Should we ban ransom payments?
techcrunch.com
techcrunch.com
The gunpoint analogy is a poor one; being coerced by physical violence is one thing, being coerced because you lost your files (and don’t have backups) is another. It’s a horse of a different color.
The companies getting their customers data encrypted are NOT victims. At best they are incompetent and should never have been in business to begin with and most certainly should never have been anywhere near any of their customers data.
Companies have a fiduciary responsibility to protect their customers and investors. If a company is letting phishers trounce all over my data then in a way I am glad that my data became encrypted so that the company can no longer hide the fact they were negligent not only to keep the thugs out but also neglected to properly back up my data. I am more concerned about all the companies that were popped and were able to hide it because they only lost my data to the phishers. Ransomware is exposing the incompetent businesses and embarrassing their leadership as it should. Securing data in an ever growing and large company can be challenging due to internal politics especially if being security focused from day one was not their priority. Backing up data is easy.
That means less potential profit for ransomware makers, less incentive to make ransomware, and less money to fund ransomware development.
Ransoms are not a net win when victims don't payout.
I did not see anything in the article that took that into account. I fear the lawmakers may not familiar with those dynamics either.
My personal assumption is that the cost is very low for the bad guys.
This may make a dent in their profit margin. But is that really worth it for the position we'd be putting victims in?
If my assumption is correct, it just going to shift the ransoms to those victims more willing pay without being caught and I'm not sure that is the a desired outcome (or maybe it is). The big companies may be targeted less if they don't pay, but is that really solving the problem?
The victims won't pay because they don't want to go to jail. If no one pays—or even if people pay much smaller amounts that are possible to hide—there isn't an incentive to launch ransomware.
My assumption is that the cost to find victims and make the request is low enough and that number folks that will still pay regardless of the law is high enough to make it it worthwhile for the bad guys.
Best case, it lowers the profit margin for the bad guys. Meanwhile, the victims face being punished even worse.
Yes, many big businesses may stop paying since the executives don't want to go to jail. Realistically if they are that big they can probably come up with a legal argument to justify the payment though within the mess of exceptions that would have to exist if this became a thing.
In the end the bad guys are just going to adjust to target smaller companies that would be under the radar for being caught paying.
In the end it doesn't really matter what the dynamics of it end up being. If it pays off to ransom, it will still happen, and I think there will always be a way to make it pay off for quite a while.
The only real solution is better security that makes it unprofitable to even attempt to breach a company that makes a random possible.
Threatening legal consequences for the victim is a very sideways way to go about achieving the goal of deterring the bad guys.