Banning ransomware payments is an incredibly attractive idea.

Proponents need to explain why it’s going to work any better than bans on buying drugs. Why will two “willing” participants not going to find a way? What do we gain by adding criminal penalties to victims trying to recover their businesses?

@adamshostack @hacks4pancakes well, while 2/3 people can palm a $100 to transact a drug deal on the street, ransomware payments involve many more ppl - an insurer and/or vastly more money which one person at a corporation tends not to trivially be able to send without accounts asking questions.

The hope wld be make paying much less attractive in the hope it might lead to money being invested up front or at least less self delusion of having “secured” the data.