13 ms·
1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the syste
by myrandomcomment 4mo ago
1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever.
2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack.
No this will not stop this and companies need to be held accountable for their lack of security investment. Every attack should be investigate if the company met an agreed industry standards best practices and staffing, etc. The penalties for not meeting the requirements should be punitive.
- bombcar 4mo agoYour "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.
- Kostchei 4mo agointerestingly, having actually done the law enforcement side of these investigations, 50% of them are local. And I understand that this is not 100% solution, but neither is any form of law enforcement, but that doesn't mean we should fail to attempt it. Kids from the local uni having a lark, stalkers, vindictive ex employees, local gangs, criminals who understand their victims because they hail from the same community. These are your local hackers. Sift them from the nation states and international crime groups, then deal with the International as a matter of diplomacy. Because we do this so poorly locally, we have little ammunition to when it comes to diplomacy. "reduce attacks by your crime groups and we buy your natural gas, seel you wheat etc" Want more motivation?- 75% of the local attacks by volume send funds back to terrorist or separatist organizations. It is not an in-soluble problem. Sentences are a fraction of the answer, effective and receptive reporting processes are more important, then government backing for investigation and enforcement, then policy around home-team activities (ie don't do the bad things yourselves Mr Gov). Deterrence comes after all that.
- hluska 4mo ago50% of ransomware attacks are local to where? You’ll need to cite some sources because I don’t believe that is possible.
- nullsanity 4mo agoTo the country or an ally of the country they are targeting, duh. it doesn't matter if you believe it, it's been the truth for over a decade. Heck, Sh1nyHunt3rs people were arrested in the UK recently.
- Aurornis 4mo agoOne tech ransom case I know of was an inside job. It definitely happens. There are already significant penalties for doing anything like this. The guy involved is in prison for a very long time. I don’t recall the exact number of years but I do remember it was so long that he wasn’t going to see his kids grow up. I don’t think anyone who puts a little thought into a crime like this doesn’t understand that the penalties are already very huge. You don’t get a slap on the wrist for extorting a company (or person, for that matter)
- da_chicken 4mo agoYeah, they identified themselves as ShinyHunters, and the IP they've put on the demonstration page is geocoded to Russia. Notice this is the same group responsible for the Infinite Campus hack last year. Really, though, if you want someone to blame, Instructure is not a particularly compelling target. Let's review: 1. Iran is intentionally targeting infrastructure due to a war started by the current administration. 2. China is actively seeking corporate secrets to steal and commercialize for themselves, spurred by extreme protectionism and retaliatory tariffs. 3. North Korea is doing anything they can -- including just taking a remote job by proxy -- in order to extract any money. 4. And Russia is working with and aiding all of them, after everything else going on has forced the embargo to break. 5. All of this while completely alienating every single one of the United States' allies. 6. Meanwhile, the American DHS is currently shut down. 7. And this is after Trump cut funding and personnel for CISA severely enough they've had to end the contract with MS-ISAC, meaning all state and local entities can only remain in the organization if they foot the bill for it directly and CISA and other agencies responsible for cybersecurity are more thinly staffed than they have been in decades. In short, the current administration systematically disassembled all the protections we have built over the last 100 years, and then placed infrastructure -- schools, in this case, but also power companies, water treatment facilities, communications companies, local governments, hospitals, food producers -- directly on the front lines of the modern geopolitical conflict. That vast ocean that has kept us safe historically is a poor moat in the modern era.
- vasco 4mo agoHaving an IP in Russia means about zero regarding their location. Literally anyone doing anything like this is going to get a Chinese or a Russian IP for obvious reasons. Mostly decoy and people like you.
- elictronic 4mo agoComplete internet blockage of nations allowing the attacks. If foreign governments are you can always execute them. We are living in a different world where this is no longer a zero probability occurrence.
- Bud 4mo ago[dead]
- deleted 4mo ago[deleted]
- Avicebron 4mo agoWe could also throw the CEOs of companies who don't properly secure their infrastructure and pay their security engineers enough in jail. A little justice on both ends.
- scheme271 4mo agoUh, who determines that the infrastructure wasn't properly secured? Who is willing to risk prison because some intern accidentally committed an API key or made a dumb mistake. Conversely, what's the chances that no one actually gets prosecuted regardless of how sloppy their security practices are?
- applfanboysbgon 4mo ago> who determines that the infrastructure wasn't properly secured An investigative body, the same kind that determines the who, the why, and the how when an airliner crashes or a bridge collapses. Obviously a lot of work needs to be done to get from point A to point B, and it won't happen overnight, but software development is currently a deeply unserious profession and at some point a genuine software engineering practice needs to be developed. I am, perhaps naively, slightly hopeful that the LLM bullshit plaguing our industry will be the gust of wind needed for the house of cards to collapse and governments to realise that allowing the entire world to be vibe coded is not sustainable.
- dghlsakjg 4mo agoPretty famously, aviation incident investigations are almost always not done with prosecutorial intent, and more about truth finding. It leads to people involved being cooperative to prevent future problems instead of ass covering to prevent jail. Aviation’s safety record is not coincidental.
- allthetime 4mo agoIn a darker reading; strong aviation safety is mostly motivated by not killing customers. An airline or plane maker who kills more customers than others will rapidly bleed those same customers and lose them to less lethal competitors. If no one cared about dying people I imagine aviation safety wouldn’t be so impressive. As someone else here said, software, for the most part, is a deeply unserious industry. The stakes are so comparatively low and the consequences less obvious that it’s a lot easier for companies like intuit to maintain their supremacy simply by being entrenched, having strong sales teams, and the hearts & minds of non-technical managers. In recent times it seems Boeing has been flirting with enshitification and half-assery but critics are not quiet and not falling on deaf ears
- parliament32 4mo ago> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to jail for accounting fraud, you should be able to go to jail for cybersecurity-promises-fraud. They claim to be compliant with a number of security standards [1]. I would love to see a postmortem audit of how much of this they actually implemented. [1] https://www.instructure.com/en-au/trust-center/compliance https://www.instructure.com/en-au/trust-center/compliance
- JumpCrisscross 4mo ago> Incidents like this should be followed by an audit and charges being laid What? Why? Who died? This whole thing is perfectly dealt with through civil process.
- phainopepla2 4mo agoHow could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know? I do agree with the audit and punishments for clear failure to adhere to established standards.
- hsbauauvhabzb 4mo agoNo building has a 100% chance of not caving in, yet somehow I think charges would be laid if a skyscraper caved in.
- jameshart 4mo agoThis analogy seems to be portraying 'ransomware hackers' as an unstoppable force of nature akin to gravity. I'm not sure that's a fair analogy.
- 4mo ago
- mikeweiss 4mo agoShouldn’t we be focusing on making it harder to pay overseas criminals in the first place? /ahem/ crypto platforms facilitating transfers to bad actors /ahem/
- ttul 4mo agoBut, then, how would Trump’s family and cronies get paid?
- joenot443 4mo agoAre you earnestly under the impression that Trump does the things he does such that he can be paid later in secret bitcoin transfers? Like is that your actual model? I’m curious
- mikeweiss 4mo agoHe may be referring to the fact that the Trumps have strong business ties and interests to crypto industry, and as we've seen in the last year this administration is a strong friend of the industry. Money is being made one way or the other and if you don't think so you are completely blind.
- Bud 4mo ago[dead]
- protocolture 4mo agoCriminals should focus on proven methods, like Steam Gift cards.
- joenot443 4mo agoI think the cat is entirely out of the bag on that one, I’m afraid. There are no shortage of coins and no shortage of sketchy exchanges. The platforms do work with LEOs, when asked, but my understanding is that unless the perp was a serious nonce, chasing the transfers themselves is a fools errand.
- pants2 4mo agoWhen will countries start treating cyberattacks as an act of war? If the North Korean military came to America and robbed fort Knox of $200M in gold there would be retribution. But hack an American company for the same amount and the feds do nothing.
- prodigycorp 4mo agoOk, so we treat it as an act of war. Now what? Attack North Korea? Great, the entire city of Seoul gets shelled within five minutes of your attack and hundreds of thousands of innocent people die. It's very easy to play with lives that aren't yours.
- toraway 4mo agoExactly. This is the "Declare fentanyl a WMD" of solutions to ransomware. Sounds kinda badass as long as you don't spend too long thinking about it but has no practical relevance to actual enforcement challenges. It's a familiar example of the perennial "[THING] could be solved overnight if [PERSON_OR_GROUP] would just start taking [THING] seriously" trope.
- sayamqazi 4mo agoYou would be surprised how many people naively think "Why doesn't my country just open a war on X country and this Y problem will be solved forever" in their head they think war is just a flurry of bombardments and the other side (not theirs) is just destroyed to rubble and their country will have only minimal losses
- flexagoon 4mo agoMany country leaders also clearly think the same
- kqp 4mo agoNever retaliating is a great way to get people to attack you. Of course escalating to all-out war provokes the same in response, but there does need to be a proportionate response, because it needs to be stupid to hurt us, not good business. t’s a significant failure of the US government when half the world freely loots US citizens and businesses.
- charlie90 4mo agoIf someone robs a bank and someone inside dies of a heart attack, thats felony murder. I would be happy if the same applied to ransom attacks or other blackmail/leaking of info. If someone commits suicide because of it, its murder.
- scratchyone 4mo agofelony murder is pretty widely regarded as a leading factor in incredibly unjust prosecutions and sentencing decisions. perhaps not the best concept to build your ideas on top of.
- dev360 4mo ago> No this will not stop this and companies need to be held accountable for their lack of security investment. I think in principle, its sound. Im also just baffled hearing anecdotes from friends that are in big corp world and hearing the type of incidents they have, and how they respond to it.. It makes me wonder if there is enough capable talent to go around for the "boring corp" crowd. Hint: I don't think there is nearly enough talent to go round, but for these companies, its either that they think they have solid experts (and didn't), OR its not a real priority until you get hit.
- protocolture 4mo ago1. It should be illegal to run insecure services. Massive Fines. 2. The payout to the hackers should form part, but not all of the penalties. Pay those guys for their great service to humanity they earned it.
- gruez 4mo ago> If you do this to a hospital and someone dies you are life in prison / chair. If you're going to get the chair you might as well murder some witnesses or destroy some systems to hide the fact you got hacked. "Hack? What hack? Our servers all burned down in an arson attack".
- deleted 4mo ago[deleted]
- Ekaros 4mo agoFailure to protect computer system from forseen failure should result passing corporate veil and resulting all stock holders and managers/leadership of funds to be jailed for same period as perpetrator. It is only way to ensure that these things are taken seriously and enough pressure is put on leadership of companies.
- bux93 4mo agoOr maybe it should be mandatory for all companies to pay ransomware attackers. Think of it as an involuntary bounty program. Now they get to just say 'sorry (for your hurt feelings)' and suffer no consequences. Apart from the 4% of the total worldwide annual turnover fine that theoretically could be levied under GDPR, but has never been imposed in full.
- thinkingemote 4mo agoOne of those eye opening moments for me was learning about how these criminals work on trust. They need to be trusted to not release the data or to unencrypt when paid, and by and large they do. One way to weaken any group that works on trust would be to make them less trustworthy. That way victims wouldn't be as confident paying the criminals and thereby making the effort by the criminals less attractive.
- ivanjermakov 4mo agoThe only way to prevent terrorism is to never meet terrorists' demands.
- chrisjj 4mo ago> It should be illegal for any company to pay ransomware attacks. Period. That makes as much sense as illegal to give your wallet to a mugger. I.e. no sense.
- 0123456789ABCDE 4mo agoi disagree wholeheartedly with this. a loved one, gun to the head: "please pay the ransom, i don't want to die!" what's your play now? save loved one, and go to prison? or worse, bank blocks transfer, and they die? go ahead and tax ransom payments (0 tax if human life at risk, 10x otherwise) if you have to, but making it illegal feels disconnected from the messiness of the real world. then, go after the attackers.
- hootz 4mo agoThe idea behind blocking ransom payments is to disincentivize asking for ransom. If you know it's almost impossible to pay ransom, the risk of not getting paid for your attack is much higher.
- itsalwaysgood 4mo agoIt's not necessarily a lack of investment. Cyber security researchers are using AI to discover and post very serious Linux vulnerabilities that give root. We should expect to see more of this type of activity for a while. We're talking about vulnerabilities that have existed 10+ years but nobody noticed until AI.
- zulban 4mo ago"It should be illegal for any company to pay ransomware attacks. Period. No pay out ever." You seem to think "if it's illegal it won't happen". Instead you need to think about unintended consequences and what would actually happen if this were law. People would hesitate to contact the police for help before they've decided, or not do it at all. And not report it.
- TheSkyHasEyes 4mo agoThis reminds me of the 'fine the johns to mitigate prostitution' argument.
- matthewfcarlson 4mo agoI don't think there should be an investigation. Data got leaked? That's a fine. Consequences happened? The people who stole it are accountable but so are the people who had the data in the first place. Just don't have the data. There are plenty of companies out there who don't have cyber security incidents despite being huge targets, what are they doing? Insurance is also a thing if companies are that worried about fines or getting sued.