Don’t Miss a Post. Subscribe now.

New Battle Cry: We Need to Ban Cryptocurrency to Fight Ransomware

Here’s an attack on cryptos from a new angle.

Lee Reiners, executive director of the Global Financial Markets Center at Duke Law, says in a WSJ Op-Ed  Ban Cryptocurrency to Fight Ransomware

No one is out of reach from ransomware attacks. The Colonial Pipeline hack made that clear, along with the nearly 2,500 cases of ransomware—a form of malware that encrypts computer files and holds them for ransom—reported to the Federal Bureau of Investigation last year, a 66% annual increase. In 2020 ransomware victims paid hackers $350 million in cryptocurrency. Since many victims pay ransom without reporting the incident, these numbers understate the damage.

The solutions floated after the Colonial hack—improved cybersecurity in the private sector and public-private collaboration to protect critical infrastructure—are pro forma and inadequate. There is a simpler and more effective way to stop the ransomware pandemic: Ban cryptocurrency.

Ransomware can’t succeed without cryptocurrency. The pseudonymity that crypto provides has made it the exclusive method of payment for hackers. It makes their job relatively safe and easy. There is even a new business model in which developers sell or lease ransomware, empowering malicious actors who aren’t tech-savvy themselves to receive payment quickly and securely. Before cryptocurrency, attackers had to set up shell companies to receive credit-card payments or request ransom payment in prepaid cash cards, leaving a trail in either case. It is no coincidence that ransomware attacks exploded with the emergence of cryptocurrency.

Obvious Attack

This is an obvious attack, yet it is one I missed.

I have mentioned fraud, money laundering, energy usages, and tax evasion as reasons to expect more government attacks on cryptos.

HODLers still believe Bitcoin will be impervious to governmental regulations.

I strongly disagree.

One Simple Question

Bitcoin Supporters Cannot Answer One Simple Question

What would happen to the price of Bitcoin if the US did not allow merchants and banks to make Bitcoin transactions?

Ban Bitcoin? Why Bother?

It is not necessary to ban Bitcoin to kill it. 

Alternatives

  1. Ban transactions making it impossible to get hard currency in or out.
  2. Tax Bitcoin energy use
  3. Tax Bitcoin profits at an enormous rate

Ultimately I expect the governmental method of attack will be #1 and possibly #2. 

What’s the Trigger?

The above article is most likely meaningless. It’s just one opinion.  

But it will not be meaningless once the Fed or US and EU governments concur. 

There may be no hint when it happens. Tether cold easily be the trigger. 

So could a another ransom attack that wildly succeeds. 

Serious Questions

We have already seen on numerous occasions Trump putting in place absurd tariffs on grounds of national security.

Might we not see Biden do the same on cryptos?  

Perhaps it’s still a far off concern, year’s away. Perhaps it’s this year, without warning.

However, a major coordinated government crackdown is coming and Bitcoin will not be impervious when that happens.

Bitcoin a Free Market Construct

I do not support these attacks. Bitcoin is a free market construct. 

If people want to speculate, what business is it of mine? (Other than the cause of intense speculation – The Fed and free money from Congress).

Rather, I simply point out the methods I believe governments and central banks will ultimately use to squash it.

Tether fraud is another matter. 

Investigating the Charge “Bitcoin Price is Dependent on $60 Billion Accounting Fraud”

In case you missed it, please see Investigating the Charge “Bitcoin Price is Dependent on $60 Billion Accounting Fraud”

Feelin’ Lucky?

Mish

Subscribe to MishTalk Email Alerts.

Subscribers get an email alert of each post as they happen. Read the ones you like and you can unsubscribe at any time.

This post originated on MishTalk.Com

Thanks for Tuning In!

Mish

Comments to this post are now closed.

32 Comments
Newest
Oldest Most Voted
EWM
EWM
5 years ago
What would happen to the price of Bitcoin if the US did not allow merchants and banks to make Bitcoin transactions? That idea was suggested by a politician on the other side of the ocean. His assassination was completed within a week.
cmc
cmc
5 years ago
Another option is to add layers and layers of bureaucracy until the crypto market suffocates.  I suspect this option will happen because it creates new regulatory
bloat and bureaucracies always love bloat.
Webej
Webej
5 years ago
No one is out of reach from ransomware attacks
Of course they are out of reach if the devices have no (bridged) connection to the internet.
Absurd that Colonial would have critical control devices connected to the internet.
Make sure any control equipment is not, remove any USB devices and harden PC’s in a few more ways, voila.
Colonial even has its own right of way and could simply run their own fiber for physical separation and convenience.
What part of ‘critical’ do people not get?
The solutions floated after the Colonial hack—improved cybersecurity in the private sector and public-private collaboration to protect critical infrastructure—are pro forma and inadequate
There is not need for all kinds of higher league security experts.
Ransomware only affects files, so if you can restore them, there’s hardly/no problem.
Using modern backup techniques (shadow volumes/copy-on-write), you can always return to previous versions of files and databases (they use atomic transactions, integral consistency, and journaling logs). Just make sure your version histories are granular enough for your ends and don’t thin version histories if you have low confidence in how long ago the last undetected ransomware incident was.
Felix_Mish
Felix_Mish
5 years ago
Reply to  Webej
“critical control devices connected to the internet”
Apparently, the attack was not to pipeline control but to the billing system. And, the first thinking was it was a social attack or normal email phishing.
Anyway, the pipeline worked just fine, but they couldn’t bill (or account?) for the material going through the pipes, so they pulled the plug. Kinda funny, really, when you think about it.
TexasTim65
TexasTim65
5 years ago
Reply to  Felix_Mish
Correct. And of course they were publishing all the info on the customers so it was an embarrassment factor and lost of trust. Then customers have to fear their passwords and credit card info are compromised on other sites and so on.
Webej
Webej
5 years ago
Reply to  Felix_Mish
Yes, I read that, but it doesn’t make too much sense and sounds like an attempt at PR damage control.
You don’t take refineries, pipelines, thermal plants, etc. offline because of a glitch in keeping track of payments.
The costs of shutting down and starting everything up again are too great, and it can take days to stage all the moving parts properly.
You keep stuff moving or adjust throughput and figure out/adjust the paperwork later.
If billing and customer relations are critical infrastructure, then so is baby sitting.
Felix_Mish
Felix_Mish
5 years ago
Reply to  Webej
@Webej – I had the same thought. But, as my first reaction to reading the “billing explanation” was laughter rather than scorn, experience says it’s a completely possible explanation. Or, put another way, couldn’t an outfit in this biz who managed to get themselves ransomwared be reasonably expected to stop operations because someone in HR was late filing their Form 11G-3 this month? OK. That’s being unfair. Sorry, Colonial Pipeline Inc.
TexasTim65
TexasTim65
5 years ago
Reply to  Webej
You do realize there is air-gap malware. It’s used by government spy organizations very successfully. So while air gap absolutely helps, it’s not fool proof.
Running your own fiber is absurd. The cost would be in the billions. It’s cheaper to just pay a few million in ransom now and then.  That’s the general problem with hardening things. It costs too much relative to paying up / chances of ever being hit.
Webej
Webej
5 years ago
Reply to  TexasTim65
Exotic tricks like air gap still require you to install and run code on machines in physical proximity, and amount to a bridged connection to the internet. But too get the malware on the machines is impossible if you cannot connect in the first place.
As for your own fiber, it’s not billions but millions (< $10,000/mile including fiber)
TexasTim65
TexasTim65
5 years ago
Reply to  Webej
Even if it’s just millions (hundreds of millions for the distances involved) and years of effort to lay the fiber, why bother. It’s still cheaper to pay a few million in ransom.
Its sort of like shoplifting losses. As a store you can double (or triple etc) your shoplifting budget to lower your losses but if doubling the budget costs more than the losses it’s madness to do so.
Webej
Webej
5 years ago
If you have a baby who spills food on their bib, you could solve it by having no bib. After all, the bib is enabling the kid to spill by reducing its cost.
Alternatively, you could ban vegetables, or you could ban clothing.
Once you starting thinking along these lines, there are soo many ways to get rid of ransomware.
TexasTim65
TexasTim65
5 years ago
#1 is the easiest way.
Not many people will run VPNs and flout the law just to dabble in crypo as an investment. Especially if it’s all but impossible to get money in/out once US banks are forbidden to transact with any crypo exchange.  Especially if fines/jail time is the price for doing so and the gov’t dangles the carrot of ‘fink on a friend about crypo and get paid some $ if it proves true’ causing banks to start looking for suspicious money flows from foreign sources.
It also means you won’t be able to go to yahoo finance and find the price of crypto in US dollars nor will it be able to be discussed on financial channels or invested in by hedge funds etc. If you think otherwise, try and find some website/finance show etc discussing the price of an 8-ball of cocaine in US dollars.
frozeninthenorth
frozeninthenorth
5 years ago
Reply to  TexasTim65
Tons of people use VPNs and they do so for their own security.  If you’ve ever stayed in a hotel using a VPN is standard practice since their network are rarely very secure, a simple and cheap software will provide that protection.  Honestly, I think that not using a VPN is careless
Zardoz
Zardoz
5 years ago
What needs to happen is all these internet connected systems be hardened against that kind of attack.  A ransom is one thing…. a foreign adversary, or random crazy person simply destroying millions of systems to sow havoc is quite another.
Morn
Morn
5 years ago
Reply to  Zardoz
This is a huge argument for the adoption of decentralized databases based on blockchain tech – cryptos, in other words.
Zardoz
Zardoz
5 years ago
Reply to  Morn
No, not really.
TexasTim65
TexasTim65
5 years ago
Reply to  Zardoz
Costs more than it’s worth in most cases.
The US spends 20 billion a year on anti-terrorism with in the US. It’s a crazy amount of money and as far as I know we’ve never prevented a single terrorist attack (never seen a single headline about it and you know it would be front page news if we did). Gov’ts can waste that kind of money but few businesses or individuals can.
Zardoz
Zardoz
5 years ago
Reply to  TexasTim65
Unlike Sept 11 Security Theater, there are actually proven techniques to prevent hacking.  It’s an engineering problem.
TexasTim65
TexasTim65
5 years ago
Reply to  Zardoz
Yes its an engineer problem. But it’s also a cost problem and what’s worse is it’s unknowable how large a cost because it requires constant vigilance since technology is forever changing and most problems aren’t detected until after something goes wrong.
So you spend millions a year on security you might be better off not spending anything and just paying the ransom if/when it ever happens to you. This is essentially what Ford/GM do when they decide a recall is too costly and it’s cheaper to just pay out some lawsuits. For smaller companies they may not be able to afford thousands a year.
Or put it another way. Maybe companies should just pool some cash together as a quasi insurance fund and if any one of them gets hit, they just pay out of their insurance fund. There’s a good chance that’s cheaper than all the equipment and software necessary.
Zardoz
Zardoz
5 years ago
Reply to  TexasTim65
It’s not just ransom you need to worry about.  Hackers can destroy your data and equipment if so inclined.
PostCambrian
PostCambrian
5 years ago
Put a 25% withholding tax on Bitcoin transactions with the withholding returnable upon filing income taxes and paying any capital gains on the Bitcoin.
Bam_Man
Bam_Man
5 years ago
It has never been anything more than a gambling token and clearly never will be.
Zardoz
Zardoz
5 years ago
Reply to  Bam_Man
Makes the perfect reward for illegal behavior.  I sense a real synergy here!
Morn
Morn
5 years ago
A lot of what goes on in the crypto space isn’t even focused on the “crypto-as-payment” mechanism and calling them crypto-currencies at all is an unfortunate legacy that promotes a lot of misunderstanding.  “Work Tokens” is a better term (although not perfect) and they are better understood as distributed computing projects that perform different functions for the given blockchain for which they’ve been developed.  Essentially, it’s just software, the equivalent of running Folding@home or SETI@home on your personal computer, albeit with a relatively novel means of encouraging participation and the ability to profit from your services.  The creation of the “token” and requirement that a minimum amount be staked, or dedicated, in order to validate/process information, creates the demand and the resultant value of that particular token – with heaps of speculation added.  You’re then also paid in the native blockchain token (Ethereum, the theoretical value -absent speculation and fed funny money – of which is tied to the total value of economic activity taking place on the network, for example) as your network transaction fee.
That’s not the whole of it, but it would be unfortunate if this is strangled in its infancy due to ransomware attacks.  I suppose if you believe that decentralized blockchains have no future economic value you may think the tradeoff is worth making.
Doug78
Doug78
5 years ago
Governments could take it down if they wanted but the cost might not be worth it. It would be more useful, more secure and cheaper if they could drive them onto highly regulated exchanges where they can become integrated into the financial ecosystem. They have gotten big enough for that to become necessary. Another thing I keep hearing is that Bitcoin can’t be traced and that is wrong. They can be and they are traced. You can bet that finding ways to trace crypto transactions has been a major priority of just about all the big security agencies since the beginning. I would even say that they have all been pretty much penetrated already so you can forget about the secrecy issue. 
Eliminating cryptos would not eliminate ransomware at all. They would just demand payment in other very creative ways.
Eddie_T
Eddie_T
5 years ago
Reply to  Doug78
They haven’t ALL been penetrated. Not Monero, or a few others. Maybe they could do it with quantum computers.
In general, ordinary citizens are easy to bust, because they take money from their bank account or use a credit card to make their buys, and they put their wins into dollars again, so TPTB can see the money going in and coming out, at least. 
Coinbase was forced to let the government look behind the screen, since they are trying to be 100% compliant with all US regs. 
Morn
Morn
5 years ago
Reply to  Doug78
“Eliminating cryptos would not eliminate ransomware at all. They would just demand payment in other very creative ways.”
If allowed to thrive and grow as a technology, blockchain services (“Cryptos”) can actually help provide the solution to these growing pains.
frozeninthenorth
frozeninthenorth
5 years ago
Granted ransomwear presents the best BS reason to kill cryptos.  Eventually the US government will look for a way to try to kill cryptos, I wish them luck. Once institutional investors are playing the game it will be a hard conversation.  Also we are coming to the end of mining, already Etherium is moving to a new model, where mining plays a smaller and smaller role — also Ether take a fraction of the energy that bitcoin requires.  Although I seem to remember that bitcoin is limited to 25 million coins.
But you are right the government will try to kill it, I don’t think it will work, 90% of all crypto transaction are already on the dark web.
Too little and too late
Scooot
Scooot
5 years ago
I expect the authorities thought cryptos would fail on their own at some point but I think they would definitely like to ban them now. The problem they have is how to do it in an orderly way. Any suggestions anyone?
Eddie_T
Eddie_T
5 years ago
I think it’s a fairly valid argument, fwiw. Ransomware attacks would go away without bitcoin. QED.
Silly rabbit, money creation is for bankers, not libertarian tech entrepreneurs.
goldguy
goldguy
5 years ago
100% correct Mish, its just a matter of time before our government bans all of it.  
KidHorn
KidHorn
5 years ago
If crypto currency ever does become a mainstream method of payment, people won’t be using bitcoin or whatever is available now. They’ll be using a government issued crypto currency that the gov’t can create more of out of thin air.

Decorate Your Walls with Mish Fine Art Images

Click each image to view details or purchase in the store.

Stay Informed

Subscribe to MishTalk

You will receive all messages from this feed and they will be delivered by email.