Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
Of this $5M, expect $4M to be spent on salaries in the next year or 2, funding 20 person-years of malicious hacking. 20 skilled people paid to hurt the internet instead of building it up. A terrible crime.
This is not how companies actually work. This is a fun “incompetent executive” fantasy that floats around but in real businesses you don’t pocket a huge bonus solely by cutting costs.
You’re gonna have a lot of explaining to do on why that money was being spent in the first place and why it’s not needed now.
We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
First, in many jurisdictions, paying protection money for physical security is illegal.
Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person.
> We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
I submit that oil pipeline operators, hospitals, and large corps are part of that 1%.
However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.
People are quick to conclude that Colonial’s security was “bad.” But do we know that to be true? A sophisticated, potentially state-sponsored organization initiated this attack. The best security in the world is not 100% secure. It might be wise to get the facts before rushing to judgement.
No, that's why we have division of labor. Law enforcement is just another brick in the wall. If a company is already making massive profits from the public by running critical services, why should tax payers fund their lack of diligence? Should we just fund their entire payroll while we're at it?
It's why, I think, such a law wouldn't pass Constitutional review.
If your person is threatened with imminent danger, you have a right to self-defense, we'll even let you commit intentional homicide if the threat is serious enough.
And self-defense also covers your property and livelihood to a lesser extent.
I think it'd be extremely hard to convince courts that this right to self-defense doesn't include negotiating with an attacker. Imagine if it were a crime to toss some money at a mugger and run away, for instance.
https://www.natlawreview.com/article/us-government-warns-com...
There are cases covering a justifiable use of force because intentionally killing or harming a person is illegal, and self-defense is a defense against those charges.
It's normally perfectly legal to pay someone whatever you want. You don't need a defense against something that's not a crime. There's no conflict in paying a ransom, so there's no case law.
Regarding OFAC, as your link points out:
> One issue is that victim organizations are required to check the list of sanctioned entities; however, many times the true identity of the cybercriminals are not known.
I'm guessing there's no case law regarding paying ransoms to SDNs because nobody has an identity they can check.
But do we need case law when OFAC says:
> OFAC will consider a company’s self-initiated, timely and complete report of a ransomware attack to law enforcement to be a significant mitigating factor in determining the enforcement outcome if the situation is determined to have a sanctions nexus.
If someone wanted to make a law against paying ransom, it would be quite novel and courts would have to look for applicable doctrine. I think the doctrine of self-defense would be a roadblock.
If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off.
The government can help coordination by making defecting more costly (with criminal penalties).
not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, but this should be a priority going forward.
Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm.
Three letter agencies have used (and destroyed) companies for unrelated reasons and then left everyone without any recourse. With smaller companies, this happens regularly.
Those governments will have representatives from their lenders, from their investors, from their large clients and so on in them, who will get a lot of details they wouldn't normally get access to.
This is not happening.
Good luck guessing that password. I'm not even German.
What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice OSHA safety guidelines will get in major trouble.
Setting aside the appeal to emotion, there are a couple of things to unpack. In real-world ransom kidnappings, life and death was always at stake and the government still errs on the side of not paying.
Second, you presume ransomware authors are prepared to commit murder. If a hospital cannot legally pay, the only thing to gain by shutting it down is murder.
This is bullshit. US laws do not prohibit ransom payments except to sanctioned and/or designated entities which tend to not operate within the US.
In certain cases, it is: https://www.sidley.com/en/insights/newsupdates/2020/10/offic...
All you are doing is incentivizing companies to not report these attacks.
Furthermore, a corporation's bottom line is not truly comparable to a human life. However it is my understanding that paying ransoms to save human lives is technically illegal to. If paying a ransom to save your family member's life is illegal, then corporations paying ransoms to protect their finances should certainly be illegal.
You are wrong.
Arguably the bigger problem is you don't know that the ransomer will actually give you a valid key, but suppose you guess a likelihood P that they do.
Now you have some scenarios:
1. Don't pay. We're out $C.
2. Do pay, and get a valid key. We're out $R.
3. Do pay, and get no key. We're out $R + $C.
So the limit is at scenario 1 being equal to the combination of 2 and 3.
Set C = PR + (1-P)(R + C), and your max ransom R = CP
(You could probably work in additional costs for cleaning up even if the ransom is paid.)
Suppose god handed down powers that allowed you to smite from the earth anyone who ever paid a ransom with perfect accuracy and you made a credible commitment to do so. If this fact was well known, presumably random-paying would disappear overnight and ransomware attacks would soon cease to exist as well (ironically rendering the power to smite ransom-payers redundant). We won't ever live in that world but we can move marginally toward it by severaly penalizing clear cut cases where a company or individual pays a ransom.
There is another much greater chance that some party with a fiduciary duty to shareholders could be sued for misrepresenting the risk of this happening to shareholders.
Perhaps instead it should not be legal to say publicly you paid a ransom but ok to pay the ransom. That would tamp down a bit the publicity that encourages more actors. That would be a quick and easy fix along the lines of insider trading.
If a have a firm that makes $100,000,000 a year in net-profit , paying a $5 ransomware is a cost of doing business, an unfortunate one nonetheless
Businesses don't have a right to do whatever they want just because it is profitable.
How many jobs are you willing to lose in order to stop ransomware attacks?
One ransomware attack probably costs the ransomware operation a few thousand dollars, any legislation would have to be extremely successful to result in a negative ROI.