The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claiming billions for nonexistent PPE.
As a member of society, I don’t care if I’m paying a professional ransomware group, or a professional corruption gang.
That argument could be used to justify any theft or even kidnapping.
I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives.
There are real harms to randomware. Companies go out of business, people lose their jobs, people lose their service providers, etc.
To say, "it serves them right for not following proper security" literally can be said for a mom/pop business in a poor neighborhood who didn't have bulletproof glass or bars on their windows. It is negating the fact that (a) the harms are very real and (b) security costs money and resources, which is effectively another tax on their business.
If instead the government made it illegal to pay such ransoms and actively audited large BTC transactions and charged people accordingly, then we could get rid of the incentives to do this in the first place.
The government should similarly hold firms accountable when they are hacked (due to the harms on consumers) and require prompt disclosure of any hacks.
There are ways to incentivize the preferred outcomes without supporting the active theft of property and destruction of someone's business.
I get where you're coming from but you can't really just flat out say "you can justify kidnapping with the same logic". Like, no, you can't. Fully agreed the government should be the ones playing the role of incentivizing security, but you can't then go back and say that security takes time and money those companies should not have to spend. They should, regardless of who keeps them accountable for it...
And does anyone really believe the hackers deleted the data off their own servers? They can easily double-dip by selling that information. It's valuable, so why would they delete it?
What should the govt so when govt agencies get hacked?
The kidnapping analogy makes for a better understanding of why paying ransoms is bad for everybody else. If kidnappers know, or really just think, that they’ll get paid, they’re more likely to kidnap and hold hostages.
It’s not that companies are not solely responsible for their own lax security policies. It’s that incentivizing the exploiting of them is bad for society.
I don't think it does. It puts a much more tangible value on security, which encourages businesses to do a risk analysis like 'Do we spend $1m on security every year, or accept that there's a 0.xxx probability of a $4.5m ransom every n years?' That cost base analysis is often used to reduce the value of things that aren't obvious profit centers.
I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?
When I was (a lot) younger, I had a pet theory that the anti-virus companies were making the viruses and that it was a sort of protection racket.
> What makes crime "organised"?
Your answer is:
> Organized crime has a specific meaning
Well... what is it?
But then again, this makes the barrier to entry even higher for newcomers and gives an unfair advantage to the entrenched players. Tragedy of the commons?
If they were to start a consultancy, even if they are as skilled as anyone else, they’d have an uphill battle from the get go; and have to either stick to their home market, or heavily discount their services. Either way making less than from their ransomware.
If you live in the third world, that immediately puts you on the radar of corrupt government officials and organized criminal organizations that want to extort you.
The ransomware gig allows you to stay small and keep a low profile. Nobody has to know that you are raking in the cash until you pack up your family and book it to Tahiti.
> With their current approach they will almost certainly get traced eventually and end up in jail.
Prison in a first world country is a lot better than getting executed, watching your family get executed, or getting kidnapped and forced into slave labor for the local mafia boss.
If your backup process "isn't that simple", then you should make it that simple. Otherwise failure looms.
Particularly this conversation: https://news.ycombinator.com/item?id=23951941
Depends. If they are a couple guys (or a single guy), and it's a one shot for him, he has very good odds of getting away with it. Cleanly launder his BTC and then move somewhere not suspicious and keep a low profile. At the end of the day, $4m is not that much money (ie: not able to afford multiple Ferraris).
Perhaps the key to ending ransomware is some high profile attacks (real or fictional) where the victim pays but does not get their data back.
Could governments outlaw these ransom payments?
You'd likely still see US companies pay the ransom anyway, but just try to keep it secret. Probably less risky than losing their crucial data and systems.