Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

121–130 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#121
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

As a native Russian speaker living in New York, I concur. I work in Ad Tech and deal with clients from Eastern Europe quite often. Russians' English is _always_ recognizable.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#122
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> I do wonder if ransomware is (in a strange way) a(n illegal) free-market response to what is perceived to be an under-valuation of tech skills - aggrieved people who can carry out attacks and gain access to deploy ransomware are likely to be able to earn more through this route, even factoring in their "risk of being caught".

Sure. In the same way the mugging people is a response to undervaluing “beating the crap out of people and taking their money” skills.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#123
post #93
post #60

Earlier quoted context omitted.

>Until someone cracks it This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.

There are ways to crack encryption that have nothing to do with math. It doesn't matter how good your crypto is. You could probably get by plain text as far as the FBI's effort to crack your crypto are concerned as they won't waste their time checking if you are that stupid.

This doesn't really make sense. In the case of a criminal laundering crypto, they don't know who the criminal is, so the rubber hose attack doesn't work.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#124

Earlier quoted context omitted.

Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.

I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.

lolwut? this is insane. If oil infrastructure is completely disrupted it would be beyond catastrophic. Oil is completely foundational to our economy

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#125
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#126
post #66

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

> like they should invest more into cybersecurity I would say invest more thought, less money. For example, use open source more. Minimize the amount of data and information you have that needs to be closed source. Avoid Windows. Use Gmail over Outlook. Have offline backups with sneakernet disaster planning. Get a cheap safety deposit box for storing keys. Use 2FA. There are lots of free/low cost ways to have better…

> Use Gmail over Outlook.

Why would you recommend this? I can understand the reasoning behind the rest of your recommendations, but not this one.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#127
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives [sic],” reads an update to the DarkSide Leaks blog. “Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”[1]

[1] https://krebsonsecurity.com/2021/05/a-closer-look-at-the-dar...

Yeah, just dirtbags making money.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#128
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

I think the point people are missing is that hospitals don't just stop providing services when they are hit by ransomware, at least not in my admittedly limited experience. There's a ton of paper involved even today and life could move on with ballpoint pens and forms.

The game was changed when Colonial closed the valves and services were impacted.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#129
post #52

Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.

It just takes one agent or informant on the inside to bring the whole house down.

> takes one agent or informant

Only if that agent has the master keys. Strong security is about making sure that there is no master key.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#130
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

ETH can be sent through tornado.cash or through zkDAI. Both of these use zero knowledge proofs to break the link in the chain.
Post reply on HN