Hacker News new | ask | show | jobs
by kemonocode 1823 days ago
If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.
2 comments

In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today.

There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the source immediately at that scale. There's only so much money you can move through services that give you kickbacks of various kinds. What else is left?

Basically unless ransomware teams know of a new really good way of laundering money without a trail, or are happy to take a massive pay cut, that would be the end of most of their operations.

>...theoretical universe where banning crypto is possible...

Money grows on trees, there, too.

I'll bet you dollars to donuts that if you made crypto illegal, there's still a whole lot of countries that won't give a shit and the problem will only get worse.

All these situations are nebulous and complicated, something as simple as legally banning crypto is not going to solve the problems.

Suitcase full of gold coins delivered somewhere in Russia would be an easy replacement for crypto coins.
That doesn't sound easy at all.
There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.
Then you hire the services of brokers that don't have the same compunctions about transacting in crypto. And even if you were to magically erase all cryptocurrency from the earth, it wouldn't still stop ransomware, or the same state sponsored actors would gravitate towards even worse things.

It's like nobody has learned a thing from the war on drugs, my point being: you deal with the root cause of the disease (infosec in most companies and even government offices is a joke and bad people have taken notice), not playing whack-a-mole with the symptoms (crypto use) that hint towards systemic decay.

The root cause is the blackmailers/thieves committing the crime, not that the crime was easy. Addressing the root cause might include things like improving education and reducing poverty. That in combination with a bam on paying ransoms would likely reduce these crimes.
There was ransomware before crypto currencies. There will be ransomware after crypto currencies.
There was? How did it work? Bank transfers?
Yes, actually, people overestimate the reversibility of wire transfers. And before cryptocurrency, there were still shady money services such as Liberty Reserve or Perfect Money with little qualms about their habitual clientele.
Ever heard of corporate kidnappings?
(not saying I think this is a solution, but...)

If the goal is to stop companies from paying ransom, then why not just make that illegal?

It is already illegal to pay most ransomware gangs in the USA:

https://home.treasury.gov/policy-issues/financial-sanctions/...

Better yet, add a 200% tax on top of ransom payments. That will tranfer the profits to the government. The attackers will know that the ability to pay is cut to 1/3.