Live data from Hacker News

The Oncoming Ransomware Storm

stephendiehl.com

91–100 of 147 posts

Re: The Oncoming Ransomware Storm

#91
post #60

Earlier quoted context omitted.

Why are comments in the form of putting words into someone's mouth which they didn't say, so pervasive? The blog says "reign in and regulate", not "ban". But, to address your point, because they're good arguments. "We need to regulate $thing" has saved lots of lives. No longer can you sell plain river water to drink, dump sewage directly back into rivers, dump industrial waste into rivers, build houses which collapse…

> reign in and regulate Crypto is heavily regulated at least in the US, Western Europe and huge swaths of Asia. Exchanging to/from fiat can only be done through entities subject to KYC, AML laws, and OFAC regulations. Additional regulations are coming - see "travel rule". Bitcoin is infinitely more traceable than cash. Here's one of the most popular software routinely used by law enforcement to trace crypto payments:…

>Crypto is heavily regulated at least in the US

Most of these criminals perpetrating ransomeware aren't in the US or Western Europe.

Re: The Oncoming Ransomware Storm

#92
post #44
post #41

Earlier quoted context omitted.

That's not how the world works my friend.

so long as encryption-as-we-know-it holds-up, there's no rescue for orgs that repeatedly get hit and can't get their backup strategy together. Sure, you make a regulatory mis-step and you have friends in high places, they will look the other way. This indeed, is how the world works. If your entire infrastructure is encrypted into a solid block of nothingness it doesn't matter if your dad is a senator, you're done.

Name a single company that has died due to data breaches.

Meanwhile, I'll name a dozen that got breached/leaked data, and got away with it: Experian, Microsoft, Facebook, Google, Marriott, Yahoo, First American Financial Corporation, Deep Root Analytics, Court Ventures (a subsidiary of Experian), Capital One, Anthem.

Go on, search "list of largest data breaches" and then see how many of those companies are still in business.

It sure seems like large companies aren't suffering for their breaches.

Re: The Oncoming Ransomware Storm

#93
post #5

Ransomware is great. 1. Creates a huge financial incentive to try and break PGP encryption. 2. Pushes aside all of the lame corporate compliance "infosec" people whose job it is get lied to about PCI compliance and bitch about version numbers that they don't understand. 3. Proves useless all of the "ex-special-forces" "red team" "master safecracker" Defcon LARPers. 4. Gives the insurance companies enough room to attr…

I did some searching and didn't find anything about use of the OpenPGP standard in ransomware. It appears that ransomware creators don't care about interoperability, which makes sense for their biz. A doubt that anyone has ever been motivated to try to break an encryption method just because it was used in some particular ransomware. The methods used are generally not breakable, the mistakes come from stuff like leav…

I'm not sure how satirical the parent's comment was, but every single point is completely inaccurate, irrelevant, and/or nonsensical.

Re: The Oncoming Ransomware Storm

#94
post #85

Earlier quoted context omitted.

Sure it can be done entirely out of malice, but it is now clear that cryptocurrencies enable the incentive of doing it for money. It is becoming more and more evident that ransomware attacks are the killer app of crypto.

Because there was no such thing as cyber crime prior to the invention of cryptocurrency.

Not on the scale we're seeing now.

Re: The Oncoming Ransomware Storm

#95
post #78
post #56

Earlier quoted context omitted.

1- Crypto is made to evade government control. 2- Government are there to ensure law and order. Result: Crypto is a great tool to evade law and order Governments will have to control crypto or governments will stop working

>>governments will stop working hmm... seems like all positive to me

Yay, anarchy.

The half-life of anarchy is measured in hours. Then the gangs show up. Gangs are basically governments, except even less responsive to your needs and more openly committed to enriching their own leadership.

Re: The Oncoming Ransomware Storm

#96

Earlier quoted context omitted.

Incentives matter. Bitcoin incentivizes certain types of criminal activity. As Bitcoin grows the negative externalities will become more pronounced. I truly don’t get the ethics of it. It is killing people, literally blood money as a great new technology. Bonus points for incentivizing climate destruction and burning of fossil fuels. I don’t understand the ethics of it.

Wealth incentivizes that activity. Cryptocurrency is one easy way to transfer it, but it's not the "singular" reason ransomware is "possible." > literally blood money ("Blood money" is an idiom, a colloquial metaphor. So a virtual currency is "literally" a metaphor? Ugh.)

Cryptocurrency has properties that make many kinds of criminal activity far easier than most other kinds of "wealth".

There's a reason that ransomware payments are now exclusively transferred through Bitcoin.

Re: The Oncoming Ransomware Storm

#97

Banning cryptocurrency only fixes one side of the global-internet-being-security-broken problem. If you're a nation-state actor and you can still break into computer systems throughout the world, you can still: - Manipulate and profit in foreign stock markets by short/long selling based on insider information - Choose who gets elected by making dirty laundry public - See military planning by the enemy, live, as it ha…

But that only applies to targets who are "in the game." If you are a government entity or listed company or act as their agents, then you know that security is an issue and are paid well enough to make a decent effort. Whether you do or not is a different issue. Grandma doesn't have security audits, wouldn't know how to do one, and couldn't afford it if she did. She is the victim here. She might call the police but t…

> But that only applies to targets who are "in the game."

The problem is that any entity in a nation that you're aggressive with can be "in the game". You can steal IP from foreign companies, damage foreign infrastructure, and find the personal data of high-value persons in the datasets of otherwise "boring" companies.

Re: The Oncoming Ransomware Storm

#98

Earlier quoted context omitted.

The big corporate targets and the >1m ransoms aren't doable with gift cards. A large hospital chain in San Diego[1] last week was hit with a $100m[2] ransomware attack that shut down the hospital. Can't pay that with gift cards. [1] - https://www.sandiegouniontribune.com/news/health/story/2021-... [2] - Source internal said that was the ransom amount

You'd ask for cash. A middleman would pick it up, convert it to gift cards or Tide laundry detergent (so that the traced cash would go cold) and then pass it forward through the criminal network. The middleman needs to be paid because it's high risk (cops would trace the cash to the middleman... but no further). So cryptocoin are way cheaper. But still, there's plenty of ways to do things using old school techniques.

You also need to trust that your criminal middleman with $100M doesn't just abscond with your money.

With cryptocurrency when its in your wallet, its yours, and the risk of relying on a 3rd party to transport your ill gotten gains is much lower.

Re: The Oncoming Ransomware Storm

#99
I'm not an unequivocal fan of cryptocurrencies or any particular cryptocurrency by any means, but it appears this author really hates cryptocurrency and this is just an opportunity for them to argue that governments should ban cryptocurrency. Which is completely understandable and obviously in good faith given ransomware is bad and they think cryptocurrencies are bad, but I just wanted to point out their stance and that this is an anti-cryptocurrency blog rather than a security/tech blog.

Every blog post they've ever published is about why they think cryptocurrency is awful: https://www.stephendiehl.com/blog.html

>The Oncoming Ransomware Storm - May 11, 2021

>Et tu, Signal? - April 7, 2021

>The Political Case for a Blanket Cryptocurrency Ban - March 30, 2021

>Bitcoin: The Postmodern Ponzi - February 27, 2021

>The Crypto Chernobyl - February 10, 2021

>Gamestop, Bitcoin and the Commoditization of Populist Rage - February 3, 2021

>Facebook Libra is Architecturally Unsound - November 2, 2019

I think they make many valid criticisms, but they remind me of the inverse of the standard Bitcoin maximalist. It seems there are a lot of people who think Bitcoin or Ethereum or something else should become the universal currency of the world and is the best and most innovative thing ever, and a lot of other people who think they should all be made illegal and are the worst thing ever. Also somewhat reminiscent of pg's fanboy/hater dichotomy: http://www.paulgraham.com/fh.html

Re: The Oncoming Ransomware Storm

#100

Earlier quoted context omitted.

The author has multiple articles calling for an outright blanket ban on all cryptocurrencies. So in the author's own words, he is calling for a ban on all cryptocurrency.

In this article being discussed the author's own words are: " 'legislation and intervention in the financial system at only the level nation states can act. The free flow of money from US banks to cryptocurrency exchanges is the root cause and needs to halt' " Which is a call for regulating, not banning. If you want to use something different which the author said somewhere else, to back some other point and say that…

How about this article, titled "The Political Case for a Blanket Cryptocurrency Ban"? https://www.stephendiehl.com/blog/banbitcoin.html

The author is extremely prolific and vocal about his support for outright banning cryptocurrency. It's all over his blog, it's all over his Twitter. He is proud to admit it. It could have taken you 30 seconds to verify what I was saying, but instead you chose to double down on your ignorance.

Post reply on HN