Earlier quoted context omitted.
Do you have any extraordinary evidence for these extraordinary claims?
It's not possible to bring "extraordinary" evidence of a 3 letter agency doing this kind of shit the way some HN user would want without ending up as a political prisoner somewhere learning all about the meaning of the word "pain". Never-the-less, I have no doubt that FSB operatives are allowed to moonlight.
DarkSide ransomware gang quits after servers, Bitcoin stash seized
241–250 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#242Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#243Earlier quoted context omitted.
I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed). If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.
I think this is simplistic and overlooks logistics and flexibility. If a hospital closes, patients can be moved. If there's no gas, patients can't get to any hospital.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#244> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#245It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#246Earlier quoted context omitted.
Do you have any extraordinary evidence for these extraordinary claims?
The entirety of the Cold War between the USA and USSR?
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#247Earlier quoted context omitted.
There is basically a zero percent chance that the US knew where they were physically. The servers that were claimed to be seized were on cloud platforms. And even then, we don't know if this is true or if it's just an exit strategy.
It's easy to say "basically zero chance" when we're armchair quarterbacks and not the ones in the hot seat. I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)
Yep. Compromised people on the inside, informants, "intensive interrogation" etc. are more likely the way, as has always been the case.
Also the agencies that would know who these people are would not want to reveal what they know in order to save random XYZ Corp's bacon. With this being seen as a "critical infrastructure" attack and something closer to an act of war/terrorism, the stakes got higher.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#248It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#249Earlier quoted context omitted.
So they have a public representative living in the US and are associated with Harvard University. I don‘t think there‘s much shadowy cybercrime to investigate there. How do you feel about Wikileaks and the prosecution of Julian Assange?
Having a "Harvard affiliation" doesn't legitimize illegal activities. Leaking private messages, passwords, and so on from social networks is an unacceptable breach of privacy. Exposing people's private donations is also unacceptable. This is a group looking to create a chilling effect on others' speech, particularly moderates and conservatives, through illegal cyber crimes. I am not sure how you can possibly see that…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#250I'm interested to understand the psychology of ransomware types who go after these enormous and important targets. That includes the pipeline, which obviously claimed at least a few lives of its own via people not being able to drive to get medical care, etc. Are they armchair criminal masterminds who don't really have a visceral understanding of how much damage they're doing? Or just straight up psychopaths? I can't…
They've learned from this, from the article: "The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required t…
I don't know nearly enough to guess, but it doesn't seem cut-and-dried to me that this is a case of them realizing what they did was wrong.
In any case, the same question still applies for what happened before: why were they in a psychological state that made them try this in the first place?
Even if we grant that they've changed their tune for moral reasons, that would rule out straight psychopaths, but would include people who had severe antisocial traits but still started to have some feelings about it once they saw the real-life consequences. We see this with repentant murderers.
As far as rich businessmen who do evil stuff, there's a literature on that, and it seems to be a complicated mix. There's "just filling my role" (for those not at the very top of their organizations), thinking you'd be replaced by someone else doing the same thing, dissociation/denial about what you're doing, and -- yeah -- straight up antisocial/psychopath types. And more. It's a fascinating topic.