14 ms·
Ban All Ransomware Payments, in Bitcoin or Otherwise
- im3w1l 6y agoImagine secretly paying the ransom, only to be threatened with a reveal and pressured for more.
- pacamara619 6y agoWhich is why you wouldn't pay it in the first place and which is why you would actually try to make your system secure instead of having an insurance pay for your gross negligence.
- giancarlostoro 6y agoSome people might think their IT department is fully omniscient (or competent in other cases) and knows every flaw they could be targeted by which is why it would make sense to hire an external firm to audit you.
- 55555 6y ago> Which is why you wouldn't pay it in the first place Currently, ransomware operators could just decrypt half your files upon 50% payment, and demand yet another payment for the rest. But they don't. Why? Because they seem to have naturally converged upon honoring their decryption payments in order to maximize total profit. I think if paying the ransom was made more explicitly illegal, the ransomware operators would probably converge on not outing their clients. At least for now.
- shripadk 6y ago> I think if paying the ransom was made more explicitly illegal, the ransomware operators would probably converge on not outing their clients. At least for now. Or they can threaten to release your information and demand more ransom to keep your information a secret. If you stop paying they'll make it public making what you did illegal.
- bluGill 6y agoProblem is as soon as ONE decides not to pay up nobody else will either as they know they can't trust their payment will work out.
- 627467 6y agoSo, now, not only would law enforcement struggle at catching the criminal asking for ransom, they would additionally struggle to enforce the law on the victims
- jdmichal 6y agoYes, heaven forbid law enforcement perform work to enforce the law. That would be a terrible outcome. In non-sarcastic words, I'm unsure what point your comment is trying to convey.
- hombre_fatal 6y agoI assume they are referring to victims hiding their payments from the government. It definitely just looks like an additional ingredient in this wild goose chase.
- fennecfoxen 6y agoIt’s hard to get cooperation from a crime victim if cooperating is rewarded only with a choice between ruin through loss of his business and ruin through criminal charges. You’ll just see silence as people rationally seek to avoid ruin and fail to report the crime at all.
- bluGill 6y agoThat is hard to do when the criminal is hiding in a different country. Russia is often accused of helping these criminals.
- 627467 6y agoThe point of my comment should becomes clearer if the first few paragraphs is read: the author thinks it's great idea to tell law enforcement to target victims through an hypothetical law he is proposing that would make it illegal to pay ransoms. He's basing his opinion on treasury department decision to (seemingly) ban ransom payments to ransomware groups. What he seems to be misrepresenting is: treasury department is not banning ransom payments. They are clarifying that payments (including ransom ones) to an entity on sanctioned list is illegal. How does this translate to the rest of ransom requests seen in society is beyond me. Are we setting up a precog unit to classify all people and entities in the world as sanctioned/non-sanctioned?
- dividedbyzero 6y agoThat means, for many victims, that that's it, game over, you go out of business. A lot of ransom money is paid because often as not it is very hard and expensive to ensure not only that a business can recover from such an attack, but also on a timeframe and at a cost that doesn't by itself break it, so a great many can't unless it gets detected and stopped very early. Lots of businesses will pay regardless of a ban and eat the fine, or try to pay clandestinely, diverting resources law enforcement should be using to catch the perpetrators. Not sure this is worth a bit more pressure to catch criminals that probably won't get caught anyway.
- appleflaxen 6y agobut the long game is that there will be no victims, because there is no money in it.
- hombre_fatal 6y agoThere is always going to be money in it as long as there is ever anything worth ransoming. What's new here is a new type of criminalization and an incentive to hide your actions from the government. And if the ransomer is asking $5,000 and the government will fine you $50,000, then you have a good incentive to gamble on never getting caught, and that's already a game corporations play (very successfully) with taxes.
- bluGill 6y agoCorporations are not hiding their money from taxes out of sight. They are hiding it in plain site - the exceptions in the tax laws. Hiding out of site is basically impossible for any large company: somebody internally is sure to get disgruntled at some time and tell the police (often for a significant reward).
- Pick-A-Hill2019 6y agoThe Corporates just add a shield layer of employing an 'external consultant' who offers to 'find a way of fixing it'. In fact, there is already a term for it. A quick search of the term 'Ransomware Negotiator' provides citations.
- vmception 6y agoPaying anyone on the OFAC list was already illegal. It should be largely impossible to tell if a ransomware operator is on the OFAC list or not. Stop using surveillance coins. You can send a tornado.cash note to the operator. You can send Monero. These are solved problems.
- resoluteteeth 6y agoIs it a good thing that paying OFAC sanctioned extortionists and thereby illegally financing further ransomware attacks via cryptocurrencies is a "solved problem"?
- vmception 6y agoPaying someone on the OFAC list was already illegal whether ransomware was involved or not. The novelty of the circumstances don't change anything. The novelty of the circumstances do change the futile utility of making an announcement about it, as there should be no way of knowing that a ransomware operator is on the OFAC list, and there should be no way of knowing that you paid a ransomware operator that was or was not on the OFAC list. I don't have an opinion about your question and never addressed it and won't address it, as it is completely moot. As people adopt these technologies for more benign purposes, the peculiarity of using them "when you need to" goes away.
- tolbish 6y ago"We don't know where that $200,000 went. Hackers must have stolen that too. On an unrelated note, we found our encryption key."
- anoncake 6y agoJudges aren't that stupid.
- deleted 6y ago[deleted]
- bonoboTP 6y agoStrange that it is legal currently in the first place. You are basically financing a criminal group. In normal cases that's clearly illegal. How do you even book it in your accounting and taxes? Do the criminals give you an invoice?
- Closi 6y agoBy the same logic, shouldn’t it be illegal to hand over your wallet if you get mugged? Companies aren’t really paying this money by choice, they are paying it because losing systems/data can in some cases result in an inability to operate - otherwise it wouldn’t really be a ransom.
- k_sze 6y agoThe difference is that if you get mugged, your physical safety is being threated. So giving your money to the mugger is reasonably considered defense against bodily harm. I believe that in most randomware cases, nobody's physical safety is in immediate danger (except cases that involve hospital systems or other remote-controlled/networked medical device). I'd say there should be an exception for ransomeware cases where physical safety is being threatened.
- phpnode 6y ago> I'd say there should be an exception for ransomeware cases where physical safety is being threatened. doesn't that incentivise attacks on critical services/systems?
- k_sze 6y agoI don't think so, because critical services/systems are targetted by ransomware operators regardless of the exception. And I don't think the victim should be burdened to decide between losing a life vs paying hefty fines.
- fennecfoxen 6y agoIs it clear that it’s illegal? Is the group clearly defined on a list somewhere or are those sending money supposed to use their judgment? If you’ve been defrauded is that also illegal, making you a criminal as well as a victim? Or is only ransom prohibited? If my local car dealership commits some environmental crime by pouring motor oil down the drain, does this make it illegal for me to pay them to service my car there? What about if your neighbor’s kid is in a gang, but you want to set him straight and give him opportunity, so you pay him to mow the lawn: is that illegal too? What if the whole gang mows your lawn? And if the mafia is shaking down your business for extortion payments, does it make you more or less likely to talk to the cops if that makes you a criminal too? There are answers to these, but it’s inherently a fuzzy area.
- hombre_fatal 6y agoBuilding my own PC recently after a decade on Linux/macOS made me realize how much more susceptible to ransomware PC users are at a PC cultural level. Literally every program I saw recommended when setting up my environment was available from download sites like FileHippo and Softpedia. Here's the second download link for "AutoHotkey" on google: https://autohotkey.en.uptodown.com/windows https://autohotkey.en.uptodown.com/windows - wtf is uptodown? They even train you to get used to that classic subdomain spam that malicious websites use. Another example were various driver tweaks/hacks or anything else a gamer or power user might want to do. Always from a shady mirror website that trains you to run .exes from any website that shows up in search. It was a breath of fresh air to get WSL + Debian up and running on Windows so I could rely on apt-get. The Microsoft Store is surprisingly bad, not having anything you're looking for, but plenty of apps that claim to be that thing or would confuse people who don't know any better. Normal users are really being let down from a security standpoint in computing, in general. macOS has similar issues with websites like macupdate.com, but it's slightly farther along with its much more compelling app store library. My girlfriend is a UX professional and the only few apps she uses outside of the app store is Chrome and Sketch. It definitely feels like this approach is moving in the right direction that can satisfy most people and power users as well. And for completeness, I would think a GUI over linux repos like Synaptic is also nice for normal users. I have one not-so-technical friend on Linux Mint where I saw them using whichever GUI to grab packages.
- lights0123 6y agoChocolatey is far better than downloading installers manually, but it's just slow as every installer has to do its own thing rather than just relying on a package manager to place files where they belong. It also doesn't remember why a package was installed, so dependencies of a package aren't removed after uninstalling it.
- wink 6y agoLast I checked the dependency management there is pretty basic. Also you have the additional problem, as in my case: the software requires a JDK, how likely is it that the user already has a JDK installed without chocolatey, and if not, which one will I install (not sure if it was even possible to say "any JDK between version X and Y").
- blakesterz 6y agoThere's an interesting take on this from Grugq: https://gru.gq/2020/10/18/ransomware-prohibition/ https://gru.gq/2020/10/18/ransomware-prohibition/ "The current situation, where there is no criminalisation of payment has created a market place where a number of companies working with insurers are handling the vast majority of ransomware incidents. There are crisis responders who help the companies recover, who arrange a minimal payment, and who get paid by the insurers. This is market governance and it keeps the prices down because there is a sort of gentlemen’s agreement between the gangs and the payment companies. Also, the lack of prohibition means these companies operate in the open and they can share information about pricing etc internally and with each other. (Transparency) The status quo is not the ideal world, but it is far better than the nightmare of ineffective partial prohibition."
- RHSeeger 6y agoOut of curiosity, how is paying randomware all that much different from handing a mugger your money? And is it also illegal to pay kidnappers? Honest question.
- cesarb 6y ago> Out of curiosity, how is paying randomware all that much different from handing a mugger your money? The difference is obvious: not handing the mugger your money is an immediate threat on your life. You won't die just because you didn't pay a ransomware operator. > And is it also illegal to pay kidnappers? The article already answered that: in some countries, it already is. "[...] In response to a wave of kidnappings by organized crime, Italy prohibited ransom payments in 1991. Colombia and Switzerland have also made ransom payments illegal. The Group of Seven has a long-standing policy of refusing to pay ransoms for hostages of terrorist groups."
- bluGill 6y agoIt is illegal to pay kidnappers. Kidnapping isn't nearly as common as it used to be because it is so hard to get money. Though when it happens it is harder to trace because those who would pay don't talk. The same goes for bribing foreign officials. There are exceptions for Fear for your life situations. Which is why paying a mugger is legal.
- tomp 6y agoYou don't actually pay your mugger. Forced consent isn't consent. The mugger steals from you (even if the money was actually "stolen" by your hand, not his/hers).
- logicallee 6y agoI agree with this. When you give a company gross profit (price higher than what it took them to get you the product) you are literally paying for them to spend some of that on getting their next customer. Anyone who is paying a ransom is literally paying a ransomer to do that to someone else. Not in a metaphorical sense. You are literally transferring the ransomer money which the ransomer will literally use to finance the next ransom. They will pay out of pocket for the person doing the next ransom to go and do it. It should be totally illegal to finance this.
- fennecfoxen 6y agoThis is not how it works. If you pay a company money and they earn a profit, they will have more money. But the next customer doesn’t come specifically out of your revenue. They generally won’t have waited for you at all, and they would still pay for ads and similar acquisition costs without your money, whether from their reserves or any lines of credit. You charge your own acquisition cost against the profit from your custom, not the next guys’ cost. In the case of crime you have paid them to hack you, not others.
- hajile 6y agoThe us needs to release and update a list of criminal bitcoin accounts. Any bitcoin coming from these accounts should be poisonous and any account ever receiving coins tracked back to that account should be fined plus repay the bitcoin value (receiving stolen property). The scammers can hide, but their bitcoin money can be tracked forever and interacting with the real world in significant sums requires giving up anonymity. It seems very easy for wallets to access a database and alert their user that they're about to purchase tainted bitcoins.
- seppel 6y agoHow to destroy bitcoin is two easy steps.
- hajile 6y agoThat ledger is already public. Every government in the world is guaranteed to track users. The illusion of anonymity is dangerous. If bitcoin dies because it's only used by thieves, extortionists, and cartels, then it deserves to die. I don't think the majority of transactions are of that sort though.
- luckylion 6y ago> That ledger is already public. Every government in the world is guaranteed to track users. The illusion of anonymity is dangerous. That's not the point. Any bitcoin coming from these accounts should be poisonous and any account ever receiving coins tracked back to that account should be fined plus repay the bitcoin value (receiving stolen property). is what would destroy bitcoin.
- GuB-42 6y agoSo I can just buy one "poisoned" bitcoin and send a tiny fraction of it to every public address I can find. Now the entire network is poisoned. Criminals use a variety of money laundering techniques, such as "tumblers": big buckets where you put in both legitimate and illegal transactions and get back an unidentifiable mix of both. But I'm sure a lot more cleverness is happening.
- michaelt 6y agoThe logic here is if there's a big risk to victims from paying they won't pay, and if 99% of victims won't pay, attackers won't attack. It seems to me that logic only works when attacks are expensive. With something like kidnapping, you couldn't possibly kidnap 1000 people in the hopes of getting a single $10,000 ransom payment. But with malware, where launching an attack costs almost nothing? Attacks could still be profitable even if only 1 in 1000 victim pay up.
- tomp 6y agoBut the long-term plan is, that the attacks become more expensive, because it would cause companies to stop having insecure systems (and up the product chain, e.g. Microsoft would have to patch Windows or suffer losses). Same as with spam - the simple solution is that spam (mail/email/calls) are charged to the operator/provider - I can assure you that a solution would instantly appear whereby the providers would take great care about blocking spam at its source. The status quo in both cases is just to "solve" (but not really) the problem with the cheapest, shittiest possible solution.
- andrewla 6y agoThis is utterly ridiculous. This will have the effect of reducing the number of cases of ransomware that law enforcement sees. Not by actually reducing the cases, but instead by making it untenable for a victim to notify law enforcement. <rant>This is unfettered metric fetishization -- the idea that a problem can be quantified as a metric and when the metric is reduced the problem is reduced. The map is not the territory, you can't just look for your keys where the light is good, the bed of Procrustes, etc. Or maybe it has nothing to do with this and is just a well-intentioned but stupid idea.</rant>
- blunte 6y agoI would think that for less than 400k in random payment, the perpetrators of the attack (and anyone complicit) could be located and permanently removed. That might deter future attackers, unless of course these are government sponsored attacks.
- 627467 6y agoThe Treasury department diy NOT outlaw ransom payments. They clarified what was already illegal: payments to sanctioned entities is illegal. How this author extrapolates this to "let's put the victim of any kidnap/ransom through hell" is beyond me.
- theginger 6y agoI've had the idea floating around my head for a while that instead of banning the payment, they should tax them. If you start putting a 500% levy on any business paying a ransom the whole concept becomes a lot less profitable because assuming attackers are not settling for 5x less than what they think businesses would really pay, they'll have to slash the ransoms. And the government gets a nice funding pot to try and fight them.
- tlogan 6y agoThe key here is that you will not be able to use ‘security insurance’ money to pay for ransom. What is happening now is that companies are saying: we do not need backup, let’s just have security insurance (and some minimal backup so that insurance is valid).
- 14 6y agoI will probably take some heat for this response but as a Canadian here is how I see this happening. My computer gets hacked. I am a low level target so the Ransomware asks me for something trivial like $1000. Now I have a couple choices. Not pay and not break the law or pay and break the law but get back all my baby pictures. I am going to pay and take the consequences. In Canada we had a guy literally decapitate another man and then cannibalizes the body. He did 7 years. We don’t jail people for things like paying ransom and if we did we slap people on the wrist. This law will have no teeth for some because we watch the revolving door court system where all criminal are given a slap on the wrist. It is only repeat offenders getting anything other then probation. So at worst I would risk a fine or probation. I live in Canada though so we don’t bend over backwards to screw people so my fine would be insignificant compared to the loss of all my baby pictures. Even if the punishment was 5000$ I would still be leaning towards paying to get those baby pictures I haven’t backed up. If the punishment was a week in jail again I am still going to pay we have really nice jails with all sorts of rights when you get there. I guess my point is we need a better way then telling victims they can’t pay. Thankfully I have backed up my pictures and don’t worry about this scenario currently.
- buildbuildbuild 6y agoBanning ransom payments outright would eliminate the possibility of investigating by blockchain analysis. Implementing a maximum legal payment amount and mandating that all ransomware payments’ TXIDs be reported to law enforcement would be a reasonable compromise in my opinion.
- onyourcases 6y agohttps://www.onyourcases.com/ https://www.onyourcases.com/