After all, finding such villains is not enough; you also need to compel them to stop, and in most cases I can imagine, they will be reliably protected by their contracts.
анонимный вопрос
And in a world where there is a state monopoly on violence, and in a world where the enforcement of rights is handled by private parties, and even where, as discussed in a recent post, violent collections are extremely limited, the strategy for fighting hacking groups is generally the same: to increase the cost of the attack.
To jump on a trendy topic, let’s liken the activity of a hacking group to the spread of an epidemic. You can invest in individual protection, you can make the transmission of the infection more difficult, or you can find its source.
A hacking attack can cause irreparable harm immediately. For example, a hacker steals your private keys, and your bitcoins vanish to someone else’s address. A virus can also encrypt your disk and demand money for decryption. If you send the money, the data will either be decrypted or not, depending on the strain you were infected with. An attack can also simply cause noticeable inconvenience, as in the case of a DDoS attack, for instance. For the state, catching hackers is long and expensive, and the barrier to entry into the market for such attacks is not particularly high. For a private individual, finding a hacker and preparing a body of evidence would also be costly. Thus, it is unlikely that the cyber-epidemic situation in a stateless society would be fundamentally better.
Since the cost of catching a hacker is high and the probability of success is not very great, there is every reason to impose quite large fines, in addition to damages, on those unlucky few who are actually caught. You can read about the principles of calculating fines in “The Mechanics of Freedom,” in the recently published Chapter 43.
What happens if a hacker is caught, but nothing can be seized from them? For example, they claim they forgot the wallet key. There are no legal grounds to apply thermo-rectal cryptoanalysis, and besides, it provides no guarantee of a result, as the key may indeed be lost. In this case, the only option is to impose installment payments on them, and let them compensate as new legal earnings appear. Or, perhaps, they will decide to speed up the process by remembering the key.
For the end user, I would recommend passive protection methods and insurance. As for the actual catching of hackers, let insurance companies pay for it on a systemic basis if they deem it a market-efficient measure.