successfully freeze a transfer before the funds get to the kidnappers? In that case kidnappers will kidnap three or four kids, most likely none of the parents will pay. Those kids will be horribly murdered, but then the kidnappers will decide it's not profitable and give up. Horrible if you're the parent of one of the 3 kids, especially if you end up in jail for trying to save your child's life. But from a standpoint of social policy, having 3 kids get horribly murdered and then no more is a way, way better outcome for society as a whole than having 10 kids a year get horribly murdered, plus 90 kids a year get kidnapped and their parents have to pay ransom. The problem is the 3 kids that actually get murdered have names and faces and sad / angry / incarcerated parents. The 7 kids a year who were saved from coming home in baggies, and the 90 kids a year who were saved from being kidnapped but ransomed, and the 90 sets of parents who weren't impoverished paying a giant ransom when their kids were kidnapped? They're statistical and unknowable. I suppose it's a variant of the trolley problem: Is it ethical to save a specific person whose name and face you know, if by doing so you're condemning to death many others, whose identities are currently completely unknown since they will be randomly chosen at a future date? You could also make an argument in the other direction from individual rights. Society shouldn't sanction a person who's trying to save a family member being directly threatened with death, even if their actions indirectly cause the deaths of many others. The right to protect your family is important and should be protected. I guess it depends on whether you have a utilitarian perspective (3 dead kids is better than 10 dead kids full stop) or a rights-based perspective (you always have a right to protect the life of a threatened family member full stop.)
- luckylion 6y ago
- asdfasgasdgasdg 6y ago> Anyone have any reasonable explanation for this? Wouldn't it be better to fine companies that don't have a security standard for their data? Well, your second question is basically impossible to do, as "security standards" are a constantly evolving landscape and being compliant with whatever the latest certification will not necessarily prevent you from being hacked. Also, it is much more difficult and expensive and potentially unconstitutional to enforce such a law, whereas enforcing a law that requires companies not to transfer money to certain countries or organizations is comparatively easier. It's also easier tell which side of the bright line any given action is on. The explanation for the law is obvious and you seem to know it from the previous paragraph so I'm not sure what the question is. Is it controversial? For sure. Is it without any logic? By your own admission, there is an argument to be made.
- Avtomatk 6y agoIn my comment above I talked about applying security standards or backups, I see that forcing companies to have backups is more viable... To better understand my point of view, read my example above and the comment of "luckylion ". Companies are simply not going to report because their intellectual property becomes more valuable than the ransom payment. This law does not mitigate anything, instead a backup regulation would mitigate the problem (because it would not be necessary to pay the ransom, if you need such explicit help to understand things).