Stronger investigative and enforcement actions is something we can do.
But it's something that we don't stomach. I wonder why. I suppose it's because the modern business-centric Internet is centered on the ability to scam people out of money. Investigations and enforcements would open the floodgates to every "normal" business too.
> To prevent this conversation from being painfully abstract, let’s scope it to one particular type of fraud against one particular type of actor: the bad guy steals a payment credential, like a credit card number, and uses it to extract valuable goods or services from a business. This is an extremely common fraud, costing the world something like $10 to $20 billion a year, and yet it is actually fairly constrained relative to all types of fraud.
> This fraud is possible by design. The very best minds in government, the financial industry, the payments industry, and business have gotten together and decided that they want this fraud to be possible. That probably strikes you as an extraordinary claim, and yet it is true.
Indeed! However, I would add that this article focuses on fraud perpetrated against businesses. While it does give good perspective I'm actually more concerned about fraud perpetrated by internet businesses against consumers.
The problem is it's cross-border. Domestic law enforcement will almost always run into dead ends, maybe they'll catch some money mule that got conned into the job, but that's it.
The real dent would be to get India (for US scammers) and Turkey (for German scammers) to cooperate, the way to do it would be to threaten devastating sanctions ("clean up your scammer scenes, or else"), but that cannot be done as it is important for geopolitical reasons to appease India (a significant portion of the world's pharmaceutical base compounds originate from there, not to mention the Ukraine conflict) and Turkey (same reason, Ukraine conflict + about 2 million Syrian refugees that Erdogan already abused as a political weapon once).
Phishers benefit from low domain prices because they can churn them faster than you can investigate them. Scams are fast, investigation slow.
Worse, you investigate only to find that the scammer is out of your jurisdiction (which I submit is the #1 problem with “enforcement”) and there is very little you can do. Also, if they can churn domains quickly, the thread that connects them is harder to find, so you only have the remnants of one or two scam domains where there may be hundreds more by the same perpetrator.
But it's something that we don't stomach. I wonder why. I suppose it's because the modern business-centric Internet is centered on the ability to scam people out of money. Investigations and enforcements would open the floodgates to every "normal" business too.