Legalized them, the FBI has to pay them for you, you have to give them 3x the cost of the payment. 1x to payment. 1x to finding people who committed the crime 1x to pay off everyone impacted.
Increasing the cost of not being secure is the only way the problem will be addressed.
What’s the right percentage of the economy to sacrifice to (maybe) stop one kind of crime?
Businesses are less willing to comply with the mob when the government is swinging a bigger stick. And payments/criminal rewards get pressured down when it’s blatantly illegal
Imagine that we send anyone who orders that ransom payment be made, or those who conduct payment are all sentenced to death by boiling them feet first in oil. Imagine that no judge or jury shies away from the punishment. Then imagine that there are 1 million of these crimes per year within the United States. How many people are executed? 15? 600? Unless the government's doing ransom audits monthly, how the hell will they ever catch such people? Whistleblowers are safe even if they don't whistleblow, they're not on the hook for punishment. And they're not seeing something so unethical they feel morally compelled to act. Just coworkers who are trying to keep the company from falling apart (potentially even saving the whistleblower's job too).
The criminals might try to leverage this by using it as further blackmail material, but that doesn't work in game theory. The individuals are relatively poor, so they can't be milked individually, and the business can't afford ongoing, indefinite ransom... changes the equation into the "definitely not worth it" category. If the individuals could afford it (in the strict sense), then they will refuse orders to covertly make payment, because then they are on the hook personally... so the criminals are going after the small fish and losing the big.
This is unenforceable.
By the tax authorities, who are already looking at every payment a business ever makes anyway!
> This is unenforceable.
Only for amounts that come from petty cash, at which point you have effectively reduced the major financial motivation for such crimes anyway.
Investigating price fixing or discrimination is hard, because it happens over a protracted period, and you have to show a pattern, and everything is open to interpretation, etc. But this? There are two distinctive events that are basically impossible to hide: The disruption and the payment.
Attacks on individuals are another matter, yes that's hard to enforce. But then, on the average, I don't think individuals actually benefit from paying this kind of ransom. It just tags you as a mark for further abuse. So maybe most people will accept that paying ransoms is just not something you do.
These seem easy to hide. Sure, it incentivizes quick payment, rather than dragging it out for a week. But for 99.9% of employees, this is "the computer network was down, but IT fixed it quickly". For the 0.1% of employees who understand or suspect it was ransomware... thank god corporate got it fixed before 80% of employees were laid off.
The economic losses from thoroughly investigating all widespread network outages (including many not ransomware), seems to outweigh any benefit this could have in (eventually) discouraging ransomware. Just the other day they were talking about how Pixar lost a whole movie but for a copy on some remote worker's machine... in a world where ransomware payments were criminalized, that sounds an awful lot to me as if it might've been one. How many months would they spend combing through log files trying to rule it out? How much does that cost a company like Pixar when they're trying to meet deadlines?
I'm hesitant to point this out, but I've seen shit like this my entire career (thankfully, none of them ransomware). I still have a career, thankfully, which indicates I was only tangentially associated with such incidents. But they're common. There have been big Atlassian, Amazon, and Google incidents as HN headlines within the last 2 years... and whatever explanations they gave, clearly those were just coverups for ransomware payments (or at least people could reasonably suspect that, were it criminalized).
This still seems unenforceable to me in any practical way. But I guess if we're going the totalitarian police state which ruins the economy route, there is some slight wiggle room.
Most companies aren't going to cook their books over this.
A one-time under the table purchase from some dark web bitcoin broker doesn't seem like that big of a deal. It's not the sort of book-cooking that tends to get noticed.
In my eyes, this would do almost as much to improve cybersecurity as liability in tort for insecure software.