Hacker News new | ask | show | jobs
by jszymborski 1805 days ago
The main perverse incentive I see here is that it encourages companies to hide the fact that they've had a breach so they could pay the ransom w/o consequence.

I do think regulation making ransoms hard/impossible to collect is the way to stopping the immediate problems posed by ransomware.

More disturbingly, however, is that such hacks just underpin how vital infrastructure is exposed to nation states. When the motivation isn't collecting a ransom but rather to disable a country's vital infrastructure, such regulation would do little.

2 comments

"I do think regulation making ransoms hard/impossible to collect is the way to stopping the immediate problems posed by ransomware."

That's rather difficult to do in the current cryptocurrency environment.

Couldn't you make disclosure mandatory and impose significantly higher (business ending levels) on failure to disclose?