Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

171–180 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#171
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

Crypto currency itself can be completely anonymous, but the difficulty is in the on-ramp and off-ramps to and from state fiat money.

For example, I want to buy ZCash that is untraceable to me. I need to exchange ownership of a hardware wallet (like a physical USB device) for a pre-determined amount of state fiat, lets say USD in this case. In order to facilitate this I need to find a trusted seller, arrange a meeting, verify the actual value of the physical wallet, and make the exchange. There are non-physical means of making it harder to trace state fiat back to you, but not impossible. The state has simply had too much influence over these places of transaction for too long for anybody to be truly un-findable given a long enough period of time.

Assuming I can find someone willing to on-ramp me like this I will need to take steps to ensure that our communications are encrypted and untraceable. This means not only do I need a decentralized encrypted messaging service, I also need to conduct this communication in a way that does not give away my geographical location and is not vulnerable to security logs (say by checking the cafe's video feed from the time I was messaging my seller). Then I need to go to the meet, exchange the physical wallet for cash, and verify the amount in it is accurate (and also preferably not stolen). I need to do this without revealing my identity to my seller and avoiding security logs once again. This is all now possible whereas before Satoshi it was impossible, but it is still difficult.

Alternatively, I could just sell some kind of digital asset in exchange for ZCash to begin with. Now I do not have to worry about an on-ramp. If I control my distribution server then I can erase or encrypt my sales logs in order to prevent any estimation of my total sales for the year.

Off-ramping is much harder. I either need to become a seller of a physical wallet which has all the same problems that plagued me before, or I need to live in an economy where off-ramping is not required. This would be a physical location where all transactions are conducted in secure, anonymize, cyrpto-currency transactions. Similar to my earlier problem, this is now possible but extremely difficult. An individual or a group of individuals is going to have to bootstrap an entire local economy.

Being localized is also an issue since there is nothing preventing the USG from simply rolling in the tanks to break up this localized tax haven.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#172

Earlier quoted context omitted.

I think it's still just pseudo-anonymity, even for monero. Which means, practically, that I don't think it would have done more for these guys than just delay the seizure.

Nope. Monero is actually private and untraceable.

How many times are we going to learn that that's just not true.

There is no safe, only shades of safer.

Is the mathematical underpinnings of Monero sound? That's a good starting point. There are still implementation bugs, compiler bugs, architecture bugs, supply chain vulnerabilities, and state actors with unlimited $.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#173
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

> business side of the oil company What are the sides of any company other than "business"?

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#174
post #50

DarkSide's English is incredibly good for some supposed Russians. It even has the correct use of the apostrophe in "clients'". I know nothing, but my hunch is that this was written by a well-educated person who grew up in the US or Canada.

I can’t decide if it’s worse to imply that Russians can’t learn English or to think that the anglosphere only exists in North America.

I am just saying that it is idiomatic North American English. I, for instance, could not write in idiomatic British English if I tried. For instance, your use of "state" in your username and "anglosphere" in your one sentence strongly hints to me that your English is not purely North American. (I see your profile, too.) The vast majority of Americans would use different terms.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#175

Earlier quoted context omitted.

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

> there are also instances of refunds if they can't decrypt your files due to technical issues. I would like to hear more about this, that sounds kind of hilarious. "Ah, apologies, we'll get that back to you within 3 business days. Have a nice day, I hope you had backups"

That’s exactly how it is and has been for a very long time (half decade or more).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#176
post #158
post #7

why are ransomware groups transacting in BTC, which can be easily traced?

It's easier to launder and transfer the BTC than to do the same with real money. According to the article, the people behind Darkside were also behind a bitcoin "mixing" service that was recently shut down.

but... Monero. Mixing is fine, but there's fees and overhead that make it undesirable, IMO.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#177
Statements like "money of advertisers and founders was transferred to an unknown account" don't make sense to me. Why is the money held on a server at all? Surely it's more secure to keep wallets receiving money locally on a laptop or in a paper wallet, no? Why would they put the gold in the munitions depot if they don't have to?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#178
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

> business side of the oil company What are the sides of any company other than "business"?

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#179
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

This is why it's a problem. What's the point is the business side, but when taken as a whole, this type of infrastructure is too important to the country as a whole.

Everyone want's to make the calculation and hope it's not them, but if it's everyone at once, or there is no ransom option it's a completely different ball game. This is a situation where we are asking private companies to take responsibility for something outside of a profit motive and the results are some what less than surprising.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#180

Earlier quoted context omitted.

I can’t decide if it’s worse to imply that Russians can’t learn English or to think that the anglosphere only exists in North America.

I am just saying that it is idiomatic North American English. I, for instance, could not write in idiomatic British English if I tried. For instance, your use of "state" in your username and "anglosphere" in your one sentence strongly hints to me that your English is not purely North American. (I see your profile, too.) The vast majority of Americans would use different terms.

[deleted]
Post reply on HN