Earlier quoted context omitted.
Lol this was my first reaction as well, they now have a nation-state on their ass. But that being said its not impossible that this was just a cover for a Russian state-sponsored attempt on US infra
"nation-state" is not just a fancy infosec word for country, and there's some debate as to whether the USA constitutes an actual nation state, rather than a state.
US passes emergency waiver over fuel pipeline cyber-attack
301–310 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#302Forgive my ignorance, but is it incredibly hard to determine the actual identities of the people behind this? I don’t know why a government wouldn’t simply assassinate culprits who were guilty of crimes at a level that would qualify as an act of war.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#303"Multiple sources have confirmed that the ransomware attack was caused by a cyber-criminal gang called DarkSide, who infiltrated Colonial's network on Thursday and took almost 100GB of data hostage." re: "infiltrated Colonial's network" I have been reading some of the other reports of this incident from different publications. Many of the stories include a line about attackers downloading "100 GB in only 2 hours" as…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#304Earlier quoted context omitted.
Who was it again that has the most effective intelligence community and military in the world?
I hope you're not talking about the CIA, whose network of agents in China (to pick one example) was rounded up and killed due to either shoddy IT work or a mole in the Agency. Either possiblity reflects poorly on the American intelligence community: https://www.reuters.com/article/us-usa-china-espionage-idUSK... >Investigators remain divided over whether there was a spy within the Central Intelligence Agency who betr…
Even still, do you expect any intelligence agency to be perfect? I’m not sure what point you’re trying to prove here.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#305* Critical infrastructure should not be allowed to run on Microsoft Windows
* The remote workers, through which the attack was performed, didn't even use a VPN, just TeamViewer and MS Remote Desktop.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#306Earlier quoted context omitted.
Make it a crime to possess, consume, or distribute substances that are bad for people. Make it a crime for people to knowingly withhold information about such activities from the authorities. Abuse of substances, trafficking, and associated criminality will go away. But seriously... > Make it a crime to pay the ransom in a ransomware attack. Ok, so ... what should a company do? File a report with some government agen…
I don’t see an analogy to drug laws. Is your point simply that such a law is impractical to enforce? Paying extortionists begets more extortion. The only argument I’m seeing is a bunch of hand waving and people telling me I’m being hopelessly naive. I don’t think I am.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#307Earlier quoted context omitted.
> I like how they are charging 10% more if you pay with Bitcoin than with Monero. I smell a business opportunity... Kick off a ransomware attack and accept Bitcoin or a Shitcoin at a 30% discount. Some shitcoins have such little liquidity... a 50k buy would push their price off by hundreds of percentage points. You can even refund their money back after they pay... a modern day pump/dump. The thing about being an eth…
Illiquid asset pumping is the best way to launder the money in the crypto space. AccountA has bought or owns the illiquid asset using clean money, in advance. AccountB has the ransom proceeds in the more liquid digital asset. AccountB eventually buys the illiquid asset and pumps it. All the blockchain detectives are still following AccountB across many more addresses and blockchains, hoping and praying and imagining…
Seems like they either, 1) sell periodically or as the assets value appreciates, but this is generally unreliable and tough or 2) create a liquidity pool or yield farming opportunities
For 1, this isn't necessarily reliable but it seems like the most plausible popular case. For 2, given the previously mentioned challenge of the illiquid asset, how does it work to provide incentive in liquidity pooling and yield farming?
Note, that I'm less well aware of the mechanics of 2 so perhaps its also a fundamental ignorance issue.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#308Re: US passes emergency waiver over fuel pipeline cyber-attack
#309The reason that cyberattacks are proliferating is because it has only recently become easy for the threat actors to receive massive payments quickly and anonymously. Remove that ability and the entire cyberattack ecosystem shuts down instantly. It is only a matter of time before this happens.
I assume you're thinking of blockchain tech? How do you think the genie will be put back in the bottle?
Re: US passes emergency waiver over fuel pipeline cyber-attack
#310Earlier quoted context omitted.
Solarwinds hack, Mueller report, this... I don't know what the best response is. First we have to wake up that we are under attack.
Take a deep breath, you are jumping at shadows and telling everyone that "they" are out to get us. Thieves are thieves, organized crime is organized crime. You think there aren't major criminal organizations in the US committing ransoms in other countries?
Calling this an "act of war" is of course hysterical.