Live data from Hacker News

A 96 Bitcoin ransom payment ends up on Bitfinex

jpkoning.blogspot.com

111–120 of 126 posts

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#111
post #102
post #85

Earlier quoted context omitted.

anything useful on bitcoin cash is easily ported to bitcoin, vice versa. with cashfusion not even the server owners know which transactions belong to who, which isnt the case with normal mixers[1]. [1] https://medium.com/@james.waugh28/is-cashfusion-really-anony...

No, it's not "just copy it" because Bitcoin Cash has some OP codes that Bitcoin doesn't have. See OP_CHECKDATASIG for example.

if OP_CHECKDATASIG is beneficial btc can implement it

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#112
post #98

Earlier quoted context omitted.

You said "Bitcoin works like the coffee example not the bike." after "Now you can't identify your distinct stolen coffee anymore." But you can identify distinct stolen/tainted Bitcoin. Just like you can identify distinct stolen banknotes. The difference (according to the article) is that banknotes have special legal status meaning that they're effectively fungible after being spent.

Only after the coffee goes in the big container full of lots of other coffee is it rendered unidentifiable. If the coffee vendor didn't pour the stolen bag of beans into the rest of it then it's still clearly identifiable. Bitcoins are not quite like the a banknote. If I have a $1 and $20 bill that's 2 things each with a serial number. I can give them to you, and you can give them back to me. Bitcoins on the other ha…

However as the exchanges are visible it is easy to know the exact amount that has to be returned, therefore theft of such property has a clearly known value (plus damages) as if you kept a precise ledger.

Said value thus does not have to be decided in court to be returned - the question is, do you have to return it in cash of choice or Bitcoin?

The big question is how you find the responsible ransomer if they used a mixer, and whether mixer is culpable for not following KYC for big transaction amounts.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#113
post #96

Earlier quoted context omitted.

Due diligence is not sufficient in the interesting cases. If exchanges instituted a blacklist of known ransom payments, for example, ransomware authors would just wait until the coins have been changed into some other untraceable form before releasing their hostages. Blacklisting the transaction in time to do any good would be the same as not paying the ransom. Reporting the address after the fact can only harm innoc…

Making the receiving parties intent in covering losses can help a lot during discovery. Dragging "innocents" into it might just get us to a system that makes it hard for extortionists. And that system might not look like the Bitcoin we know. You can argue that we should suffer the extortionists for other benefits we get out of Bitcoin. I'm not convinced at this point.

> Dragging "innocents" into it might just get us to a system that makes it hard for extortionists.

If you're willing to harm innocents for the sake of your cause—even if the goal is to make things harder for extortionists—then you're no better than those you're fighting.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#114
post #45

There already is such tracking going on, exchanges do freeze balances sometimes. The problem is that if the stolen coin gets traded before exchanges can freeze them you wind up with a lot of innocent people holding those coins and it's not practical to freeze those later. Consider these two scenarios: A stolen bike vs a stolen sack of coffee. In the case of the bike, if you can find it you can take it back from someo…

Yeah, but for bitcoin ransoms, isn't one big difference (from the coffee case) that you know the destination address long in advance? In that case, it's much harder for it to reach the point of "too distributed".

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#115
post #11

Earlier quoted context omitted.

You can write down the serial numbers of paper money you hold, but that's not going to help you recover the money if someone steals the money and spends it at a shop. Traceability doesn't need to be a problem.

Governments are unlikely to give cryptocurrencies the same legal privileges as the currencies they issue. As such, traceability will remain a risk for anyone receiving cryptocurrency payments. If a chain analysis reveals an illegal transaction as a precursor, it's going to be considered stolen goods, not money, as the article states.

> Governments are unlikely to give cryptocurrencies the same legal privileges as the currencies they issue.

That's fine, but if the governments don't take action it'll be up for the courts to decide that.

>it's going to be considered stolen goods, not money, as the article states.

This is not at all obvious. It's not even clear that the nemo dat rule would apply to any kind of ransom payment.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#116
post #96

Earlier quoted context omitted.

Making the receiving parties intent in covering losses can help a lot during discovery. Dragging "innocents" into it might just get us to a system that makes it hard for extortionists. And that system might not look like the Bitcoin we know. You can argue that we should suffer the extortionists for other benefits we get out of Bitcoin. I'm not convinced at this point.

> Dragging "innocents" into it might just get us to a system that makes it hard for extortionists. If you're willing to harm innocents for the sake of your cause—even if the goal is to make things harder for extortionists—then you're no better than those you're fighting.

I see this as an example where the ends can justify the means. The maximum loss those people could incur would be the sums exchanged. If those are restored to the damaged party I don't see how there's a good reason to protect the people who traded. They can still demand restoration from their partners after all. If they traded with crooks, they might get nothing back. Such is life.

To say this is the moral equivalence of extortion is a long shot.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#117
post #15
post #11

Earlier quoted context omitted.

You can write down the serial numbers of paper money you hold, but that's not going to help you recover the money if someone steals the money and spends it at a shop. Traceability doesn't need to be a problem.

Untraceability sidesteps getting courts or lawmakers to give you legal status as money. I don't see why governments have any motivation to extend this protection to cryptocurrencies as it would seem to mainly facilitate crime without providing any benefit in terms of encouraging adoption of government controlled currency.

>I don't see why governments have any motivation to extend this protection to cryptocurrencies

The governments don't need to do this, the courts do. There's an existing principle they could very cleanly apply here.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#118
post #45

There already is such tracking going on, exchanges do freeze balances sometimes. The problem is that if the stolen coin gets traded before exchanges can freeze them you wind up with a lot of innocent people holding those coins and it's not practical to freeze those later. Consider these two scenarios: A stolen bike vs a stolen sack of coffee. In the case of the bike, if you can find it you can take it back from someo…

The problem is that the stolen coin has been traded before exchanges froze them you, if wound up with a lot of innocent people holding those coins, every alleged victims should reach davidveksler(at)engineer com, he is an expert in applied crytography.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#119
post #111
post #102

Earlier quoted context omitted.

No, it's not "just copy it" because Bitcoin Cash has some OP codes that Bitcoin doesn't have. See OP_CHECKDATASIG for example.

if OP_CHECKDATASIG is beneficial btc can implement it

With Bitcoin's history of extreme hardfork aversion, it's not that simple. In theory you're right, but in practice it's much harder.

Re: A 96 Bitcoin ransom payment ends up on Bitfinex

#120
post #101

Earlier quoted context omitted.

> The problem is that if the stolen coin gets traded before exchanges can freeze them you wind up with a lot of innocent people holding those coins and it's not practical to freeze those later. Isn't this fundamentally _not_ how it works in the traditional financial world? If you are paid in ill-gotten money it can certainly be clawed back no matter how innocent you are.

Are you sure? Do people in some countries lose their money if they, for example, sold their car to a bad guy?

In the US, stolen property is the property of the person it was stolen from. If you bought a stereo from a pawnshop and it turns out it was stolen, the original owner gets his stereo back and you get to try and reclaim your money from the pawnshop. Anything else would create perverse incentives like the grandparent describes.

This rather prominently came into play during the 2008 financial crisis when it turned out banks were forging wet copies of the original mortgage paperwork on foreclosed properties. When banks realized that it was a problem, title insurance started specifically excluding this, so the original owner could take their property back and you would end up with a mortgage on nothing.

Post reply on HN