Ban All Ransomware Payments, in Bitcoin or Otherwise
coindesk.com
coindesk.com
Literally every program I saw recommended when setting up my environment was available from download sites like FileHippo and Softpedia. Here's the second download link for "AutoHotkey" on google: https://autohotkey.en.uptodown.com/windows - wtf is uptodown? They even train you to get used to that classic subdomain spam that malicious websites use. Another example were various driver tweaks/hacks or anything else a gamer or power user might want to do. Always from a shady mirror website that trains you to run .exes from any website that shows up in search.
It was a breath of fresh air to get WSL + Debian up and running on Windows so I could rely on apt-get.
The Microsoft Store is surprisingly bad, not having anything you're looking for, but plenty of apps that claim to be that thing or would confuse people who don't know any better.
Normal users are really being let down from a security standpoint in computing, in general.
macOS has similar issues with websites like macupdate.com, but it's slightly farther along with its much more compelling app store library. My girlfriend is a UX professional and the only few apps she uses outside of the app store is Chrome and Sketch. It definitely feels like this approach is moving in the right direction that can satisfy most people and power users as well.
And for completeness, I would think a GUI over linux repos like Synaptic is also nice for normal users. I have one not-so-technical friend on Linux Mint where I saw them using whichever GUI to grab packages.
When something that was written by a single person, and maybe had half a dozen users at the very most, gets an illegitimate mirror, how can anything larger stand a hope?
I upgraded the firmware on a hardly-used Lexmark printer, which promptly blocked me from printing as my original cartridge was old — a DRM failure.
I think it was Softpedia where I found the older firmware and was able to downgrade.
I'd like to be in a position where I can recommend specific sites as safe and reliable, specifically when giving recommendations to less technically adept family/friends. However, with how quickly those reputations become stale (e.g. Sourceforge being bought out, then immediately burning its reputation by adding malware to downloads), that's not something that really can be done without coupling to a hardware ecosystem as well.
When it comes right down to it, I prefer the Windows convention of installers and zips to package management and all its limitations. Precisely because things like "Another example were various driver tweaks/hacks or anything else a gamer or power user might want to do." are easily available with that model. Distributing software on Windows is something anyone can do very easily, without relying on a third party package repo or maintainer.
However, what we should really be doing, in my opinion, is something like AppImage (or NeXT Application Directories , or RiscOS AppDirs, etc.) combined with a sandbox-by-default similar to what exists on mobile, but without pops or the ability for the application to tell when it has been denied a permission.
Is that so? Last time I checked you had to choose between 3 installation approaches and then choose a 3rd party installer (all of which have bad UX) and set that up.
Fragmentation exists on Windows too, it's just internal.
> However, what we should really be doing, in my opinion, is something like AppImage (or NeXT Application Directories , or RiscOS AppDirs, etc.) combined with a sandbox-by-default similar to what exists on mobile, but without pops or the ability for the application to tell when it has been denied a permission.
You're probably taking about Flatpak and Snap. One has great marketing but is not usable for ethical/practical concerns while I haven't had a very good experience with with Flatpak (its "runtimes" are basically extra Linux distributions).
Due to the convention of not relying on fixed-paths in Windows software, as well as Windows providing a stable base platform of common libraries, pretty much anyone can just compile a program and put it and its resources into a zip file. The vast majority of the software I install is distributed this way.
> Fragmentation exists on Windows too, it's just internal.
The fragmentation of Windows is orders of magnitude less than Linux. I can write software today that will work without modification even on versions of windows from 15 years ago without recompilation[0]. Occasionally there are minor incompatibilities between Windows versions and editions, but it isn't that way for most software.
> You're probably taking about Flatpak and Snap. One has great marketing but is not usable for ethical/practical concerns while I haven't had a very good experience with with Flatpak (its "runtimes" are basically extra Linux distributions).
No, I'm not. In my opinion Flatpak and Snap combine the worst of both worlds in that they still require repos and a special tool to manage them. I meant exactly what I said: AppDirs with default sandboxing.
[0] Hell, thanks to WINE it will probably even work on Linux without recompilation.
On the other hand if my Windows app is complete in and of itself, but depends on a library which requires security updates, I will have to continuously release and distribute updates to it for the next 15 years (or however long it remains useful) even though the app itself is not changing.
I'm currently working on a Windows plugin for an app, which requires linking to a ~20MB library, and also another library which in turn links to that same ~20MB library, but using an incompatible linker. The plugin is also for an application that uses that ~20MB library, distributed separately, and in turn many users install a standalone version of that library to use alongside the program. That's 4 copies of the library just for one application on Windows, and this library is common and most likely also distributed with many other apps on most users PCs. All of them will need separate updates.
Only if that library is not part of the base Windows platform, which already supplies a whole lot of things you'd typically need, cryptographic functions among them.
So yeah, if you depend on things that aren't part of the base platform it is your responsibility to update them. Or, and this is equally imporntant, not update them if doing so breaks your application. If you only depend on the platform then you don't really need to worry about it except in the rare case of an ABI break.
By contrast, breaking user space ABI on Linux is tradition, and there isn't really any such thing as a stable and consistent set of libraries you can depend on as a platform because of the ludicrous level of fragmentation.
> I'm currently working on a Windows plugin for an app, which requires linking to a ~20MB library, and also another library which in turn links to that same ~20MB library, but using an incompatible linker. The plugin is also for an application that uses that ~20MB library, distributed separately, and in turn many users install a standalone version of that library to use alongside the program. That's 4 copies of the library just for one application on Windows, and this library is common and most likely also distributed with many other apps on most users PCs. All of them will need separate updates.
I'm curious what this library could be. At that size and level of commonness, I can only imagine that it is Qt or GTK, or some other "portable" platform layer.
This is true but for apps where source code is available, it doesn't seem like that much of an impediment to keeping things working. I use various tools that haven't been updated for many years but have been easy to keep working as Linux userspace has changed. For closed-source things indeed it's different.
>I'm curious what this library could be.
The example was ffmpeg. You're right that there probably aren't that many examples of common libraries of that size. But Qt is a good example and why shouldn't it be reasonable to use it and not have a burden placed on me to provide security updates? If I am writing an app and want to use something like libcurl, I would prefer not to have the onus placed on me to monitor and distribute libcurl security updates for the rest of my life, especially if this is just a hobby project. Suddenly I am taking on the role and responsibility akin to a whole Linux distribution, and all because I wanted to write some silly little app.
And even if I am that responsible, I as a user have to count on all the developers of apps I'm using to be just as responsible themselves. I mostly have no way to know whether they are, unlike the situation for example as a Debian user where they have a known track record and I can have some level of confidence.
Closed source or unmaintained. Setting up build environments is such a chore with a high probability of conflict that people often use docker containers for it. On top of that, compiling unmaintained older software yourself often requires enough knowledge to dig into the code and correctly fix the errors that have been introduced by API changes. Personally, I find it easier to try and get old binaries working instead.
Besides, closed source software not only exists, but also describes some of the most popular professional tools in existence.
> The example was ffmpeg. You're right that there probably aren't that many examples of common libraries of that size. But Qt is a good example and why shouldn't it be reasonable to use it and not have a burden placed on me to provide security updates?
Windows provides both its own media and GUI layers. I don't see why Windows should be expected to maintain any alternatives people choose to use.
> If I am writing an app and want to use something like libcurl, I would prefer not to have the onus placed on me to monitor and distribute libcurl security updates for the rest of my life, especially if this is just a hobby project. Suddenly I am taking on the role and responsibility akin to a whole Linux distribution, and all because I wanted to write some silly little app.
Your choices as a developer have consequences! Windows has its own APIs for this. If you don't want the burden of maintaining a non-platform dependency then don't use one. If it is "just a hobby project" and you don't want to update your dependencies then just don't. The alternative is being beholden to third party volunteers to keep your software both available and working.
Yes and using the Windows APIs in any meaningful way requires the user to install a ffmpeg-based backend for it anyway (LAVFilters) as it is insufficient in and of itself. And even this leads to problems often enough that media players seem to bundle their own version of LAVFilters anyway (defeating the purpose of using the API...at this point why not just use ffmpeg directly?) and forego using the globally installed ones.
Unless the system APIs can cover every use case that a software could need a library for, and do it just as well as the commonly used standard, I think the fact that there are some Windows APIs for some of these things is kind of beside the point. This dependency problem will still rear its head at some point.
I had a Windows user loudly say this in a room while I was in it. It's true Microsoft does a reasonable job of keeping one programs working. Not perfect, I've had many stand alone programs fail to run in "compatibility mode". It's a commendable effort nonetheless.
But in contrast, Linus has kept his "don't break userspace" promise damned near perfectly. So upon hearing someone claim yet again how much better Windows does this than Linux, laptop running some 2020 debian stable and a 64 bit Linux kernel, download Debian potato (circa 2000) and expand to a directory on machine running the latest Linux 64 (potato is 32 bit only), chrooted into it, apt install whatever, and showed him it all just works. I could do that with any distribution on my modern Debian laptop.
Yes, because Linus gets it. The people behind the userspace of desktop Linux really really don't though. If I want to write a Linux program that will work in 20 years without recompilation I can only depend on the kernel. Case in point:
> download Debian potato (circa 2000) and expand to a directory on machine running the latest Linux 64 (potato is 32 bit only), chrooted into it, apt install whatever, and showed him it all just works.
You basically had to swap out the entire userspace to do that because ABI compatibility outside of the kernel is practically nonexistant.
Bit of a stretch. Most simple tools I'm aware of do not require elevation, or even installation for that matter. That said, a lot of tools do insist on elevation even when it is unnecessary.
I agree with the overall point: Mac does it better with Application Directories. You don't even need to drag them to the Applications folder, they run anywhere including off of removable media.
"Because packages in the Snap Store are maintained by developers themselves, distribution maintainers cannot ensure packages meet quality standards and are timely updated."
It's an alternative android store https://en.uptodown.com/aboutus/uptodown
>Another example were various driver tweaks/hacks or anything else a gamer or power user might want to do.
Never saw a driver hack a power user might want to do.
What were you using Linux/macOS on if not a PC?
https://gru.gq/2020/10/18/ransomware-prohibition/
"The current situation, where there is no criminalisation of payment has created a market place where a number of companies working with insurers are handling the vast majority of ransomware incidents. There are crisis responders who help the companies recover, who arrange a minimal payment, and who get paid by the insurers. This is market governance and it keeps the prices down because there is a sort of gentlemen’s agreement between the gangs and the payment companies. Also, the lack of prohibition means these companies operate in the open and they can share information about pricing etc internally and with each other. (Transparency)
The status quo is not the ideal world, but it is far better than the nightmare of ineffective partial prohibition."
This will have the effect of reducing the number of cases of ransomware that law enforcement sees. Not by actually reducing the cases, but instead by making it untenable for a victim to notify law enforcement.
<rant>This is unfettered metric fetishization -- the idea that a problem can be quantified as a metric and when the metric is reduced the problem is reduced. The map is not the territory, you can't just look for your keys where the light is good, the bed of Procrustes, etc. Or maybe it has nothing to do with this and is just a well-intentioned but stupid idea.</rant>
What's new here is a new type of criminalization and an incentive to hide your actions from the government. And if the ransomer is asking $5,000 and the government will fine you $50,000, then you have a good incentive to gamble on never getting caught, and that's already a game corporations play (very successfully) with taxes.
It seems to me that logic only works when attacks are expensive. With something like kidnapping, you couldn't possibly kidnap 1000 people in the hopes of getting a single $10,000 ransom payment.
But with malware, where launching an attack costs almost nothing? Attacks could still be profitable even if only 1 in 1000 victim pay up.
Same as with spam - the simple solution is that spam (mail/email/calls) are charged to the operator/provider - I can assure you that a solution would instantly appear whereby the providers would take great care about blocking spam at its source.
The status quo in both cases is just to "solve" (but not really) the problem with the cheapest, shittiest possible solution.
The scammers can hide, but their bitcoin money can be tracked forever and interacting with the real world in significant sums requires giving up anonymity. It seems very easy for wallets to access a database and alert their user that they're about to purchase tainted bitcoins.
If bitcoin dies because it's only used by thieves, extortionists, and cartels, then it deserves to die. I don't think the majority of transactions are of that sort though.
That's not the point. Any bitcoin coming from these accounts should be poisonous and any account ever receiving coins tracked back to that account should be fined plus repay the bitcoin value (receiving stolen property). is what would destroy bitcoin.
Criminals use a variety of money laundering techniques, such as "tumblers": big buckets where you put in both legitimate and illegal transactions and get back an unidentifiable mix of both. But I'm sure a lot more cleverness is happening.
The network could and should be built to adapt to such potential attacks. Spamming transactions (essentially a ddos attack) should be banned anyway.
Accidental receipt of stolen goods isn't a crime if you immediately turn them over to the police. People could forward all those coins over to a law enforcement account and receive no penalties while the sender would lose money without gaining anything. This too could be automated.
The problem you mention comes up in the other direction - I am a money launderer and I have some bad BTCs. I can use the UTXO system to mix it with good BTCs I control, creating questionable BTCS. This is is why there was recently news of bitcoin mixers being fined: https://cointelegraph.com/news/us-financial-watchdog-fines-e...
Only if these tiny fractions are actually used. When you send something to a Bitcoin address, what you are actually doing is creating an unspent transaction output which can only be spent by that Bitcoin address. Nothing prevents the wallet software from ignoring that tiny fraction and instead using a larger unspent transaction output to the same address, which would result in a smaller transaction (one input instead of two, since the tiny fraction most probably wouldn't be enough for the transaction).
edit: fix wrong link
There needs to be widespread buy-in from many countries at a granular level for it to be particularly successful. Otherwise bitcoin makes it too easy to turn day-trading into laundering.
But how do you get your idea working? The whole point of bitcoin and crypto is that its decentralized. Even if governments bought in, they cant stop individuals
Imagine you try to buy something and are greeted with "The US government has forbidden access to your account due to it containing bitcoin involved in criminal activity. Go to blah.gov to see what you can do to unfreeze your account and try again". You go there and find out you have to turn over X bitcoin to unfreeze your account and maybe get a recommendation to get a wallet app that can alert you before you get bad bitcoin.
After just one time, most people will move to something that makes sure it never happens again which will trickle down into bitcoin to bitcoin transfers too and stop these illegal transfers in their tracks. Extorters will move to other means of payment which will either be easy to track (physical payment or traditional money transfer) or some super-volatile coin where they're very unlikely to get a meaningful payout.
Currently, ransomware operators could just decrypt half your files upon 50% payment, and demand yet another payment for the rest. But they don't. Why? Because they seem to have naturally converged upon honoring their decryption payments in order to maximize total profit. I think if paying the ransom was made more explicitly illegal, the ransomware operators would probably converge on not outing their clients. At least for now.
Or they can threaten to release your information and demand more ransom to keep your information a secret. If you stop paying they'll make it public making what you did illegal.
The difference is obvious: not handing the mugger your money is an immediate threat on your life. You won't die just because you didn't pay a ransomware operator.
> And is it also illegal to pay kidnappers?
The article already answered that: in some countries, it already is. "[...] In response to a wave of kidnappings by organized crime, Italy prohibited ransom payments in 1991. Colombia and Switzerland have also made ransom payments illegal. The Group of Seven has a long-standing policy of refusing to pay ransoms for hostages of terrorist groups."
There are exceptions for Fear for your life situations. Which is why paying a mugger is legal.
In non-sarcastic words, I'm unsure what point your comment is trying to convey.
He's basing his opinion on treasury department decision to (seemingly) ban ransom payments to ransomware groups.
What he seems to be misrepresenting is: treasury department is not banning ransom payments. They are clarifying that payments (including ransom ones) to an entity on sanctioned list is illegal.
How does this translate to the rest of ransom requests seen in society is beyond me.
Are we setting up a precog unit to classify all people and entities in the world as sanctioned/non-sanctioned?
The ransomed company is in the clear. They paid for a legitimate service, it is in the books, taxes paid, all that stuff. They may even really think that they got their data back without a ransom being paid.
Less so for the data recovery company, but they can probably try to justify expenses by hiring "foreign cryptography experts", or doing "security research".
How this author extrapolates this to "let's put the victim of any kidnap/ransom through hell" is beyond me.
How do you even book it in your accounting and taxes? Do the criminals give you an invoice?
Companies aren’t really paying this money by choice, they are paying it because losing systems/data can in some cases result in an inability to operate - otherwise it wouldn’t really be a ransom.
I'd say there should be an exception for ransomeware cases where physical safety is being threatened.
doesn't that incentivise attacks on critical services/systems?
There are answers to these, but it’s inherently a fuzzy area.
Clearly, not the case. That might be an interesting way to naturally limit the size of corporations and their influence; if everyone who fills up their car at a gas station becomes a felon by being a customer.
Yet it seems to scale too low for some purposes. Its the rare restaurant that has never had a minor (or major?) health code violation. Certainly we shouldn't shut down all restaurants?
Maybe the strategy to implement "sons inherit the sins of their fathers" as government policy would be customers inherit one step down from the sins of their corporate retail operator. So a step down from a minor regulatory issue at a local restaurant would be nothing, but a step down from a major felony committing megacorporation would be a misdemeanor ticket violation.
Anyone who is paying a ransom is literally paying a ransomer to do that to someone else. Not in a metaphorical sense. You are literally transferring the ransomer money which the ransomer will literally use to finance the next ransom. They will pay out of pocket for the person doing the next ransom to go and do it. It should be totally illegal to finance this.
You charge your own acquisition cost against the profit from your custom, not the next guys’ cost. In the case of crime you have paid them to hack you, not others.
Implementing a maximum legal payment amount and mandating that all ransomware payments’ TXIDs be reported to law enforcement would be a reasonable compromise in my opinion.
Stop using surveillance coins.
You can send a tornado.cash note to the operator.
You can send Monero.
These are solved problems.
The novelty of the circumstances do change the futile utility of making an announcement about it, as there should be no way of knowing that a ransomware operator is on the OFAC list, and there should be no way of knowing that you paid a ransomware operator that was or was not on the OFAC list.
I don't have an opinion about your question and never addressed it and won't address it, as it is completely moot. As people adopt these technologies for more benign purposes, the peculiarity of using them "when you need to" goes away.