The push to ban ransom payments is gaining momentum
socket.dev
socket.dev
Do take this seriously, we operate on a few millions EUR budget yearly - tightly counted - and still we were worthy for attack in their eyes. Watch out all!
The question is what happens with an employee who acted when there wasn't a problem?
If an employee opens a phishing attachment or something, they should be able to report it without fear of losing their job so the incident can be contained.
Instead - they are incentivised to say nothing and hope for the best for fear of getting fired.
It was an employee today, but the cord was going to get yanked anyways. A data center tech who pulled the wrong cable out, a power cut, a backhoe with a taste for fiber, whatever.
So long as the employee was acting as best they could with the information they had, the resultant business implications are really the businesses' fault. Having a system that cannot be recovered is risky. Assuming that system will never die is foolish. Blaming the employee is pointless.
My vote would be to understand why the employee thought it was necessary to shut the system down, and then educate them (and the rest of the department, since it's probably a collective problem) on why it wasn't necessary and what they could have done instead or how they could have known it wasn't an issue.
That employee probably also deserves a couple days off once the system is recovered (delivered in person, by their manager). It sends a message that they're not in trouble, but more importantly, they're likely fried from trying to juggle internalizing their mistake, getting the system back up, and worrying they're going to get fired because _this_ is how the CEO learned their name. They probably shouldn't be near a prod system for a couple of days until they've come down from the adrenaline and had some time to internalize what happened.
It's the victims that would now have two problems: damned if they pay, damned if they dont.
It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments openly (it's not like they used a bank account).
The actual cost of launching an attack like this is basically nothing - initial access, etc, is largely automated and performed at scale.
The “costly” part is the hands on keyboard part, but even that can be largely automated, and even manually doesn’t take long.
This is not a company where you automate people out of job and CEO gets all the profit. Organised crime groups share profits among themselves, and the profit is by far the main motivator for all of them.
This would basically remove the prospect of million dollar payouts; it probably removes the prospect of payouts in the hundreds of thousands. Any company with the money to make those kinds of payouts is likely to have reporting requirements that make it very hard or impossible to hide.
Payments in the tens of thousands could maybe be hidden or targeted at small enough businesses that they don't have to report what happened to their money, but is it even worth it at that point? We're talking people with at least some level of technical ability; do they really want to piss off the FBI/NSA/European equivalents for tens of thousands of dollars? I sure wouldn't.
Do you think we should do similar for theft? Should it be illegal for a store assistant to hand over money to armed robbers, because theoretically if less people handed over money there might be less armed robberies?
And I disagree with what you're saying anyway. I doubt this would stop ransomeware. I think if anything this would just push ransomware to become even more cruel so that they increase the likelihood of their victims choosing to break the law over not giving the ransomware owners what they want.
If the size of the ransom stays the same, this provides a stronger incentive to keep IT security at a sensible level. Or, if this means criminals have to lower their demands to get paid, then the profitability goes down.
Use the money collected to fund IT security programs (research, awareness and assistance to companies in need of improving security.
Just look at the British Library as discussed in the article, not paying the 500K ransom cost them more than 6M so far. And was much more damaging to the public (I know because I tried to register after the ransomware and they simply don't have online registration anymore). They are STILL basically offline more than 6 months after:
> We're continuing to experience a major technology outage as a result of a cyber-attack. Our buildings are open as usual, however, the outage is still affecting our website, online systems and services, as well as some onsite services. This is a temporary website, with limited content outlining the services that are currently available, as well as what's on at the Library.
You could change that percentage to any amount and it wouldn't change a thing, it will still be cheaper to pay in most cases, and ransomware attackers will just lower the price if it's not. Change the British Library to any privately owned company, and no matter the price it will ALWAYS be better to pay than to be literally out of business for more than half a year (dead at that point).
So what you're saying is that the criminals could quadruple their demands, and everyone would still pay?
I doubt it works like that. SOME high profile companies would still pay, but in many cases the threat would not justify paying 4x more.
If we assume the criminals do not generally do much research on each company's ability to pay, but just have a more or less even price for everyone, I think it's rather safe to assume that they've tuned the ransoms to a level that more or less optimizes the total payment they receive.
If it's made 4x more expensive to pay, fewer organizations would pay. And those who still pay will provide a lot of funding for efforts to battle this kind of crime.
> and ransomware attackers will just lower the price if it's not
This is at least half the purpose of adding the tax. If the price is lowered significantly, the economic loss for the non-criminal part of society is reduced.
Also, lower revenues means that it will get harder for ransomware groups to "attract talent", meaning there will be fewer threats out there.
Making payments illegal, on the other hand, just pushes the payments under ground. It's going to be about as successful as when they tried to ban alcohol.
Maybe, maybe not. Everyone has a different threshold of what they will pay. Everyone has different costs to recover. Nobody really knows the exact cost to recover until they are done, by the time you realize you underestimated the cost of recovery it is too late.
If so, why don't they?
No. There's a major psychological difference between paying 1M to criminals to recover your data and 3M to the government, and paying 4M to criminals.
At least the capitalists I've met tend to really HATE taxes.
When I was a teenager and started playin D&D (1st ed), there was only Lawful/Neutral/Chaotic. No Good/Evil.
At the time, I tended to see the world primarily as Good vs Evil, so AD&D (2nd ed) seemed like an improvement.
As I got older, I came to realize that what people consider "Evil" is mostly used for people we're in some partisan conflict with.
Like in Israel/Palestine: Each side see the other side as "Evil" and themselves as the "Good Guys".
If anything, the main purpose of allowing ourselves to see some groups or individuals as "Evil" is to dehumanize them in ways that allow us to do "Evil" things to them.
Lawful vs Chaotic makes a lot more sense to me than back then, though. It's the yin/yang dualism that when in balance gives rise to most of the interesting dynamical phenomena.
The "victims". Most of those victims have only themselves to blame. They are more often than not quite public and successful companies that couldn't are less about security. They get hacked, pay out transom money and don't change a thing.
I mean, just look at the poor victim British Airways https://www.bbc.com/news/technology-54568784
--- start quote ---
A subsequent investigation concluded that sufficient security measures, such as multi-factor authentication, were not in place at the time.
The ICO noted that some of these measures were available on the Microsoft operating system that BA was using at the time.
--- end quote ---
Or the poor victim Microsoft: https://edition.cnn.com/2024/04/02/tech/us-government-micros...
--- start quote ---
The hack “was preventable and should never have occurred,” says a report released Tuesday by the US Cyber Safety Review Board (CSRB), a group of government and private cybersecurity experts led by the Department of Homeland Security.
--- end quote ---
Given that even top intelligence targets we read about being hacked, I seriously doubt it's just about getting some better security mentality.
A credible commitment to ban ransom-paying means that future ransomware attacks will get zero value for the attackers (beyond whatever they can get out of stolen data I guess).
The optimal short term response of the ransomware attackers is to push as hard as possible to make such a ban non-credible, through appeals to emotion like this one.
The optimal long term response for the rest of us is to pass a law banning ransomware payments, make a few high profile examples of those who violate it, and then watch the ransomware epidemic die off, much the same way that kidnapping for ransom died off 50 years ago.
The ransom would be a few hundred dollars.
Things got rather interesting after WannaCry and NotPetya - some underground markets/sites banned discussion of ransomware for a while, a lot of groups went quiet.
Then it came back with almost exclusively targeting of enterprise/companies for big payoffs instead of a shitload of small payoffs.
Fundamentally the financial incentive needs to be stopped in order to curb ransomware activities.
If your data is in the cloud, it's probably good to have an offline backup onsite - sometimes cloud providers delete your account: https://news.ycombinator.com/item?id=40304666
...and tested on independent infrastructure.
I worked with a financial Customer in the late 90s who, quarterly, sent a backup to an independent party for restore of the data into a freshly created application environment. They verified the backup with reproduction of key reports and random spot checks of data. It was impressive.
For absolutely business-critical data, I would consider using multiple backup approaches and/or vendors. Shout out to Tarsnap as vital here that every commercial enterprise should use for essential customer, contract, and accounting data.
The problem is, a lot of bad actors in cyberspace aren't individuals any more - Russia, China, Iran and North Korea have groups backed or outright created by the governments. There is no way to hold them accountable, three of these countries have nuclear weapons and one is only a few weeks away from building one should they decide to go for it [1]. Other cybercriminals like scam callcenters in India and Turkey have been found to bribe local governments to turn a blind eye or to warn against enforcement by federal authorities.
The only way to hold them accountable is to cut the countries off from the global communications networks so they can't do any more damage until they show credible efforts and successes in being better netizens, but we don't want to do that for a variety of "realpolitik" reasons either.
> and I think companies that get hacked should have to sit with their actions and DO BETTER for their customers.
EU GDPR has made some effort there, but in the end all software has security-critical bugs and there is only so much one can do to prevent getting hacked.
[1] https://www.reuters.com/world/middle-east/explainer-how-clos...
They do run intel campaigns against targets or sell the tools to run such campaigns, but so does every somewhat developed nation in this world. Intelligence operations are older than the Bible, they have been a part of civilizations ever since civilizations existed as a concept.
Legalized them, the FBI has to pay them for you, you have to give them 3x the cost of the payment. 1x to payment. 1x to finding people who committed the crime 1x to pay off everyone impacted.
Increasing the cost of not being secure is the only way the problem will be addressed.
What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?
Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United States. How many people are executed? 15? 600? Unless the government's doing ransom audits monthly, how the hell will they ever catch such people? Whistleblowers are safe even if they don't whistleblow, they're not on the hook for punishment. And they're not seeing something so unethical they feel morally compelled to act. Just coworkers who are trying to keep the company from falling apart (potentially even saving the whistleblower's job too).
The criminals might try to leverage this by using it as further blackmail material, but that doesn't work in game theory. The individuals are relatively poor, so they can't be milked individually, and the business can't afford ongoing, indefinite ransom... changes the equation into the "definitely not worth it" category. If the individuals could afford it (in the strict sense), then they will refuse orders to covertly make payment, because then they are on the hook personally... so the criminals are going after the small fish and losing the big.
This is unenforceable.
By the tax authorities, who are already looking at every payment a business ever makes anyway!
> This is unenforceable.
Only for amounts that come from petty cash, at which point you have effectively reduced the major financial motivation for such crimes anyway.
Investigating price fixing or discrimination is hard, because it happens over a protracted period, and you have to show a pattern, and everything is open to interpretation, etc. But this? There are two distinctive events that are basically impossible to hide: The disruption and the payment.
Attacks on individuals are another matter, yes that's hard to enforce. But then, on the average, I don't think individuals actually benefit from paying this kind of ransom. It just tags you as a mark for further abuse. So maybe most people will accept that paying ransoms is just not something you do.
These seem easy to hide. Sure, it incentivizes quick payment, rather than dragging it out for a week. But for 99.9% of employees, this is "the computer network was down, but IT fixed it quickly". For the 0.1% of employees who understand or suspect it was ransomware... thank god corporate got it fixed before 80% of employees were laid off.
The economic losses from thoroughly investigating all widespread network outages (including many not ransomware), seems to outweigh any benefit this could have in (eventually) discouraging ransomware. Just the other day they were talking about how Pixar lost a whole movie but for a copy on some remote worker's machine... in a world where ransomware payments were criminalized, that sounds an awful lot to me as if it might've been one. How many months would they spend combing through log files trying to rule it out? How much does that cost a company like Pixar when they're trying to meet deadlines?
I'm hesitant to point this out, but I've seen shit like this my entire career (thankfully, none of them ransomware). I still have a career, thankfully, which indicates I was only tangentially associated with such incidents. But they're common. There have been big Atlassian, Amazon, and Google incidents as HN headlines within the last 2 years... and whatever explanations they gave, clearly those were just coverups for ransomware payments (or at least people could reasonably suspect that, were it criminalized).
This still seems unenforceable to me in any practical way. But I guess if we're going the totalitarian police state which ruins the economy route, there is some slight wiggle room.
Most companies aren't going to cook their books over this.
A one-time under the table purchase from some dark web bitcoin broker doesn't seem like that big of a deal. It's not the sort of book-cooking that tends to get noticed.
In my eyes, this would do almost as much to improve cybersecurity as liability in tort for insecure software.
Businesses are less willing to comply with the mob when the government is swinging a bigger stick. And payments/criminal rewards get pressured down when it’s blatantly illegal
While this looks at face value like it's just making things worse, in fact it cuts the profits by 75% for any criminal trying to optimize the ransom demanded.
Then use the tax collected to fund IT security research or something.
There are variety of ways kidnapping for ransom works (including cyper attacks here but also something like human trafficking activities...etc [1])
So there are many actions taken to address those. They are not just confined into the islamists category.
[1] https://www.nationalcrimeagency.gov.uk/what-we-do/crime-thre...
- some country or its exiled representatives directly ask for aid , e.g. against narco empires, but it's nowhere near a given that we react (e.g. Haiti, who has been begging for help for years now)
- it threatens international shipping safety on popular trade routes, e.g. the Houthis in Yemen or Somalian pirates... and it's funny that the shipping co's complaining the loudest until military intervention comes are the ones who refuse to fly their ships under Western flags.
- islamists threatening to spread their terrorism to other countries
And that's it. Our general publics aren't very happy any more to spend trillions of dollars on oil grab operations or even on desperately needed support such as in Ukraine.
This applies to criminal groups (and individuals), clans in places like Afghanistan or Somalia and even to whole countries when dealing with each other.
Essentially, such groups are playing repeated games of Prisoner's Dilemma. They need to be seen as playing a tit-for-tat strategy. If they are known for playing always-defect (or always-cooperate), other "players" will (if rational) play always-defect against them.
This means they need to be honorable in that they keep their promises. But if someone disrespects them, they also must be predictable vengeful.
To me that suggests that rational economic forces really are at work and as a result, banning payments would cut back on ransomware attacks.
This is very similar to having a "we don't negotiate with bad guys" policy, which is common at least as rhetoric if not in fact.
Your company's policies are subordinate to its survival.
in a balance sheet, paying the ransom is just catching up to inadequate budgeting for systematic security efforts. while the person at the end will always be the weakest link, so much more can be done to avoid most attacks.
maybe everyone going back to thin client like windows 365 would finally put this to end.
The rules are complex here. If your kid really is kidnapped ask the FBI (or local equivalent). Often they can pay a random on your behalf - with money they have means to trace. Sometimes if your life is in danger you can pay a bribe - but be sure to report to the FBI (or local equivalent) as soon as you are safe.
Are we trying to get a free working market or what??
1. Cryptocurrency allows for unimaginably huge untraceable ransom payments that Amazon gift cards did not support,
2. No liability in tort for insecure software, and
3. Lack of computer security regulation (e.g., your car must have a seatbelt and ABS but your software can be arbitrarily bad without being prohibited).
Insurance. Is not going to fix cybersecurity.
It will show up somewhere in the tax filings. There's no such thing as discreet payments unless it's in such small amounts that it comes from petty cash.
And since the ransomers are demanding payment in crypocurrency, it's even easier to spot for the clear majority of victims.
Create a shell company in some remote tax haven with lax disclosure laws, have them pay the ransom, and close the shell company afterwards. Companies are already good at dodging taxes this way.
That only works for hiding income, not hiding expenses.
You create a shell company in Malta (for example). Now how do you get $$$ into that company so that it can pay the ransom?
Okay, so you assign your payment to $MALTA-COMPANY the line-item of 'consulting fees'. It only takes a few companies to do this before the tax authorities are wise to it.
After all, even for relatively tiny amounts companies still have to perform KYC on customers!.
Think about it this way: if it was that easy to hide expenses from authorities, embezzlement schemes would be a lot simpler than they are now.
Tax authorities already don't give a fuck about where a company shifts its money to. As long as there's a proper entry in the books, at least. There are schemes involving up to six different legal entities [1]. A measly million dollars or two is a minor rounding error for a multibillion dollar company.
> Think about it this way: if it was that easy to hide expenses from authorities, embezzlement schemes would be a lot simpler than they are now.
Embezzlement is easier the higher the embezzler is in the command chain. When the CFO orders something to happen - say, a monetary transfer or the creation of a shell company - it will usually be executed without question by the lower levels. Maybe, given the rise of impersonation attacks, the underlings will follow protocol and call the CFO back to verify that it is really the CFO ordering that thing, but that's it.
If I were to guess, 90% are accepted at face value, 10% are flagged for some irregularity and 1% are audited in detail.
Independent auditors check to see if a company's accounting is following GAAP accounting standards (so that a statement can be put in the SEC filings). They don't comb through each payment in detail (corporations can have millions of them each year). And if they find things, they tell the company to fix it or report any deviation from GAAP standards.
But much of it is dependent on good faith of the company along with some spot checking to see if their accounting processes line up with what they said they do.
And plenty of companies who have been found to commit fraud have gotten the "thumbs up" during their "independent audit". It gives you a sense as to how cursory their audits are.
Double money
The United health care exploit was a password compromise as was the British library.
The EPA just released a report saying 70% of the water infrastructure has laughable vulnerabilities like default passwords: https://www.newsweek.com/drinking-water-warning-issued-natio...
This is conjecture presented as fact.
Here is an alternative conjecture: what if ransomware is mainly a sociopathically-driven enterprise, with a side interest in profit? Or what if a good chunk of it is?
How many ransomware perpetrators have we captured, and subjected to psychological study, to be able to confidently say what ransomware is or is not?
To say we shouldn't do X because it doesn't perfectly eliminate/solve Y is akin to saying we should do nothing because by that standard, we'll never do anything about Y.
Those ransomware perpetrators who are motivated by profit could multiply their activities, if the yield is reduced: have more heists going on.
Reminds me of https://youtu.be/9pOiOhxujsE?si=GG6X16c8efr0I3Ey&t=213
Your own conjecture that ransomware authors are somehow a special breed is the one that needs backing.
Vandals are real.
It would be easier and safer to just destroy the data or cause other damage and walk away.
I mean they do already but now when they get paid they can "dob in" a payer for a secondary attack vector.
What this means is it is legal for some people and they can target you. Which now leaves the problem of what should "western" countries do about this? The options are limited. Either it is CIA activities - but this assumes they have spies in place and risks given them up and so it is very limited; or it is a military invasion (of a major nuclear power!). There is diplomatic pressure of course, but there doesn't appear to be anything that can do about this. If you have a good idea I'm sure governments will be interested - but in general smart people have already been thinking about this so odds are you just don't understand why your idea is bad.
I'm sure some people don't like that way of thinking, but where else do you think one spends $22mil per "victim"? $30 billion a year buys a lot more than fancy clothes and yachts.
Hacks happen. Where starts or ends someone’s responsibility? Where stops the buck? Can we really expect that every layer in an organization is always fully aware of security and security risks, even unknown vulnerabilities? Security practices change over time. Not so long ago 12 character passwords were considered safe, 2FA didn’t exist, …
I don’t think that harsher punishments and victim blaming is the way to go.
North Korea is well-known for that, although I’m not sure about ransomware, and I wouldn’t be surprised if Russia were into it too now.