Doesn't allowing near-infinite amounts of scams, fraud, and other abuse threaten the free internet far more than arresting bad actors?
Doesn't allowing near-infinite amounts of scams, fraud, and other abuse threaten the free internet far more than arresting bad actors?
Think how the world changed after the PATRIOT (lol) act, and how many terrorists have been actually detained in exchange for such invasive measures on the general public. I'd bet the most benefited from all these years of mass surveillance have been advertisers, not law enforcement.
I think so, but this is backwards. State and corporate spying gets justified by the scammers and fraudsters, not by whether or not the takedown operations are successful. If scammers and fraudsters weren't doing wildly unpopular things like taking health care systems hostage with ransomware, etc, we'd all have a lot more ammo to tell the cops to respect our privacy.
Online scams, fraud, and malware have been around since the '80s, and we've survived.
Additionally, a huge industry has been built around it, employing many people and generating massive amounts of wealth compared to the direct costs of these activities. Just compare the cost of ransomware to the "cost of cybercrime"[1][2] which is mostly revenue for the cybersecurity industry, and there is a magnitude of difference.
[0] https://www.vice.com/en/article/qj454d/private-intelligence-...
[1] https://www.bleepingcomputer.com/news/security/ransomware-pa...
[2] https://www.weforum.org/agenda/2024/01/cybersecurity-cybercr...
And the revenue of the cybersecurity industry the "cost of cybercrime"?
You seem competent, me I don't know much about practical cybersecurity.
But the combined cost of companies or medical facilities being infected by ransomware surely is not covered by the total ransom payments, right?
Sorry if I'n grossly misunderstanding your take, but I struggle to make sense of it.
I see however your point about surveillance.
And also, affected companies and institutions + the software companies, consultants etc they work with should carry a certain responsibility in some cases.
For example, a social engineering breach with one employee who had normal privileges shouldn't allow to easily propagate over the whole network etc
Personally, I have seen during incident response many organizations drop seven figures on EDR, IDS/IPS, and a bunch of widgets while ignoring or refusing to do simple things like network segmentation and configuration/patch management, and it's because they've been sold silver bullets by their vendors, so I also hold a bit of contempt for the industry as well.
I got your point though, that's why I edited in the paragraph about accountability.
Thanks for your insights.
This gives me flashbacks. I worked in hospital IT for a few years, and the main IT office was constantly trying to fold the (unpatchable, running a mix of OS2, win95, win98, MSdos, and proprietary OSs in -2007) medical devices into the main, internet accessible network.
I had to spend countless hours in meetings to keep them segregated. At times, I actually had to just pull fiber jumpers out of the switch. They’d eventually have a fit because they couldn’t see the medical devices with their threat scanning software.
They could have just hooked up a laptop to the medical device network and said “yep, every single ip address on there is vulnerable” and sent a strongly worded letter to each manufacturer demanding a patch, which will never be released. Since the devices are FDA certified medical devices, you can’t just patch them without manufacturer endorsement of the software change…so any device more than a few years old is usually vulnerable.
3 months after I left they had a major ransomware event. Weird. Who could have imagined?
That's a really awful take. We've also had plagues killing large chunk of population and we've survived. That doesn't mean it wasn't an issue for people affected. There are people who have lost their life savings and relationships due to scams. There's an individual/society cost to all of this.
In the context I was discussing I consider it a pragmatic take because our response to these issues needs to be understood across multiple domains including privacy.
That's not to say that nothing should be done. Personally, I'd like to see measured legislation placing more security, privacy and liability onto manufacturers and providers.
That's an unfortunate but necessary cost, not something to be happy about. It's as much a positive argument as the broken window fallacy.
Has anyone been convicted of anything? We are siezing control of personally owned assets under the presumption the responsible parties will be found guilty. That seems like a slippery slope.
if someone is dumb enough to register with a real name, the amount of time needed to coordinate it can be reduced.
like with the 911S5 botnet, they got evidence over the years to build a case to arrest them.
if it's a large group of people, it may take time or a turncoat to slowly gain evidence on the other parties.
seizure of assets in those countries required the police and courts in those countries to have probable cause that yeah it was definitely related to the crime and necessitated seizure in a coordinated fashion. This is similar to the coordinated quiet takeover of a darkweb market, or the coordinated spooky takedown of another, to scare criminals onto the bugged one.