After all paying a ransom is very literally funding terrorism, in the most direct possible way.
"Whosoever knowingly pays a ransom", etc.
Of course those seeking a ransom could make their language less and less clear, so it's no longer clearly a ransom. But isn't that still an improvement over the status quo?
Maybe I'm missing something, but I don't see why it should be legal to pay.
I agree that it's probably a bad idea to pay a ransom, since that just supports the success rate and makes ransomware more popular. But do you really think that you should throw a grandparent in jail because paying a ransom is the only way they can get their digital memories back? Are you going to throw all of City Hall in jail because they needed to pay to get their tax records back?
The best option is to have good backups and not give into the demands, and that should be encouraged. But criminalizing people because they didn't adhere to the best digital practices is a bad idea.
(Or cannot detect infections before they become so widespread the whole thing falls down.)
Several parts of the world have kidnapping and piracy issues, and you can buy kidnapping/piracy insurance to pay ransoms in case you are the victim of such a crime. I think most people in the world acknowledge that sometimes bad things happen even when you take reasonable precautions, and you shouldn't be punished just because you were the unlucky one. Most security experts agree that no computer system is un-crackable, there are just varying levels of sophistication and access needed to do so. We've even seen that Stuxnet was capable of jumping air gaps. If a business had such good security that their database and backups were air-gapped but still was hit by ransomware do you think that they should still be fined?
Then I'd say there weren't doing things right. Granted there should be exceptions for when they really did do their best, but generally no.
> Most security experts agree that no computer system is un-crackable
It doesn't have to be, merely needs being not worth the effort to the criminals.
Could they have done more with the resources they had? Would taxpayers/stockholders fund it? Would a small business have the cash flow to do better? If they were told it was secure from the tech folks, would the non-tech folks have any way to prove this wrong?
It is really easy to say after something happens that they weren't doing things right. It isn't always so easy before things happen to know if things are done correctly, though. And trying to figure out what isn't worth it to the criminals is rather difficult. Some folks do quite a bit for an otherwise small amount of money, especially if they feel the victim "deserves" it.
And who pays the ransomware when it happens, if not the taxpayers/stockholders? Or does money just get created out of nothing when needed?
> Would a small business have the cash flow to do better?
IME small businesses can do it if they want to. It takes care, meaning policies, it's not expensive. Also small businesses are less attractive to large criminals.
> If they were told it was secure from the tech folks, would the non-tech folks have any way to prove this wrong?
If they got publicly ransomed, it would become very obvious something needed looking at. The process of potentially hammering them legally would involve them being taken to court where their level of culpability would be decided (and it may be they did do enough so get let off, and everyone can see what happened, and other businesses can decide perhaps to up their security based on the results).
These are all strawmen. I'm not asking for uncrackability, merely due diligence. A little of that goes a long way. These arguments don't stand up. You seem to be arguing for... what?
considering the order of magnitude of place that do not receive a ransom compared to places that get ransomed, the cost is probably on the security side.
> These are all strawmen. I'm not asking for uncrackability, merely due diligence.
but you apparently define due diligence as "not getting cracked," which while different from uncrackability is still an unfeasible demand.
And if ransoming is profitable, what does that do to the market? Does it a) inhibit more ransoming or b) encourage more ransoming?
> but you apparently define due diligence as "not getting cracked,"
Don't misrepresent me - here's what I actually said: "The process of potentially hammering them legally would involve them being taken to court where their level of culpability would be decided (and it may be they did do enough so get let off..."
So they can be let off. It says clearly.
How is this different from making it illegal to give your wallet to a thief at gunpoint?
(obviously here there is the difference of personal harming which correctly resides at a different level; at the same time the stance of non-negotiation with terrorist organization was also justifiable in my opinion.
If what we can agree on is that you must way for the permission of law enforcement before you pay ransom so that they can reasonably confirm you are not inadvertently funding ISIS and also put in place all available precautions that is already a step forward.
Nobody think that paying ransom is a good thing that should be done as soon as possible. At the same time not everything is a nail.)
If we put that on the table, yes, that's a grand idea.
Think of it this way - let’s suppose you make it a crime to give your wallet to a mugger with a gun. Is that going to end up with less crime, or just more people shot, and some innocent victims going to jail just because they didn’t want to get shot?
This seems like an excellent way to siphon public funds. Get infected by "malware", pay "ransom". Voilà, public funds are now some cryptocurrency under your control.
It would surprise me if this has never happened.
My point is simply that Grandma shouldn’t go to jail or be punished because she got hacked and a hacker made her pay to get her grandkids photos back. If you’re saying we shouldn’t let state governments do the same I think that’s reasonable.
But to attack your admittedly cherry picked example, I guarantee that the US government wouldn't fault Bill Gates, they would help him out and track the money that he transferred and turn it against the terrorists.
By the way, another other dark side of making paying ransoms legal is that transferring money to a terrorist group (just because they support it) now has a plausible deniability: "Don't blame me! It was just a ransom!"
Most these "what ifs" get close to solutions in search of problems. Instead of ensnaring innocent people in the hopes of catching people who intentionally commit fraud and fund terrorism, let's use the laws we already have on the books to do so.
Edit to address the bitcoin issue: While a bitcoin transaction is hard to reverse, knowing the wallet addresses of terrorists and being able to track their bitcoin transactions would be a huge win for the good guys. And when that bitcoin inevitably gets turned into useful currency it will be another opportunity to track them. I don't think ISIS would move a billion dollars through bitcoin anyway, they'd probably pick a different method. That kind of transaction would be super hard to deal with and the network would get stressed to the point that trying to sell a billion dollars worth of bitcoin would ensure that it would be worth a lot less than a billion dollars.
Only if you assume that federal law enforcement agencies are a bunch of rule-following robots incapable of rational deduction.
It seems weird to talk about ‘making ransoms legal’ or ‘allowing ransoms to be legal by default’, as if someone has decided it. That’s not how laws work, at least in the US & EU. Laws can only limit rights, there aren’t any default restrictions.
Italy tried to make kidnap ransoms illegal, and it’s controversial, but there have been some high-profile cases of it backfiring. https://www.independent.co.uk/news/kidnap-makes-an-ass-of-it...
So I'd say it's exactly the same.
If you want to stop city from paying the the law need to state that even if they get their data back they need to delete it.
Was those bank accounts blocks where a successful move, or kidnappings stopped due to other measures government made?
This city had proper backups, and indeed was able to avoid paying ransom. Others weren’t so competent.
Unfortunately, these networks will continue to be insecure and that’s a real problem - right now everyone is pretending that it’s “lose your data or pay” for which backups are useful. However, if a hacker gains foothold into a network, and then, for 3 months, randomly changes record (say, randomly exchanging penalties owed among 1000 people every day through the day), then it’s unlikely backups will help - you’d have a mix of new and corrupt data in every backup set even if you have a daily one going back a whole year (and most places are lucky to have more than a week at daily)
Computer people don't want to raise the barrier to entry by requiring licensing and following regulations, and money people don't want to pay for licensed computer/software engineers. Not to mention just deciding what the standards should BE and how the standards body should be constituted and run is guaranteed to be a rats nest and a sequence of progress-thwarting horrors... but the cost of not tackling it and paying for it will cost lives. We can be guaranteed that.
Technically no, but pigs will fly and the state police will stop abusing the overtime system first. Massachusetts is not known for passing laws that reduce the ability of government officials to do as they see fit and of the possible reasons to pass such a law "we gotta be responsible with taxpayer money" would have everyone crying with laughter on beacon hill. The idea of criminalizing paying a ransom for the common man is bad for reasons other commenters have stated. There is exactly zero chance of MA making it illegal for the government to do something peasants can do.
Yes, there are many reasons. You seem to adopt a highly deontological ethical stance. But in actual decision making, being pragmatic, showing some grace by being human and making hard compromises, and at the same time being utilitarian are often more rewarding. For example, governments all over the world have (often secretly) paid ransom money for kidnapped citizens. If they couldn't do that any longer, because it is illegal, then that would doom the fate of many kidnapped citizens.
Elected officials should make reasonable decisions that minimize harm and costs and should be willing to make compromises, not brag with their iron fist policies no matter what the consequences are. (That's just my personal opinion, of course.)
> After all paying a ransom is very literally funding terrorism
Do you have any proof for that claim? If not, then you are merely watering down the meaning of the word "terrorism". AFAIK, these ransomware attacks are conducted by ordinary criminals, not by terrorists.
What? No, that's not the logical solution. Have you considered the consequences of paying that money beyond the immediate deaths? You've suddenly put a real price on terrorist attacks - as in, if I decide to go through with a terrorist attack after 9/11, I know that I can extort the country for anywhere up to $100m. Hell, everybody with a grudge against the US suddenly has massive financial incentive to carry out attacks against the US. How many more people will die because you've decided that it's okay to pay terrorists?
There are plenty of people with a grudge against the US, some of them quite rich. US foreign policy made sure of that. Extra 100 million would make no real difference. The thing stopping them is distance to US and threat of deadly force.
When everything is terrorism, nothing is terrorism.
https://www.ibanet.org/Article/NewDetail.aspx?ArticleUid=780...
Get outta here