If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off.
The government can help coordination by making defecting more costly (with criminal penalties).
not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, but this should be a priority going forward.
Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm.
Three letter agencies have used (and destroyed) companies for unrelated reasons and then left everyone without any recourse. With smaller companies, this happens regularly.
Those governments will have representatives from their lenders, from their investors, from their large clients and so on in them, who will get a lot of details they wouldn't normally get access to.
This is not happening.
Good luck guessing that password. I'm not even German.
What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice OSHA safety guidelines will get in major trouble.
Setting aside the appeal to emotion, there are a couple of things to unpack. In real-world ransom kidnappings, life and death was always at stake and the government still errs on the side of not paying.
Second, you presume ransomware authors are prepared to commit murder. If a hospital cannot legally pay, the only thing to gain by shutting it down is murder.
This is bullshit. US laws do not prohibit ransom payments except to sanctioned and/or designated entities which tend to not operate within the US.
We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
First, in many jurisdictions, paying protection money for physical security is illegal.
Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person.
> We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
I submit that oil pipeline operators, hospitals, and large corps are part of that 1%.
However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.
People are quick to conclude that Colonial’s security was “bad.” But do we know that to be true? A sophisticated, potentially state-sponsored organization initiated this attack. The best security in the world is not 100% secure. It might be wise to get the facts before rushing to judgement.
No, that's why we have division of labor. Law enforcement is just another brick in the wall. If a company is already making massive profits from the public by running critical services, why should tax payers fund their lack of diligence? Should we just fund their entire payroll while we're at it?
It's why, I think, such a law wouldn't pass Constitutional review.
If your person is threatened with imminent danger, you have a right to self-defense, we'll even let you commit intentional homicide if the threat is serious enough.
And self-defense also covers your property and livelihood to a lesser extent.
I think it'd be extremely hard to convince courts that this right to self-defense doesn't include negotiating with an attacker. Imagine if it were a crime to toss some money at a mugger and run away, for instance.
https://www.natlawreview.com/article/us-government-warns-com...
There are cases covering a justifiable use of force because intentionally killing or harming a person is illegal, and self-defense is a defense against those charges.
It's normally perfectly legal to pay someone whatever you want. You don't need a defense against something that's not a crime. There's no conflict in paying a ransom, so there's no case law.
Regarding OFAC, as your link points out:
> One issue is that victim organizations are required to check the list of sanctioned entities; however, many times the true identity of the cybercriminals are not known.
I'm guessing there's no case law regarding paying ransoms to SDNs because nobody has an identity they can check.
But do we need case law when OFAC says:
> OFAC will consider a company’s self-initiated, timely and complete report of a ransomware attack to law enforcement to be a significant mitigating factor in determining the enforcement outcome if the situation is determined to have a sanctions nexus.
If someone wanted to make a law against paying ransom, it would be quite novel and courts would have to look for applicable doctrine. I think the doctrine of self-defense would be a roadblock.