> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
DarkSide ransomware gang quits after servers, Bitcoin stash seized
251–260 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#252Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#253Statements like "money of advertisers and founders was transferred to an unknown account" don't make sense to me. Why is the money held on a server at all? Surely it's more secure to keep wallets receiving money locally on a laptop or in a paper wallet, no? Why would they put the gold in the munitions depot if they don't have to?
I'm seeing statements about the payments server and the money associated with the payments server, but (at the risk of using an analogy) it seems like they've lost their "petty cash" box, not their main account. Surely they were wise enough to only put a small amount of money in the payments server. The bulk of their cash would be in a separate account (which wasn't lost).
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#254It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#255Earlier quoted context omitted.
The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.
If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#256> The crime gang announced it was closing up shop after its servers were seized and someone drained the cryptocurrency from an account the group uses to pay affiliates. If so, this is either: 1. one heckuva Mickey Mouse operation 2. a smokescreen The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to. That Bitcoin private keys were being stored on a "server" strains…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#257Earlier quoted context omitted.
Well, sometimes they're right. The hit company will likely call in some consultancy to institute a bunch of newer and better security protocols, then call it a day. If they really aren't hit again for another decade and staffing a department would cost $500k a year or more, were they wrong? It's a gamble. It's easy to point fingers at the company that was caught out, but for the hundreds or thousands that aren't rans…
They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#258It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
It was a mistake to attack overtly . I believe $5 million can be easily drained covertly and inconspicuously from megacorporations. I'm pretty sure it's actually happening we just don't hear about it.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#259It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…
A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal.
If attackers just intend to get money, they're probably well-described as extortionists (or in some cases, as you said, akin to pirates). If they just intend to damage a particular society without demanding anything from it or getting it to change its behavior, they might be saboteurs.
Attacks with these motives or that pretend to have these motives could still be considered national security threats (and taken very seriously), but maybe shouldn't be described specifically as terrorism.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#260Earlier quoted context omitted.
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
I know you're saying this in jest, but that's the calculus. The outcome here shows that executives made the right call. The $5MM fee was easily paid, less than the costs of security, and the insurance company will probably cover it anyway. And the government/people were so outraged that the attackers were met with fucking swift justice. The company will probably get some grants or something to cover the cost of "secu…