4 ms·
Maybe it's naive, but I wonder if escalating fines then sanctions against countries responsible for a lot of cybercrime could work. Right now the incentives ar
by thmsths 3y ago
Maybe it's naive, but I wonder if escalating fines then sanctions against countries responsible for a lot of cybercrime could work.
Right now the incentives are all messed up. If citizens from country A lose millions from scammers in country B, country B has little incentive to spend precious resources on making it stop. In some cases it's even worse as country B might be benefiting from the scam.
Telling some countries "we won't let you route calls to our country because a disproportionate amount is scams" might provide an incentive, and if it doesn't it makes the scamming harder. Of course this needs to be weighed against the potential costs.
- MrYellowP 3y agoYou make little sense. What are they going to do about it? Digitally lock down everything somehow? Outlaw encryption? Forbid VPNs? Implement a massive, nation-covering firewall that actually can enforce any of that?
- _fat_santa 3y ago> Maybe it's naive, but I wonder if escalating fines then sanctions against countries responsible for a lot of cybercrime could work. Unfortunately that gets wrapped in Geopolitics. I'm sure the cybercrime unit will love to issue sanctions against certain countries but the higher ups will never allow that because they need that country as an ally in the region more than they need to stop cybercrime from that country. Ie. bigger fish to fry.
- grotorea 3y agoAnd those are mostly third world countries so I doubt it would look good to basically sanction countries that have enough trouble with national debt as it is. And is there any country where the "bilateral" cybercrime is more significant than the legitimate bilateral trade? India is notorious for the phone scam centers but it also has a giant legitimate call center business.
- pksebben 3y ago> Of course this needs to be weighed against the potential costs. On both ends. Listening to Darknet Diaries [1] recently with a story on email fraud, and they mentioned that the estimated yearly take for one particular fraud group in Nigeria amounted to roughly a third of Nigeria's GDP. Even if we interpret this as inflated, it's hard to imagine that the Nigerian government is highly motivated to put a stop to that flow of capital. 1 - https://darknetdiaries.com/episode/141/ https://darknetdiaries.com/episode/141/
- FredPret 3y agoDear lord, what if they actually make one of them the Prince of Nigeria for real
- HowTheStoryEnds 3y agoHe'll still need you or your parents to get to his money.
- grotorea 3y agoI like the interpretation of cybercriminals as privateers, specially where the state lets it be like in Russia.
- 14 3y agoHow can you prove what country a criminal is from? You would have to make vpns and tor illegal so that it is impossible to mask your connection and that will never happen. I believe right now they can sometimes gleam hints as to the source country of malware but it’s not a certainty as of course a smart hacker would take steps to mask their work.
- AnthonyMouse 3y ago> You would have to make vpns and tor illegal so that it is impossible to mask your connection and that will never happen. It would also be irrelevant, since criminals don't follow laws.
- ajb 3y agoIndeed, cybercrime is cross-border because that makes it difficult to reverse fraudulent transactions. There should simply be an international treaty such that fraudulent transactions crossing a border can be reclaimed from the government of the destination country, leaving them with the problem of reclaiming it within their own country.
- AnthonyMouse 3y agoThis is assuming you even know where they are. Suppose you want to impose tariffs on China because of cybercrime originating from there. Then China comes back and says they've investigated your claims, the computer you say the attack was coming from was actually another victim being used as a proxy and the real perpetrators are in North Korea or wherever. Then they make up some IP address in North Korea and tell you to go after them, which you can't because they don't have any money or don't trade with you or already hate you. Or cybercriminals in whatever country actually do just compromise some machines in other countries and use them as proxies to keep their own local authorities from having to care, and then you legitimately don't know where they are.
- ajb 3y agoAny such crime involves a transfer of money, and the destination country is easily determined. The point is not to figure out where the criminals are, but to place responsibility on the country that can act on it. That's why I said the refund should come from the destination country, not the country where the criminals are located. If the criminals are not located there, then that country will have a claim on the next country that the money is transferred to, etc.
- AnthonyMouse 3y agoMoney isn't any easier to trace than data packets. Dollars get converted into bullion or Monero some other fungible commodity with no tracking attached, then back into money. The country where the conversion happens isn't inherently the country where the criminals are, and you can't plausibly make it illegal to buy <fungible commodity> for every value of <fungible commodity>.
- ToucanLoucan 3y agoI mean, one can easily make the argument that this an incredibly rare instance where the global south get to be the exploiters as opposed to the exploited, and online scams could be argued as a "colonialism tax" on the richer, dumber citizens of western nations that are used to a government that at least feigns giving a shit about their security. I'm not saying that's right, of course, something something two wrongs. I don't condone it but I don't judge them for it either. As with most crime, the answer largely seems to be elevating the communities from which the crime comes, because while there's certainly a non-zero population out there that will just fuck shit up for their own gain, regardless of how harmful and risky it is, numerous studies on the subject and the successful rehabilitation programs in other countries not using a punitive system of justice demonstrate that the vast majority of the time, what "criminals" really need is a legal option to make a decent living. That can require a wide spectrum of things from proper education/skills training for that given person, to environmental or medical help to address untreated mental/physical illnesses, to systemic improvements so jobs pay enough to actually live and are available where people are. Basically: Our society demands people have money to survive, and most people given a reasonable opportunity to earn money in a pro-social way will do that, because if for no other reason, it's easier and less risky. However if you live in a place where you are denied the opportunity to make that living, what do you expect people to do? Lie down and wait for the cold embrace of death, or start stealing shit? Put in that position I'd tell you exactly what I'd do.
- AnthonyMouse 3y ago> online scams could be argued as a "colonialism tax" on the richer, dumber citizens of western nations that are used to a government that at least feigns giving a shit about their security. Which brings us to the actual problem that causes these others. We don't put the consequences of bad security practices on the people who could have taken better precautions because they're "the victim" even though they're also the only person who could have prevented it. So instead we move the cost to the merchant via the credit card companies etc., or some other intermediary whose fault it was not. Which removes the incentive for ordinary people to care about security, and then they don't. Who cares if your IoT garbage provides an entry point into your home network and some Russians get your credit card number? Don't spend time choosing a device with open source firmware that gets indefinite community support. Don't worry about giving your credit card number to scammers. Just buy whatever's cheap and when it happens you can call the credit card company and make it their problem. Which in turn makes it the credit card company's problem, which they don't like, so they start asking for awful cybercrime bills to do something about this, even though the only something that works is to make consumers feel meaningful consequences for not caring about security.