Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Arresting malware distributors and seizing their domains threatens the free internet?

Doesn't allowing near-infinite amounts of scams, fraud, and other abuse threaten the free internet far more than arresting bad actors?



Like seriously, that was like saying that arresting the purveyors of contaminated, tainted meat is harming the food supply. It’s an argument that seems to be intentionally reversed in order to destroy logical debate.


Could it be that the original commenter is saying state and corporate spying gets justified with these kind of succesful and positive operations, and this gives states the goodwill to push for deeper surveillance, which is then used unethically?

Think how the world changed after the PATRIOT (lol) act, and how many terrorists have been actually detained in exchange for such invasive measures on the general public. I'd bet the most benefited from all these years of mass surveillance have been advertisers, not law enforcement.


> Could it be that the original commenter is saying state and corporate spying gets justified with these kind of succesful and positive operations, and this gives states the goodwill to push for deeper surveillance, which is then used unethically?

I think so, but this is backwards. State and corporate spying gets justified by the scammers and fraudsters, not by whether or not the takedown operations are successful. If scammers and fraudsters weren't doing wildly unpopular things like taking health care systems hostage with ransomware, etc, we'd all have a lot more ammo to tell the cops to respect our privacy.


I've worked on several high-profile botnet takedowns that have resulted in arrests. There is a very fine line and a slippery slope that you absolutely need to stay on the right side of, or things can become very invasive and unethical[0].

Online scams, fraud, and malware have been around since the '80s, and we've survived.

Additionally, a huge industry has been built around it, employing many people and generating massive amounts of wealth compared to the direct costs of these activities. Just compare the cost of ransomware to the "cost of cybercrime"[1][2] which is mostly revenue for the cybersecurity industry, and there is a magnitude of difference.

[0] https://www.vice.com/en/article/qj454d/private-intelligence-...

[1] https://www.bleepingcomputer.com/news/security/ransomware-pa...

[2] https://www.weforum.org/agenda/2024/01/cybersecurity-cybercr...


> Online scams, fraud, and malware have been around since the '80s, and we've survived.

That's a really awful take. We've also had plagues killing large chunk of population and we've survived. That doesn't mean it wasn't an issue for people affected. There are people who have lost their life savings and relationships due to scams. There's an individual/society cost to all of this.


That's a bit of a unfair comparison.

In the context I was discussing I consider it a pragmatic take because our response to these issues needs to be understood across multiple domains including privacy.

That's not to say that nothing should be done. Personally, I'd like to see measured legislation placing more security, privacy and liability onto manufacturers and providers.


You consider total ransomware payments the "cost of ransomware"?

And the revenue of the cybersecurity industry the "cost of cybercrime"?

You seem competent, me I don't know much about practical cybersecurity.

But the combined cost of companies or medical facilities being infected by ransomware surely is not covered by the total ransom payments, right?

Sorry if I'n grossly misunderstanding your take, but I struggle to make sense of it.

I see however your point about surveillance.

And also, affected companies and institutions + the software companies, consultants etc they work with should carry a certain responsibility in some cases.

For example, a social engineering breach with one employee who had normal privileges shouldn't allow to easily propagate over the whole network etc


The true cost of any of this is very hard to quantify. There are reputational costs (though you generally want to buy the dip after a hack), national security concerns, intellectual property theft, etc. So, it is a weak argument in that regard, but that's only because there's not a lot of good data to even form a solid opinion on. Sorry if my comment seemed a bit ambiguous.

Personally, I have seen during incident response many organizations drop seven figures on EDR, IDS/IPS, and a bunch of widgets while ignoring or refusing to do simple things like network segmentation and configuration/patch management, and it's because they've been sold silver bullets by their vendors, so I also hold a bit of contempt for the industry as well.


>network segmentation

This gives me flashbacks. I worked in hospital IT for a few years, and the main IT office was constantly trying to fold the (unpatchable, running a mix of OS2, win95, win98, MSdos, and proprietary OSs in -2007) medical devices into the main, internet accessible network.

I had to spend countless hours in meetings to keep them segregated. At times, I actually had to just pull fiber jumpers out of the switch. They’d eventually have a fit because they couldn’t see the medical devices with their threat scanning software.

They could have just hooked up a laptop to the medical device network and said “yep, every single ip address on there is vulnerable” and sent a strongly worded letter to each manufacturer demanding a patch, which will never be released. Since the devices are FDA certified medical devices, you can’t just patch them without manufacturer endorsement of the software change…so any device more than a few years old is usually vulnerable.

3 months after I left they had a major ransomware event. Weird. Who could have imagined?


Yeah, I was also thinking about hospitals and other crucial infrastructure where ransomware attacks have even cost lives.

I got your point though, that's why I edited in the paragraph about accountability.

Thanks for your insights.


Law enforcement industry partnerships weird me out a little bit too. Cases like this are maybe a little more innocent: https://www.wired.com/story/big-pipes-ddos-for-hire-fbi/. But then you have Spamhaus compiling literal dossiers and sharing them with police and pressuring hosts into sharing information to help with their extrajudicial ROSKO investigations. Or the "Shadowserver Foundation," which ostensibly exists to stop botnets, yet also for some reason hosts the seizure page for Liberty Reserve.


> Additionally, a huge industry has been built around it, employing many people and generating massive amounts of wealth

That's an unfortunate but necessary cost, not something to be happy about. It's as much a positive argument as the broken window fallacy.


Are we following the rule of law here? We are talking about arresting bad actors, built on the fundamental principal of due process. There are rules to follow. If the department of justice wants to bring criminal charges against individuals or corporations, should the first step be 'sieze all assets'? When is the doj allowed to sieze assets, if we think its a scumbag foreigner but what if its an upstanding american tax paying LLC? Should your business be subject to immediate takedowns while the doj investigates and attempts to prosecute you?

Has anyone been convicted of anything? We are siezing control of personally owned assets under the presumption the responsible parties will be found guilty. That seems like a slippery slope.


Why are you assuming that rules weren’t followed? Is there any reason to suspect this? I’m not the greatest fan of the police by far, but it’s not like this (seizing assets without prior conviction) is a novel or anything but standard procedure happening in the frame of clearly defined rules. Should a murderer run free up to his conviction, even when there’s strong evidence of his crimes? Shouldn’t the police seize assets of drug cartels at the moment they can instead of years later when everybody is convicted?


Monitor the transactions, collect evidence, get warrants, seize things, collect evidence, get arrest warrants, etc.

if someone is dumb enough to register with a real name, the amount of time needed to coordinate it can be reduced.

like with the 911S5 botnet, they got evidence over the years to build a case to arrest them.

if it's a large group of people, it may take time or a turncoat to slowly gain evidence on the other parties.

seizure of assets in those countries required the police and courts in those countries to have probable cause that yeah it was definitely related to the crime and necessitated seizure in a coordinated fashion. This is similar to the coordinated quiet takeover of a darkweb market, or the coordinated spooky takedown of another, to scare criminals onto the bugged one.


A free internet allows a degree of lawlessness.


depends on your definition of free




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: