Remix.run Logo
bombcar 9 hours ago

Your "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.

Kostchei 9 hours ago | parent | next [-]

interestingly, having actually done the law enforcement side of these investigations, 50% of them are local. And I understand that this is not 100% solution, but neither is any form of law enforcement, but that doesn't mean we should fail to attempt it.

Kids from the local uni having a lark, stalkers, vindictive ex employees, local gangs, criminals who understand their victims because they hail from the same community. These are your local hackers. Sift them from the nation states and international crime groups, then deal with the International as a matter of diplomacy. Because we do this so poorly locally, we have little ammunition to when it comes to diplomacy. "reduce attacks by your crime groups and we buy your natural gas, seel you wheat etc"

Want more motivation?- 75% of the local attacks by volume send funds back to terrorist or separatist organizations.

It is not an in-soluble problem. Sentences are a fraction of the answer, effective and receptive reporting processes are more important, then government backing for investigation and enforcement, then policy around home-team activities (ie don't do the bad things yourselves Mr Gov). Deterrence comes after all that.

Aurornis 8 hours ago | parent | next [-]

One tech ransom case I know of was an inside job. It definitely happens.

There are already significant penalties for doing anything like this. The guy involved is in prison for a very long time. I don’t recall the exact number of years but I do remember it was so long that he wasn’t going to see his kids grow up.

I don’t think anyone who puts a little thought into a crime like this doesn’t understand that the penalties are already very huge. You don’t get a slap on the wrist for extorting a company (or person, for that matter)

hluska 8 hours ago | parent | prev [-]

50% of ransomware attacks are local to where? You’ll need to cite some sources because I don’t believe that is possible.

nullsanity 8 hours ago | parent [-]

To the country or an ally of the country they are targeting, duh. it doesn't matter if you believe it, it's been the truth for over a decade. Heck, Sh1nyHunt3rs people were arrested in the UK recently.

da_chicken 9 hours ago | parent | prev | next [-]

Yeah, they identified themselves as ShinyHunters, and the IP they've put on the demonstration page is geocoded to Russia. Notice this is the same group responsible for the Infinite Campus hack last year.

Really, though, if you want someone to blame, Instructure is not a particularly compelling target. Let's review:

1. Iran is intentionally targeting infrastructure due to a war started by the current administration.

2. China is actively seeking corporate secrets to steal and commercialize for themselves, spurred by extreme protectionism and retaliatory tariffs.

3. North Korea is doing anything they can -- including just taking a remote job by proxy -- in order to extract any money.

4. And Russia is working with and aiding all of them, after everything else going on has forced the embargo to break.

5. All of this while completely alienating every single one of the United States' allies.

6. Meanwhile, the American DHS is currently shut down.

7. And this is after Trump cut funding and personnel for CISA severely enough they've had to end the contract with MS-ISAC, meaning all state and local entities can only remain in the organization if they foot the bill for it directly and CISA and other agencies responsible for cybersecurity are more thinly staffed than they have been in decades.

In short, the current administration systematically disassembled all the protections we have built over the last 100 years, and then placed infrastructure -- schools, in this case, but also power companies, water treatment facilities, communications companies, local governments, hospitals, food producers -- directly on the front lines of the modern geopolitical conflict.

That vast ocean that has kept us safe historically is a poor moat in the modern era.

vasco 7 hours ago | parent [-]

Having an IP in Russia means about zero regarding their location. Literally anyone doing anything like this is going to get a Chinese or a Russian IP for obvious reasons. Mostly decoy and people like you.

elictronic 8 hours ago | parent | prev [-]

Complete internet blockage of nations allowing the attacks. If foreign governments are you can always execute them. We are living in a different world where this is no longer a zero probability occurrence.

Bud 7 hours ago | parent [-]

[dead]