4 ms·
In the corporate sphere, this is way easier to investigate than most other forms of corporate crime. Investigating price fixing or discrimination is hard, beca
by munch117 2y ago
In the corporate sphere, this is way easier to investigate than most other forms of corporate crime.
Investigating price fixing or discrimination is hard, because it happens over a protracted period, and you have to show a pattern, and everything is open to interpretation, etc. But this? There are two distinctive events that are basically impossible to hide: The disruption and the payment.
Attacks on individuals are another matter, yes that's hard to enforce. But then, on the average, I don't think individuals actually benefit from paying this kind of ransom. It just tags you as a mark for further abuse. So maybe most people will accept that paying ransoms is just not something you do.
- NoMoreNicksLeft 2y ago> There are two distinctive events that are basically impossible to hide: The disruption and the payment. These seem easy to hide. Sure, it incentivizes quick payment, rather than dragging it out for a week. But for 99.9% of employees, this is "the computer network was down, but IT fixed it quickly". For the 0.1% of employees who understand or suspect it was ransomware... thank god corporate got it fixed before 80% of employees were laid off. The economic losses from thoroughly investigating all widespread network outages (including many not ransomware), seems to outweigh any benefit this could have in (eventually) discouraging ransomware. Just the other day they were talking about how Pixar lost a whole movie but for a copy on some remote worker's machine... in a world where ransomware payments were criminalized, that sounds an awful lot to me as if it might've been one. How many months would they spend combing through log files trying to rule it out? How much does that cost a company like Pixar when they're trying to meet deadlines? I'm hesitant to point this out, but I've seen shit like this my entire career (thankfully, none of them ransomware). I still have a career, thankfully, which indicates I was only tangentially associated with such incidents. But they're common. There have been big Atlassian, Amazon, and Google incidents as HN headlines within the last 2 years... and whatever explanations they gave, clearly those were just coverups for ransomware payments (or at least people could reasonably suspect that, were it criminalized). This still seems unenforceable to me in any practical way. But I guess if we're going the totalitarian police state which ruins the economy route, there is some slight wiggle room.