Writing a law with proper disincentives is also trivial -- forget about fines. Proper jail time for senior execs and board members.
Execs and boards will be damn sure not to pay ransoms, and additionally damn sure that any company they hire to help knows in no uncertain terms that they are also not to pay any ransoms.
It really isn't that hard to write laws that disincentivize paying ransoms and aren't possible to route around with wink-and-nod bullshit.
Someone may have paid into that wallet, but who? Was it the attackers themselves, to make it seem to observers as if they succeeded? Did some consultant happen to keep a stash of crypto? Maybe the boss of the hacked organization wisely maintained a wallet for that purpose, funded by embezzling?
Loopholes exist, but in general the government is not terrible at figuring out basic schemes like this and adapt administration of the law.
As in this case, pointing out a hypothetical way a law could fail, to insinuate that all laws would fail.
Insurance. Back-ups. Bail outs. Go out of business. That ransom paid has negative externalities that manifest nationally.
Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business hits their competitors to drive them out of business, etc)?
Isnt that what fire/flood insurance is for?
Take out a port, and screw an entire region.
There is definite economic attack damage incentive still in place.
In fact - if ransoms are banned - then it would seem that such types of attacks become more of a state sponsored attack to affect the economy of your enemy/competition
What if it were apple attacking FB or something like that. Surely we will see this in the future, just as originally foretold in Neuromancer.
Unencrypting for vicitims in the US that couldn't pay would just add more exposure risk to them of getting caught, so they would have no incentive to actually do it. It would take a large bit of money out of the system, but it seems like you need all countries to coordinate and that one country doing so on its own, enforcing a no pay out rule, won't have much effect on non-targeted attacks.
How many of these attacks are fully automated in the initial attack/encrypt phase vs. human operators explicitly working to more fully infiltrate a target?
Given the effectiveness of social engineering in hacking's history, that's a very good question. I wouldn't be surprised if randomized attacks are used to create a "sales funnel" of high value targets with poor IT ops/outdated equipment/etc that can be exploited for big payouts. All it takes is a few hundred or thousand dollars to bribe a low level employee so the vast majority of the cost is likely in finding targets. Once they've identified a target, the exploitation process is probably mechanical.
The argument for banning payment of ransom for a ransomware attack applies just as much to any other situation where a ransom is demanded.
No, that’s what our military is for. That said, we have limited evidence any of these recent attacks were state backed.
For those of us who make money when cybersecurity dollars are spent, yes. Practically, you’d get a federal agency writing checklists.
Do you use https?
Do you store password hashes instead of passwords?
Is the DB storing passwords in a firewalled network?
Is access to the DB restricted to only "need to know individuals"?
Does the DB send password hashes to other services?
Have you had a penetration test of your authentication system?
Do you sanitize the SQL you send to your DB?
etc.
Unfortunately the majority of security incidents occur due to someone forgetting something pretty basic or assuming "no one will ever find that".
This is the limiting factor in secure coding. We need more efficient ways of scaling out the few teams doing top tier work, as it only takes a single bad code review to open a security hole.
Teams should not need to implement their own authentication mechanism. Most companies should not need to implement their own mechanism. Authentication providers should explicitly and automatically verify that their clients have implemented auth correctly.
For the most part determined actors (many of them state sponsored) are going to be hard to prevent if they target you. Your best defense is early detection and reaction to the initial breaches. If you only do the hardening part and leave out the monitoring/observation part you are going to get owned.
No one expects the check lists to result in a perfect outcome but not having them quite likely results in a worse outcome.
Ban cryptocurrencies. They are the cause of the ransomware epidemic.
This is meant sincerely, not glibly: How? How can cryptocurrencies be banned in any meaningful sense?
We can "ban" them in a legal sense ("Use of cryptocurrencies are illegal after 1 Jan 2022"), great. But how can they be practically banned so long as computers themselves are not invaded by governments to observe every detail of their operation and private overlay networks are still technically feasible?
The main avenue would be by getting rid of the sanctioned on/off ramps for crypto (that is, crypto exchanges), leaving only the illegal on/off ramps which I'm sure exist.
This obviously wouldn't stop everybody, but it would certainly be a deterrent for all but the most motivated and well-connected of buyers. At that point, exchanging a large amount of crypto would be similar to laundering a large sum of dirty money; possible, but not trivial and certainly not an "easy out" for a major corporation experiencing a ransomware attack.
Laws are how you prevent this.
Can you imagine the Massachusetts Steamship Authority paying in cocaine?
Why would paying in Bitcoin be any different?
Bitcoin is parroted largely by a bunch of libertarian speculative grifters that think they're above the authority of our government to manage the monetary supply. They want to soak up all the advantages of building and controlling an economy.
If you look through the covers, it's all speculation and hype. There's noting "decentralized" or "democratic" about it. Bitcoiners are fine with letting social services and the underserved slip through the cracks as long as they get their reward that they feel they earned.
The US is a democracy, and theoretically it helps people of all backgrounds and socioeconomic statuses. It might not be evenly distributed, but at least we can toss out the bad players. Bitcoin is not a democracy. It rewards the Ponzi schemers at the top and leaves everyone else out to dry.
And now look at what it's gotten us -- unprecedented crime from across international boarders that we can't stop. All brought to you by the remarkable "governmentless decentralization".
Just wait until the kidnappings start. Or the murders for hire.
Fucking good for nothing bitcoin. The world was better before it existed.
Are you seriously using the war on drugs as an example of a successful policy? Drugs are easier to get and more numerous than ever, even though we have these magical laws in place for decades.
What are you basing this on?
From what I've read it seems its only the stupidest of criminals who are using exchanges like Coinbase to cash out, because that's the easiest way to get caught.
Even if cryptocurrency<->fiat transactions continue to be legal in other jurisdictions, making it illegal to trade USD for $crypto would make it very hard for a US company to pay cryptocurrency ransoms making such schemes much less lucrative.
By banning them? In the law? Enforcement would probably pay for itself, plus some. Throw in a whistleblower bonus, like the SEC has, if you want it to run on autopilot.
More aggressive: level repeated 51% attacks. This is well within the budget of any of the G7.
The only way to buy or sell cryptocurrency for the vast majority of people is through exchange companies that have the blessing of the US to continue operating. Even LocalBitcoins goes out of their way to follow KYC laws.
Legal/technical framework is already here.
I think a complete ban on cryptocurrencies is unlikely to succeed, for much the same reasons that the US hasn't banned guns and that the war on drugs is such a shitshow. A punitative tax: 10% of every transaction, for example, would still make cryptocurrencies viable for some extreme schemes, but would make the practice much harder and help establish the "real identity" -> Bitcoin address audit trail. Al Capone was busted on tax evasion, after all.
In what world does a ban on paying ransoms get wantonly evaded while a ban on cryptocurrencies does not?
If they wanted to prevent this kind of behavior there are two straightforward approaches:
- make it also illegal for the consulting company to pay a ransom.
- attach Strict Liability to any ransom payment, even if made through an intermediary. The executives quoted above from the paying company could still face criminal liability for such a payment disguised with plausible deniability https://en.m.wikipedia.org/wiki/Strict_liability