Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

261–270 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#261
post #86

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I think you're right - as I said on a sibling comment, if beans are all you count, and bean-counters rule the roost, you can write this off as a one-off, and point out you had 30 years without a ransomware, and therefore we don't need to do anything...

[deleted]

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#262
> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.”

I am... flabbergasted. What? Ransomware has always been a brand of extortion; it's right there in the name. Extortion has become dangerous and toxic? You have got to be kidding me. I wonder what's next for these folks. A life of simple, honest, pleasant and non-toxic crime?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#263

Earlier quoted context omitted.

> “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives [sic],” reads an update to the DarkSide Leaks blog. “Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”[1] [1] https://krebsonsec…

This is better then most rich businessman, actually. Many don't care if they create problems for society, if it means more money for them.

They are, of course, lying. They don’t want the extra attention that comes from attacking public infrastructure or affecting large numbers of people.

Nobody cares if you sabotage a random small business. Lots of people care when you attack a fuel pipeline. Attention is bad for this business.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#264

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

I mean it feels almost cliche to post this at this point: https://xkcd.com/538/

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#265

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

relevant xkcd: https://xkcd.com/538/

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#266
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Terrorism is a non-state use of violence for political aims.

Ransomware is non-state, not violent, and is done for economic, not political aims.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#267
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

I'd like to lean towards keeping terrorism defined essentially by intent--namely, the intent to use asymmetrical, threateningly or actually destructive, and emotionally activating ("terrorizing") means to manipulate a body politic or society towards a desired change.

If serious ransomware attacks are being conducted by state actors with the sole intent of causing damage, and we want to use powerful terminologies to describe them, "acts of war" seems a reasonable start.

Yes, this is semantics--but some of my concern here is that just freely tossing around "terrorism" gives cover for organizations not to be diligent in at least attempting to secure their networks and digital assets.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#268
post #49

Earlier quoted context omitted.

So they have a public representative living in the US and are associated with Harvard University. I don‘t think there‘s much shadowy cybercrime to investigate there. How do you feel about Wikileaks and the prosecution of Julian Assange?

Having a "Harvard affiliation" doesn't legitimize illegal activities. Leaking private messages, passwords, and so on from social networks is an unacceptable breach of privacy. Exposing people's private donations is also unacceptable. This is a group looking to create a chilling effect on others' speech, particularly moderates and conservatives, through illegal cyber crimes. I am not sure how you can possibly see that…

I don't think any of this is a crime?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#269
post #255

Earlier quoted context omitted.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

If you anger a sufficiently powerful nation-state, you should assume all options are on the table for recovering you, your hard drives, and your keys.

[deleted]
Post reply on HN