New technology has enabled cyber-crime on an industrial scale
economist.com
economist.com
It is always a temptation for a rich and lazy nation,
To puff and look important and to say: --
"Though we know we should defeat you,
we have not the time to meet you.
We will therefore pay you cash to go away."
And that is called paying the Dane-geld;
But we've proved it again and again,
That if once you have paid him the Dane-geld
You never get rid of the Dane.
It is wrong to put temptation in the path of any nation,
For fear they should succumb and go astray;
So when you are requested to pay up or be molested,
You will find it better policy to say: --
"We never pay any-one Dane-geld,
No matter how trifling the cost;
For the end of that game is oppression and shame,
And the nation that pays it is lost!"
https://www.poetryloverspage.com/poets/kipling/dane_geld.htm...We've known for hundreds (thousands?) of years that paying ransom only encourages more demands for ransom in the future. The solution to this is backups and improved security. I know that's expensive. Pay that cost now or continue paying more dane-geld proving over and over again that you are a mark that will pay.
> or, increasingly, to prevent them from being leaked
Why did high-risk data exist in the first place? Maybe stop gathering so much risky data.
You could invest a ton into security, have a competent security team, follow best practices, set up lots of security appliances and software, have lots of analysts monitoring and responding to alerts and actively hunting for threats and writing custom SIEM rules etc., and there could still be one small mistake that lets a sophisticated attacker in.
As the adage goes, the defenders have to win every time and the attackers only have to win once. A group of sufficiently motivated, dedicated, resourceful, and talented attackers who face zero risk of any sort of repercussions will very likely get in if they put enough time and effort into it.
This isn't just old-school ransomware that merely tries to infect as many computers as possible in general and just happens to land on a corporate machine and automatically spreads from there. These are trained, experienced red teams manually targeting companies and everyone who works at them. In many cases the victims do indeed have poor security, but a company doesn't necessarily need to have poor security to fall victim to ransomware.
Which is what exactly? Speculation? And...
1. Store any amount of money easily and securely
2. Transact quickly, easily, cheaply, globally, limitlessly
3. Nobody knows your balance
4. Nobody knows transaction amounts, senders, receivers, history
5. Nobody knows about anything you do
6. Nobody can randomly freeze your assets
7. Nobody can move those coins without the key
Have you ever had your money taken away from you? My country suffered through hyperinflation in the 90s, the government got desperate and just froze the bank accounts of everybody. The amount of disruption this caused is legendary.It doesn't matter how much energy it consumes or how much crime it enables. If it allows us to escape government stupidity it's more than worth it.
It’s like replacing the local police with the Sicilians. They even have a comparable customer service policy, i.e. SFYL.
[1] https://ag.ny.gov/sites/default/files/2021.02.17_-_settlemen...
Monero currently has all of these properties.
> You get to escape government stupidity into the open arms of criminals and scammers.
This is does not justify sacrificing everybody's financial privacy and independence. The police should track the criminals via other methods. They shouldn't be able to surveil everybody's transactions at all times or freeze people's accounts over the slightest suspicions until they prove their innocence. It's better to let some criminals escape than suffer these injustices.
Agree to disagree haha. Financial records are private unless revealed to authorities in a 4th-amendment compliant probable-caused based warrant. Seems like the right place to draw the line.
> The police should track the criminals via other methods.
Why? I mean it's pretty easy with basically every crypto other than Monero, and Monero is basically Narco-dollars, which are unlikely to find any acceptance.
> They shouldn't be able to surveil everybody's transactions at all times or freeze people's accounts over the slightest suspicions until they prove their innocence.
You mean... probable cause? And offer due process to resolve? Some would argue that's the foundation of the criminal justice system.
> It's better to let some criminals escape than suffer these injustices.
You're just subbing one kind of criminal for another.
Of course the correct answer for everyone, in the long term, is to have backups and not pay.
Backups aren't necessarily enough. Sure, a lot of companies don't backup. And sure, a lot of companies backup but keep the backups on network shares that the ransomware can reach and encrypt. And sure, a lot of companies keep isolated backups which aren't encrypted, but which are missing the past few days of production data.
But even if you have a perfect backup solution up to the minute before the attack occurred, you'll still be coerced to pay. These ransomware operators are general extortionists - they manually target specific companies and come up with the most impactful threats to pressure you to pay.
They screenshot all of the sensitive documents, emails, IMs, trade secrets, and PII they've gathered and say they'll post it online and mail it to every local, regional, and national press outlet, every company you partner with, and every customer email they've harvested. (And they do indeed make good on this threat if you don't pay by a deadline.) They call all your executives every hour of every day and target their personal devices. They might SWAT your executives' houses.
If you don't have backups, the overall, reputational, and financial cost is probably way higher than the ransom payment. But even if you do, it still might be higher than the ransom payment. Even if you really want to take the moral high ground and inform your customers, partners, and the media of your choice and that you won't negotiate with terrorists or whatever, all of the damage (especially to your reputation and trust) may still be so extreme that you have to shutter your company.
I don't think you can fault someone for paying the ransom when they're being explicitly targeted by sophisticated attackers and when so much is at stake.
If people like him are telling you to pay, then people are going to pay, which will just create more and more and more attacks.
The attitude that people who are hacked should have taken better precautions and should fend for themselves is a big part of what makes us soft targets to cybercrime. Imagine if we treated murder this way. "Oh, sure, he was killed, but he was walking down the wrong street at the wrong time of day. He should have known better! Let's start an educational initiative to make sure other people know what streets they shouldn't walk down at night!"
We must expect the state to do a competent job of protecting citizens from cybercrime but, in most jurisdictions, governments do not devote adequate resources to this task. That needs to change.
New technology and inadequate response from governments is what has created this bonanza for a new kind of criminal.
Also imagine how well this would go - your child was kidnapped, but now you have to go to prison because you had the gall to make sure they go home safe.
Like, I get your point, but it's one of those armchair social science ideas that can go into a cabinet full of really cool and really obvious ideas that won't ever be implemented in reality.
So if the choice is presented as "do I not pay the ransom to reduce the chance of further kidnappings by some completely undefined %, or have my child harmed with nearly 99% certainty", who could ever chose not to pay it? What sort of mind gymnastics would you go through to justify not paying it in that case?
It’s like pollution or recycling. Why spend the effort and cost to do it if the benefit is only to future generations or society as a whole (ignoring the few who do it for their own sense of self-satisfaction)? That’s why we have things like penalties for pollution and carbon credits.
These people are externalizing the cost of their actions. At the very least we shouldn’t allow ransom payers to externalize the real cost of the ransoms to future generations and society as a whole.
Making ransom payments super illegal wouldn't stop them from being made. People(parents in particular) would absolutely try to find a way to pay the ransom anyway to save their children, no matter the consequences. Like I said in another comment - what kind of punishment would stop the parent of a child in danger from paying the ransom? Years in prison? Most parents would gladly make that trade to make sure their kid goes home. There isn't a punishment here that you can establish to absolutely eliminate ransom payments, and as I'm sure you can see - as long as *any" are paid, criminals will keep using them as a tool. So imho, any effort(and therefore money) spent on fighting the ransom payers is completely wasted time and money. Not paying a ransom does not reduce the chance of further kidnappings significantly enough to make it worth it, and I'm nearly certain you can't come up with a punishment harsh enough to scare people away from making the payments.
You can read what I wrote here about teh great firewall. https://news.ycombinator.com/item?id=27103646
"No more drugs" is not the goal, neither is "no more ransoms." The goal is to reduce the reward for ransoms so that it is disincentivized to some degree.
If our disagreement is on how to stop X to an absolute degree, then I would agree with you for all Xs that it would be impossible, whether X be ransoms or logical fallacies.
Come on. You would really make that decision if your child were kidnapped?
Also I'm not sure how the fine would even be decided to be effective? 3 years in prison? Would absolutely gladly trade it for the life of my child. Probably any amount of time in prison would be spent gladly in order to save your child. And once we start throwing ideas like life imprisonment(because really, can't go much higher than that) it would be struck down as not proportionate to the crime.
By this logic the Great Firewall of China is a massive failure because some guy, somewhere, was able to access illegal content from China. But that's not the case. It works quite well to control public opinion and it doesn't have to be 100% effective at blocking content to do so.
The same applies to disincentives to ransoms. Of course some people will still pay ransoms. But why let criminals have a monopoly on the market? The total ransom someone can pay is fixed by the market (basically how much your child is worth to you and how much money you even have, otherwise there'd be no ceiling on ransoms). Since the government is in on the action, the revenue from ransoms is split between fines/jail time/criminals. If the government's actions are decided ahead of time, and cannot be changed based on any single ransom attempt, then kidnappers will know that their potential income from ransoms will be severely cut, thereby disincentivizing ransoms by some degree. The degree to which it is disincentivized depends on how good of a competitor the government is in the market (enforcement/detection of ransom paying events).
> Also I'm not sure how the fine would even be decided to be effective? 3 years in prison? Would absolutely gladly trade it for the life of my child. Probably any amount of time in prison would be spent gladly in order to save your child. And once we start throwing ideas like life imprisonment(because really, can't go much higher than that) it would be struck down as not proportionate to the crime.
These are implementation details. If there is no ceiling to what you will pay/rob/steal/do then don't let the kidnappers out there know! But also, you'd be a massive liability to society assuming other people don't care about your kid as much as you do, since criminals can leverage you to a 100% degree. If they know this about you, they don't even have to estimate your net worth. They can get you to go rob a bank instead!
Which are what a plan is made of. If you live in a democracy and not a dictatorship, you have about a 0.0002% chance of keeping the parents of a kidnapped, murdered child in jail for more than a day for the crime of "attempted ransom paying" without you and your family becoming pariahs and being screamed at in public places, and your political party being annihilated from politics even after press releasing your expulsion.
It's not just the parents that would have to sacrifice.
I think you're right that imprisoning people for paying ransoms would probably decrease the probability that a victim would pay a ransom. And imprisoning people for blasphemy would probably decrease the probability that someone would take Jesus's name in vain. But I'm not sure how useful it is to discuss things like this. (And, for the record, I also think it's unconscionable that the US imprisons people for simply using drugs.)
And then there's the question of overall efficacy: it disincentivizes a lot of potential drug use, but does it also disincentivize drug sales? Does banning drug possession decrease the amount of drugs sold? I don't know. They could always just try to sell to more people than they otherwise would have.
Similarly, ransomers could just go for more of a spray-and-pray approach and ransom more victims per unit time to offset the fact that there's a lower probability that any one victim would pay. They could also hike up ransom prices to offset it, so that each victim is hurt more even if there may possibly be fewer total victims.
I think even if it did objectively, inarguably decrease the amount of ransoms - which I acknowledge is plausible - it'd still be completely unethical and an extremely terrible idea. But I'm not even sure if it would. We aren't exactly winning the War on Drugs by penalizing drug use, and I'm not convinced we're going to win the War on Ransomware by penalizing ransom payments. And even if we could win both those wars that way, I think it'd still be really fucked up and major governmental overreach.
There are a lot of issues with this idea, too, but I'd be more sympathetic to the ideas some others have suggested in this thread: bring back letters of marque and reprisal and provide some legal structure for American/European citizens to target international cybercriminals in certain countries and perhaps also take money from them and keep a percentage of the proceeds, etc. I'd be way more in favor of vigilante justice against perpetrators as a remedy compared to draconian punishments against victims. These people currently face absolutely no repercussions, so adding some repercussions may help deter them.
These situations involve complicated moral dilemmas, but thought experiments never take into account all possibilities, and at some point idealistic principles about the general problem have to give way to pragmatism about the immediate problem.
To give an extreme example, if someone had a button they could push that would end the world as we know it, and they demanded you pay them $1B or they'd push it, are you really going to argue that paying that billion dollars is the incorrect response because it would encourage future people with the ability to end the world as we know it to demand ransoms?
Well he wouldn't have been kidnapped in the first place if we disincentivized ransoms!
> To give an extreme example, if someone had a button they could push that would end the world as we know it, and they demanded you pay them $1B or they'd push it, are you really going to argue that paying that billion dollars is the incorrect response because it would encourage future people with the ability to end the world as we know it to demand ransoms?
Your example is indeed extreme. It posits a game with 2 players, the world, and the entity trying to end the world. In a 2-player scenario where you lose if you don't do some requested action then you would have no choice but to do it. However, in an n-player scenario where n > 2 and player "x" being the one wanting to win by ending the world, and assuming all other players can win by cooperating, then yes the world government should indeed forbid all players from paying the $1B ransom.
It's a well established fact that if ransom demanders know that ransom payers are subject to significant fines and penalties, their power to demand ransoms drastically diminishes.
This is a bizarre and emotive discussion, so I'm not sure how much more it's worth saying, but I will leave you with one final question. What law could you possibly make and what "severe criminal penalty" could you possibly impose that would be greater than the natural law that parents would do almost anything to protect their children and what a parent would suffer if they lost a child? I don't believe anyone could ever implement the policy you've been advocating effectively, and at that point, the entire deterrent argument collapses anyway.
Can't collect in cash? That's a-ok. Do me a favor and you get your kid back.
You are not talking a lick of sense. Crime finds a way. It always will. You can't tax law abiding people to invalidate criminal economic models. All you do us disadvantage the victims, undermine the legitimacy of your legal edifice by implicitly raising it above those it serves in importance, and completely do away with any semblance of sanity, and maximize tge cost in human lives exacted from the pool of the falsely accused and victimized. Game theory doesn't apply. Rational Actor Theory doesn't apply. Addressing crime via draconian laws doesn't work if you're at all interested in any State even nominally centered around the concepts of Freedom and Liberty.
And a Ransom tax? Do you want tax collectors tarred and feathered? Or are you just trying to ensure that any remaining credibility in the government is irrevocably lost? Taxes lend legitimacy to things. You're basically admitting that a ransom is even a valid transaction by enshrining it in your tax code.
Absolute madness.
They often are taken seriously. The problem is most of the ransomware gangs operate out of Russia, and Russian law enforcement permits the activity if Russian citizens aren't targeted. (There may be a short blacklist for citizens of some other countries allied with Russia, as well, but targeting and profiting from citizens and companies in America and Western Europe is explicitly allowed.)
If you're the FBI, there's absolutely nothing you can do about that if the ransomware operators never leave the country. You can try to lure them out of the country - and this does happen sometimes - but if they're smart enough to never leave, they're basically immune to all repercussions.
The Justice Department can publicly indict them, and they sometimes do, but they're just going to laugh at it; it simply increases their street cred and respect among their peers. "I'm on the FBI's Most Wanted lol." You can go after the infrastructure, but as long as the people involved are allowed to operate freely and continue to have lucrative incentivizes, it's only a minor annoyance at most.
This kind of punishing of victims is draconian, unethical, and, in my opinion, basically insane, in addition to being impractical and very difficult to enforce. In some cases the victim's negligence is largely to blame, but sometimes it isn't.
And even when they are negligent, I think threatening to imprison them for paying a ransom in order to remedy something that may upturn their entire life and cost them far more (financially and otherwise) than not paying is just ridiculous.
There should be some kind of accountability and regulation for negligence, and any company that's hit with a ransomware attack should be legally required to report the attack to authorities and disclose it to their customers, but I don't think you can or should punish people for paying ransoms. You should try to punish the ransomers, and the people who obstruct punishment and shield the ransomers (like countries whose law enforcement permits the attacks and extortion and whose financial industry permits the payment handling).
Cybercrime isn't so much crime as a basic reality of these systems. The level of policing we'd need is a ridiculously high cost in comparison to improving the public infrastructure that is computer security.
The specific problem with the murder analogy is that governments have effective ways to reduce local crime. You can't do anything similar for stuff happening on the internet. Criminals come from all over the world.
Even if you can get every government to agree, not all of them have the resource to implement any effective form of deterrence. It also seems like the solution will be way worse than the problem. You either firewall yourself off from the world (what china does) or add so much spying that you can always catch the "bad guys". I can't think of any other solution. If we want a free internet, we just have to accept some are going to abuse their freedom to do bad things and deal with it.
Extradition for murderers is incredibly common, as are cross-boarder fraud investigations (look at the case of Frank Abagnale) so tracking down people internationally isn't a new thing.
It would probably hamper script kiddies, but it's not going to do much in the face of a targeted attack. And even a semi-motivated script kiddie could probably buy a service from a botnet to route their traffic onto the secure network.
There's nothing inherently wrong with that. It is a fact that violence often can be avoided. This doesn't absolve the criminals of their guilt but it does mean people can learn to recognize danger signs and avoid many instances of violence. When faced with warning signs that a situation is developing, a lot of people feel like something is a bit off but they proceed anyway because they think they're just being paranoid.
Punishing people after the fact does nearly nothing to help victims. It doesn't undo any trauma, it doesn't bring the dead back. Avoiding violence is always the best option if possible.
Just what government response would be appropriate here. From where I sit, government already meddles way too much in this area.
"Oh, sure, he was killed, but he was walking down the wrong street at the wrong time of day."
It is an odd comparison, but also very apt. You are at fault for walking South Side Chicago, while waving wads of hundred dollar bills looking like a mark. Just because it is illegal to take from you, does not mean it is not stupid to flaunt your idiocy around.
In the aggregate, there may be more money being siphoned off businesses by offering "protection" as a service than from ransom demands.
Many small and weak nations are barely clinging on for survival by any means necessary - they cannot afford to not pay Dane-geld, and I think they'd appreciate not being mocked as a weakling by someone born to the British Empire.
Copper for the craftsman cunning at his trade."
"Good!" said the Baron, sitting in his hall,
"But Iron -- Cold Iron -- is master of them all."
https://www.poetryloverspage.com/poets/kipling/cold_iron.htm...
But then we could argue ransomware is just going to bolster and make our systems antifragile and resilient against such attacks in the future, so the ransomware attacks could backfire since in the future it would be much harder to attack the US for example with other types of malware.
It also means people are going to be storing mission critical and crown-jewels type data in airgapped systems and making filesystems read-only. The data would also be encrypted and compartmented into separate containers so attacks can't affect the whole filesystem if the airgap was breached.
Thank you ransomware authors for forcing people to have better security!
There's a kind of product life cycle where people build tough robust systems with state-of-the-art technology, then those become dominant to the point where it seems superfluous, and people see opportunity in reducing inefficiency, overengineering etc., and adding new and genuinely beneficial features instead.
Interesting. Can you give an example that happening over the large scale in some non-military field?
As the network gets more dangerous, old mechanisms aren’t safe to operate, so you transition to a cloud file solition.
The question is if actual ransomware may be politically-motivated, e.g. if the big ransomware gangs are being encouraged by the Russian security services to generally disrupt other countries' businesses and infrastructure for geopolitical reasons. NotPetya doesn't help answer that question; it just shows the Russian government does sometimes disrupt other countries' infrastructure.
Game theory-wise, though, a ransomware operator knows that a victim won't pay in the first place if they have credible reason to believe the ransomer won't stay true to their word.
My understanding is that most of them genuinely want to maintain a reputation of honesty (like old-school pirates who would hold ships/items/people for ransom), despite the obvious immorality of what they're doing. In some cases this is partly due to a code of ethics/honor (like old pirate codes), but in general it's because their goal is profit, and total profit can be impacted if many victims don't believe there's any point to paying the ransom.
You can see an interesting interview with a ransomware operator here: https://news.ycombinator.com/item?id=27097061
Also why don't we talk about tax havens while we're at it?
If anything, we need more tax havens.
I would move my money to one if I could reap the benefits and I suspect people hate them only because they're not able to also do the same thing.
There are many reasons why someone might want to live in a place, despite the state there.
The state and the country/state/city/whatever are different things.
https://news.ycombinator.com/newsguidelines.html
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...
Also, can you say I'm not being swindled if I'm spending nearly half my income on taxes?
The infrastructure argument is moot, too. Just look at US infrastructure crumbling to bits.
This is more of an intrinsic flaw of humanity than something that has an easy fix. Reality and the version in our minds don't align. Privatization isn't the answer: private companies let their infrastructure deteriorate to the point where it kills people all the time. We even rely on the government to prevent this, and get upset when they don't catch every case. Making the government go away, or underfunding it to the point where it's impotent, probably isn't the fix.
There isn't really an easy answer to society's problems. If there was, we'd have already implemented it. Now we have to deal with the hard problems, and we probably have to do that as a collective. The problem is too large for one benevolent visionary to magically solve.
Something that I think of one of HN's blindspots is the general inability to think past what one person can do alone. We sit in front of our computers and make stuff, then we go to work and make stuff that's almost the same, but it takes 10 people to do only 10% more. That's probably another intrinsic reality of the Universe -- to do a project twice as difficult takes maybe 10 times or 100 times as many resources. That's because communication scales poorly, like n! That's why every successful project management book tells you to cut scope; doing a harder project involves adding more resources, and adding more people to the project has dramatically diminishing returns. But the government can't cut scope, so they have to bear this communications cost. It looks like inefficiency, but it's more like an immutable law.
Keep this in mind while you pontificate about how having a society is akin to robbery.
"Sure the guy murdered a lot of children with poison, but let's not forget he also was the best ice cream maker in the neighborhood."
Are you comparing taxes to murdering children with poison and roads you drive on and schooling that you get to ice-cream? That is a bit of an oversimplification, don't you think?
This is a response to one possible reading of your comment.
The world's problems are well-documented and fighting technological progress is a waste of time. We need capable law makers and regulatory bodies. None seem fit to the task.
The music industry railed against stuff like Napster and got literally nowhere in the grand scheme of things.
We are watching a repeat of history and apparently nobody learned a thing the first time.
Mostly due to superior products coming out (Rdio, Spotify) but given that a founder of Spotify was involved in the torrent community, don’t think it’s a crazy theory to say the legal pressure created product pressure.
The difference here is that TSLA is already accepting Bitcoin, and the financial sector is already building on Ethereum. So is it really going to be illegal or are there just going to be smoother experiences layered on top that the average user will flock to? Because I'm guessing, based on where we are, that it has to be the latter at this point.
Illegal use will be minimized by a new breed of middleman. It's not ideal, but it's right for the majority of people I think.
the Public simply is unwilling to pay $20 for a CD that maybe has 1 good song on it any more.
Other entertainment has been better able to resist this, those COVID has dealt a much needed blow to the value of Movies it is yet to be seen if this industry will recover.
Unauthorized distribution of non-music media is still very much alive and more popular than ever really. It is also becoming more popular since unlike the music industry the video industry is creating 10's even 100's of walled gardens, that are IP and Geographically locked to hold on to old outdated distribution models
I know many people that are growing tired of the "Which streaming service has the show or movie I want" which question that changes on a monthly basis, a Netflix may have it today, but Prime may have it tomorrow, then Hulu may get it later, as it leaves each of these platforms.
Most people subscribe to a single music service, however today you need to sign up to 3 or 4 or 5 Video services, that will drive more people back to unauthorized sources that are more convenient
Maybe it’ll be something similar where government or bank backed crypto becomes the only legal crypto, pushing what’s left even more to the margins.
Stopping crypto just seems like it would take pols committed to taking action:
* Attack mining nodes using cyber + military force
* Disallow transactions between USD + crypto in the US/Europe/Any other country that is willing to join or can be leaned on
On the other hand, as soon as you interact with money, there are well-established means to control money flows. If the banking system stop interacting with crypto exchanges, much like they're banned from serving cartels or countries under embargo, cryptocurrency will essentially go back to the fringe status it had a few years ago.
Sure, some people may still use it to buy pizzas. But it will essentially lose its interest when it comes to unregulated banking.
That kind of regulation may actually be a good thing when it comes to blockchain operations, or at least the few of them that can actually demonstrate a benefit in isolation.
For almost every other application, real money is more useable, convenient and reliable.
For others, I think it's totally untrue even from the start. It's actually usually a lot easier to launder USD than it is to launder something like Bitcoin or Ethereum, given every transaction is completely public and traceable.
Given paying with crypto is as easy as a QR scan these days once someone is onboarded, the other claim that you use, convenience, is about to go out the window: see venmo, PayPal, CB integrations. You might not be following the industry much though?
The problem with your approach here is I hear that, and then I think of HSBC opening a branch for the Sinaloa Cartel, laundering absurds amount of money for them, and no one ever going to jail.
If the reason not to use crypto is not to support crime, have you or your friends used HSBC, and did you advocate for them to stop? There are several other banks on this roster as well. Two wrongs != right, but I’m not the one saying stop using fungible USD that has for certain touched crime.
But why would you want to? In most cases, there's simply no benefit to using cryptocurrencies instead of real money.
Even if we could pay for our groceries, clothing, water, electricity, rent/mortgage, taxes, etc. with cryptocurrencies (which, for the most part, we can't) rather than real money, there's no compelling reason to do so.
Adoption reasons (and evidence) are fairly well known and proven in other parts of the globe that don’t have currency safety.
Fwiw Andreas Antonopolous’s content from early 2010s is good for working through this territory.
> The beauty of Bitcoin, from a detective’s point of view, is that the blockchain records all. “If you catch a dealer with drugs and cash on the street, you’ve caught them committing one crime,” Meiklejohn says. “But if you catch people using something like Silk Road, you’ve uncovered their whole criminal history,” she says. “It’s like discovering their books.”
https://www.sciencemag.org/news/2016/03/why-criminals-cant-h...
I like cryptocurrencies, and I also work in information security and malware analysis. I acknowledge ransomware is a massive problem and that ransomware would be stupid to not use cryptocurrency. Technology isn't inherently good or bad; it just is what it is.
I think one of the main sources of the problem here is international law enforcement. The Russian government and security/law enforcement services have a pretty open agreement with cybercriminals: don't target Russian citizens and we won't impact your business. A lot of these organizations are now complementing the ransoms with harassment and blackmail, too, like threatening to release sensitive documents, directly harassing CEOs, etc. And some directly target health care facilities, knowing there'll be more urgency to pay up.
So if you're a Russian citizen, you have carte blanche to steal millions from people around the world, in an organizational structure that mostly resembles a kind of standard office job, with almost no anxiety that it'll ever come back to bite you (as long as you never travel outside of the country).
It reminds me a little of old-school naval piracy and privateering in many ways.
If you're in the US or UK or France or many other places and want to start a lucrative ransomware operation, there's a high chance you'll eventually get caught, so the risk of long-term imprisonment is enough to deter you even if easy millions may tempt you. If you have no moral qualms, great incentives, and nothing to deter you, the possibilities are limitless.
I'm not saying that all countries should extradite - just that they should at least make a good faith effort to cooperate with other countries' law enforcement and stop serious cybercrime like ransomware. Though I can understand why an "underdog" nation-state may want to have good relations with some talented criminals within their borders who they may be able to recruit or order around as needed.
That would be lovely, but I don't subscribe to The Economist.
Some commenters posted non-paywalled links below. Not sure of the legality, but I wish HN would/could automatically replace paywalled article links.
It's not just Russia but anywhere that is outside the reach of US court orders and extradition treaties.
>It's not just Russia but anywhere that is outside the reach of US court orders and extradition treaties.
Indeed. It just so happens that the vast majority of these ransomware gangs operate out of Russia and neighboring states. Probably in part due to the confluence of good technical education options, a huge population, and a government that permits the activity. (Not trying to say anything about Russia or Russians but just its government's policy. If it were the US that had this policy, I'm sure the biggest ransomware gangs would operate in the US, instead.)
Another thing that reminds me of piracy (and also EVE Online piracy, for anyone who's played that game) is the strict adherence to the basic pirate code of honoring ransoms so that future victims will be willing to pay. They're as ruthless as they can be before payment, but if the victim cooperates and pays, then they'll keep their word - they provide the decryption key, don't release any of their data, and mark them to not be targeted in future ransomware campaigns. It's solely about making as much money as possible.
I can't find a source right now and don't know for a fact how many do this, but I know I've read in at least one interview that a ransomware operator at least claimed they did this.
And regardless of what actually happens in reality - in my opinion, the most economically rational choice would be for all ransomware operators to do this (and to punish other ransomware operators who don't). In general, many of them seem to try to maintain a reputation of honesty and integrity, despite the obvious juxtaposition with the very immoral behavior. I wrote more about this here: https://news.ycombinator.com/item?id=27102646
Extradition is not a requirement. France, like Russia, will not extradite its own citizens, but you don't see so many criminal gangs operating out of France.
This is a pretty serious allegation, it might be considered terrorist activity depending on how you exactly define that. Same for attacks that intentionally target other critical infrastructure. Putting human lives at risk makes a very real difference here.
Here's a September 2020 interview with one operator: https://talos-intelligence-site.s3.amazonaws.com/production/...
>The actor appears to have a contradictory code of ethics, portraying a strong disdain for those who attack health care entities while displaying conflicting evidence about whether he targets them himself. This is probably representative of many adversaries engaged in illicit cyber activity.
>Hospitals are considered easy targets, making ransom payments 80 to 90 percent of the time during a ransomware attack.
When easy money's in front of you and there are no deterrents, the sole thing holding you back is your ethics, and given a large enough number of people, some are going to have very little in the way of ethics.
They're so brazen that many don't even care much about privacy. If there are no possible repercussions, why bother trying to conceal yourself?
>During our initial conversations, we shared what we believed to be Aleks’ identity and location based on our own research, which he confirmed.
The only analogy I can think of is if a smaller power constantly harasses a larger powers trade routes. Eventually America gets exhausted because we only know how to win a direct war.
They will exhaust us with this over time and continue building leverage. What are we seriously going to do? Goto war with Russia or China?
One is sanctions against specific individuals, which the US does do. So at least it's harder for them to participate in the international banking system.
And from my understanding, US law enforcement will often try to trick these cybercriminals to travel to a seemingly more neutral country (sometimes areas that are common vacation choices for Russians), where they'll get arrested after arriving. Some of them have gotten nabbed this way - notoriously Alexander Vinnik, the owner of BTC-e and launderer behind the Mt. Gox hack [1], though I'm not sure if he was lured there or just happened to be there. But as long as someone is smart enough to never leave the country, I think they're pretty much untouchable.
General geopolitical pressure and sanctions is probably the only viable option. Keep collecting evidence of the Russian government's permissive stance and bring it to the negotiating table. If enough pressure is exerted, they might eventually relent and actually start cracking down on the big actors.
If they could pressure Russia to permit extradition to the US for serious crimes, that deterrence would probably stop a lot of operations overnight. I doubt that'll ever happen under Putin, though. (And it'd probably be unpopular enough in Russia that I doubt it'll happen under Putin's successors, either.)
[1] https://www.justice.gov/usao-ndca/pr/russian-national-and-bi...
Russian's in general are pushed towards this idea that they want to be a "great power" on the international stage again, that this will fix their problems - it's certainly how Putin actively thinks. Of course it's never made any sense: Russia is huge. Domestically there's nothing it needs internationally to be a wealthy prosperous nation, and all it's problems are internal.
Hence the chaos: to Russian strategic thinking (that 70% isn't just "the people" its far more concentrated amongst the leadership), one way to be a great power is to knock America and the EU down and chaos suits just fine for achieving that.
Warm weather ports is one example
>And before you say cryptocurrency there’s lots of ways Western governments could intervene if they got serious.
I was definitely gonna say "cryptocurrency". I see absolutely no feasible way that any government could enforce things such that the only way a ransom could be paid would be traveling to Russia and paying the ransomers with gold bars.
I severely doubt any Western government is going to try to ban any cryptocurrency - even Monero. And if they try, enforcement will be extremely difficult.
No matter how hard they make it for a victim to pay a ransom or obtain the assets needed to pay a ransom, a sufficiently desperate victim and a sufficiently greedy ransomer will find a way to make it work.
Perhaps it could realistically help a bit if they threatened victims with prison time for paying ransoms, but in my opinion this would be pretty draconian and wrong - like threatening to imprison someone whose child is kidnapped by a cartel if they pay a ransom to prevent the child from being killed.
Sometimes the victims can be blamed for major negligence, but not always. And even when they are negligent, I don't think they should be punished or prevented from recovering their business in such an extreme way.
> Technology isn't inherently good or bad; it just is what it is.
I think we need a new framework for looking at this. All of technology creates different variations of the trolley-problem. So it's like saying: Trolley-company isn't inherently good or bad; it just is what it is.
In most cases we don't even know there is a trolley so we get away by framing it like this but it's deeply problematic IMO.Those who write the history books and get to frame things for the future are always the representatives of the trolley company. But just because we have framed it this way throughout human history by using terms such as good, bad or neutral doesn't help either. I'm not saying that tech is bad I'm saying that saying any insinuation of presenting Tech as neutral from a moral (not legal) pov is problematic. Because if we use this by looking into the past then we must also acknowledge all the medical breakthroughs that were created during WWII. (I'm using a flippant point for purpose of illustrating just how problematic this statement is and we're not gonna find a solution by focusing on Technology because it's above all not a technical problem)
Especially people in security would be well positioned to think about this because of the bird-eye pov and adversarial thought that's required to analyse it. But perhaps it's not enough and we also need to integrate people from other domains (or at least stop being hostile to the social sciences as an "inferior science" ... because this is exactly the place where we don't see the forest because of the trees)
(I totally understand your point, but my understanding is that actually very little of medical significance happened to be learned from the human experimentation conducted by Nazi Germany and Imperial Japan during WWII, if that's what you're referring to. But for the sake of argument we can assume it did result in medical breakthroughs. Or if you're just referring to all the breakthroughs that occurred due to the pressure of the war, then that works, too.)
You're right, it's difficult to consider all technology as objectively neutral. If someone invents a device that lets any random teenager easily and cheaply release an aerosolized neurotoxin into a city center and kill thousands of people, it's hard to steelman the "it's the people, not the technology" argument in that case.
Philosophically, my post wasn't too rigorous or accurate. I think in the case of cryptocurrencies, though, there's enough of a balance of positive and negative that it's foolish to discard and vilify the entire concept, even if there are many uses (e.g. scams) that do deserve the critical reaction. If something has some positive utility to it, those always need to be kept in mind. Otherwise, all the politicians arguing in favor of banning encryption would have a much easier time, for example.
Let me try, though, because I think it's important.
Technology doesn't grow on trees. There are about two ways such a deadly device could be made available to a random teenager:
1. Accidental convergence of unrelated technologies. Somehow, it becomes cheap and easy to acquire a potent neurotoxin (an exotic animal or plant, perhaps?), tools to isolate, clarify and refine it (some toolkit from a chemistry lab?), a refillable spray can, a compressor, protective gear. A random teenager could then, technically, use all these to perform a chemical attack on a budget - if they knew how, and had a will to.
2. Turn-key solution. Somehow designs and makes widely available a device for cheaply release aerosolized neurotoxins.
In the first case, it's hard to blame any individual piece of technology involved. It boils down to the person willing to weaponize them, or one teaching others how to do it. Worth noting is that all the technologies mentioned (except maybe the neurotoxin itself) are already widely and cheaply available, and necessary know-how is part of high school chemistry curriculum - and I don't think anybody sees any real risk in this.
In the second case, the turn-key solution was explicitly designed with malicious intent - designed by someone who knew the end goal. Most likely commissioned by someone else, who also knew the end goal. Also made available to random teenagers by someone who knew what it is. That's at least three people with ill intent, without whom the technology would not exist (or it wouldn't be a threat). It seems to me that in this case, it's also the humans should be the center of focus.
With respect to real, instead of hypothetical, discussions about technological neutrality, I feel the constant focus on technologies and technologists in general is one big flock of red herrings - it exists to deflect the focus from the real problem, the people who commission and use these technologies with malicious intent.
Replace neurotoxin with chemical weapon and this is already a thing — I may be overestimating the industriousness of teenagers, but there is a toxic chemical a motivated teenager can make in two distinct ways using only things found in a normal kitchen.
Thankfully it was a rubbish chemical weapon even when deployed militarily in WW1, but it is a possibility.
easy? hardly. you only hear about the successful ransomware. The twitter btc giveaway scam is way more profitable, harder to detect, and easier than trying to code ransomware. People make 1 btc/day undetectable with giveaway scam
And you're right, there are certain kinds of scams that are possibly more lucrative for way less effort. A lot of these ransomware gangs started years ago when such scams weren't quite so lucrative. I wouldn't be surprised if many are pivoting into cryptocurrency-related scams and heists.
If you're ignoring effort, though, that one Twitter hack with the BTC-doubling scam made about $100k over a few hours, and that was with access to the top accounts on the platform.
According to a random Google search, a ransomware operator makes an average of $300k per company-ransoming. If you're getting 5 companies to pay you an average of that much per week, it's probably more lucrative than any giveaway scam, even if it takes a lot more effort and skill. And if you're getting more than 5 companies per week, it might be more lucrative than almost any kind of scam.
How do I know? Because the Russia is evil mentality. This comes from media in the US and lack of knowledge of History and geopolitics.
Let's take some History lessons:
Who sank the USS Maine? It was probably a false flag operation or the ship sank itself because of gas leak.We know it was not Spain, but it was used as an excuse to enter a war against Spain for taking Cuba and Philippines from them and committing genocide of at least a million people in the Philippines.
Who killed Rasputin? The British Government. Why? Because Rasputin was very influential in making sure Russia did not enter the WWI. Because they wanted Russia to enter they propagated all kinds of lies against him that even today remain and eventually killed him.
Who supported the Volsevisk revolution in Russia? The German Govertment so Russia would abandon WWI as they did after the Lenin coup.
Governments have always supported crimes when they benefited from those crimes, and that has not stopped in modern times.
I asked Reverte, an old war news reported who killed his friends and colleagues: https://en.wikipedia.org/wiki/Arturo_P%C3%A9rez-Reverte
He told me:"Half Russian secret services, half the US secret services"
In today's world, the US Government is behind way more crimes than Russia, because they are 10x or 20x more influential,specially after Berlin Wall's fall. Russia has the GDP of Spain.
The second biggest criminal is China, for the same reason. But US media loves China though.
Now when African activist that oppose a US multinational because gas or oil gets killed. Who do you believe is behind,Russia?
Who do you believe is behind when people is killed protecting the Amazon Jungle against the people that want to plant soy so Chinese pigs(and Chine that eat pigs) could be fed?
Who is behind all the chaos that is in north of Africa today. Who supported the war in Libia that made the Libyan army to infiltrate in all the Sahel.
Who supported the war in Syria? Afghanistan, Iraq.
How is that all those new weapons magically appear out of nothing?
That's the only thing I'm referring to, here; not anything else their current or past governments or any other country's governments have done or are doing.
This new technology also enables a degree of financial privacy that's a fundamental threat to civilization. It's... uhh... significantly less private than cash and (depending on the cryptocurrency used) often less private than bank wire. Never mind.
FTFY
Financial crime is one of those things that becomes less criminal as the scale gets larger or as one approaches influential political circles. Launder a hundred grand for a street drug dealer? Go directly to prison. Launder billions for drug cartels through major banks? You might get a fine and have to apologize.
https://www.buzzfeednews.com/article/anthonycormier/hsbc-mon...
Yes this last part is part whataboutism, but not without reason. 2008 proved that meaningful financial reform is virtually impossible. A riot is the last resort of the powerless.
SOURCE: Routers. https://www.reuters.com/article/us-offshore-wealth/super-ric...
BBC: https://www.bbc.com/news/business-40442595
Forbes: https://www.forbes.com/sites/kenrapoza/2017/09/15/tax-haven-...
Tax havens aren't a party to ransomware. This is just whataboutism.
We can talk about tax havens too, but that's a different conversation for a different time.
All I'm saying is that the way I see it, there's no correlation between wealth and affinity to crime.
Tell me how you, the CFO of a small US city, would send $1M to Russia in 2006?
This does not work for cybercrime. Cyber systems must be designed so that crime cannot happen.
But a large part of the government does not want that level of security built into systems.
Bitcoin transactions are traceable and can often lead you to a real person or organization, but if you're the FBI and you're tracing some Russian resident cashing out some extortion payments at a Russian exchange and transferring that money to their Russian bank account, there's nothing you can do about it.
The vast majority of these ransomware gangs are in Russia and/or neighboring states, so that means you can't really do anything about any of them, besides trying to periodically go after some of their infrastructure in a whack-a-mole manner. You can't actually do anything about the criminals themselves.
(I wrote more about this here: https://news.ycombinator.com/item?id=27096715. Not saying about Russia or its people, of course, and I know there's a lot of anti-Russia writing in the West, but this particular issue of ransomware can definitely be largely blamed on the Russian government's stance of not addressing it as long as Russian citizens aren't targeted.)
Is there anything stopping them? It is my understanding that larger signature rings are always better. Currently it seems to be fixed at 11 signatures. Why not a larger number?
https://www.getmonero.org/resources/moneropedia/ring-size.ht...
The threat is absolutely real, and the total cost might end up being much more than the ransom payment. This happens on a daily basis. You might as well inform people to not pay when a cartel kidnaps their child and holds them for ransom.
A better PSA would be to keep off-site cold-storage backups, secure hot backups as much as you can, abide by the principle of least privilege, keep sensitive materials in as few and secure of places as possible, general network and application security advice, etc. But no matter how much you try to inform people, there'll still be thousands of companies that won't win against organized crime gangs filled with sophisticated, dedicated attackers who are constantly scouring for potential new victims and who know they have no risk of being hampered by any law enforcement organization in the world.
If a company is this incompetent once, it will happen again. Paying a ransom is just giving the company the opportunity to cover it up and collect more PII without punishment or oversight.
They're hoping to game-theoretically reduce ransomware attacks with this policy, but I'm not sure if it'll work. (It might be working to an extent, though, because in the interview I reference in https://news.ycombinator.com/item?id=27097061, the ransomware operator says he's concerned about this policy.)
So what we could see is a situation where Alice kidnaps Bob and tells Carol to pay a ransom; Carol attempts to do so but when she goes to withdraw money from her bank account Dave, her banker, puts a hold on the transaction or even freezes her account if the fact of Bob's kidnapping is widely known.
Bob doesn't make it but Eve, Frank, and Gary tell Carol that his life is a small price to pay for standing up to Alice's terrorism.
But, yeah, otherwise the US can't do much if they are currently in Russia or China.
Some of this is unusual (no gps) but the rest is standard, no? iMessage is e2e encrypted and lots of platforms have disappearing messages.
Ransomware also targets individuals, which typically don't have the knowhow to sanitize their computers. Since our industry is kind of not caring about security wrt consumer goods, they're left to fend for themselves.
This is the case for basically any transactional/accounting system.
If you lose even one day's data, if often would make more sense to pay the ransom than try to reconstruct the transaction flow for that day (or portion of the day) that was lost.
Imagine you restore your backups (taking a whole weekend) but it turns out the ransomware is some kind of kernel-level hack that also patches ls to lie to you about file being there when they aren't (as an over-simplified example). Once you realize this you can switch to another tool and pinpoint where things are going wrong, but now restoration takes twice as long as before plus the farther back you go the more commercially valuable data you lose.
You don't even need to compromise the backup software, as long as it looks like you might have done so.
except maybe that new tech in the information/internet era seem to concentrate power more and more in fewer people. So to me the problem is not the scale but the instability.