Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

311–320 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#311
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

> I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security.

A precise definition of terrorism tends to be difficult to pin down (mostly due to the difficulty of considering what is a legitimate asymmetrical warfare tactic by a nascent liberation movement versus an illegitimate terrorist act). But a general rule of thumb is that terrorism is a) violence b) directed at civilian populations c) to effect policy.

However, there are threats to national security that are not terrorist in nature; gang warfare in Mexico and Central America would be an example of such a threat.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#312
I'd love to know the behind the scenes on this.

Guessing the US leaned on some other country hard to confiscate servers asap...

Loads of "bulletproof" hosting locations but don't think any can withstand that kind of focused above national law type pressure

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#313

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

iF you store your coins on a storage device not connected to a computer, maybe. As long as the government does not have access to the computer/phone the storage gets connected to, at any one time.

With state actors, you have to assume they have access/backdoors to most modern computing devices, and that device has to connect to the internet only twice - feds activate the backdoor and give it instructions, and have the device send the requested info back to the fed.

Minix being the most popular operating system, thanks to Intel-backdoor-on-a-chip, is only the tip of the iceberg.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#314
post #126
post #66

Earlier quoted context omitted.

> like they should invest more into cybersecurity I would say invest more thought, less money. For example, use open source more. Minimize the amount of data and information you have that needs to be closed source. Avoid Windows. Use Gmail over Outlook. Have offline backups with sneakernet disaster planning. Get a cheap safety deposit box for storing keys. Use 2FA. There are lots of free/low cost ways to have better…

> Use Gmail over Outlook. Why would you recommend this? I can understand the reasoning behind the rest of your recommendations, but not this one.

AFAIK, Gmail has suffered on the order of 100x+ fewer security incidents than Outlook. However, I am unclear on the distinction between cloud Outlook and the Exchange/Outlook combo. So me saying "Outlook" may be a mistake, and the correct term may be Exchange.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#315
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Implicit in your question is the idea that the reason there was a stronger response here was because of optics—because a large mass of US citizens demanded it.

I think a more likely answer is that optics had little to do with it. Attack a hospital and you've got angry hospital administrators mad at you. Attack an oil pipeline and you've got billionaire oil executives and shareholders who have much of the US government in their pocket mad at you.

You really don't want to anger people who can buy US elections.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#316
post #167

Earlier quoted context omitted.

As a native Russian speaker living in New York, I concur. I work in Ad Tech and deal with clients from Eastern Europe quite often. Russians' English is _always_ recognizable.

Is this sarcastic? Because you’re a native Russian speaker and yet your English isn’t recognizably Russian…

Nope, it's not. I always try to polish my English as much as I can, but after more than 8 years living in US, I still occasionally get messages from co-workers saying like, "hey dude, not to be pedantic, but ..."

If I were to write a long piece, you'd almost certainly notice that I'm not a native speaker. I'm subscribed to a few Telegram channels led by Russian speaking people and I always spot minor mistakes in their messages. Even when the text is grammatically correct, the way sentences are structured is what usually reveals them. I observe similar pattern with the partners I work with. Heck, even my English teacher's English (she is my friend on FB) is different from a typical writing style of a native speaker.

It obviously doesn't mean that Russians cannot learn a more "traditional" English, but when it comes to Russian hackers...meh, the chances are low, imho.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#317
post #66

Earlier quoted context omitted.

> like they should invest more into cybersecurity I would say invest more thought, less money. For example, use open source more. Minimize the amount of data and information you have that needs to be closed source. Avoid Windows. Use Gmail over Outlook. Have offline backups with sneakernet disaster planning. Get a cheap safety deposit box for storing keys. Use 2FA. There are lots of free/low cost ways to have better…

It’s not 2001 anymore. You can have both secure windows and Linux infrastructure. Telling people to just use Linux as a remedy doesn’t help. If you don’t invest into securing your Windows infra, your Linux infra will be also full of holes.

In 2016, while I was still working at Microsoft, they gave us cloud engineers a separate laptop for accessing customer data (they called them SAWS, for Secure Access Workstation), because they decided that our normal everyday Windows 10 machines with root privileges could not be trusted. This was in 2016, not 2001.

I do not think you can have secure Windows infrastructure today. In the future, a few years after it's fully open source, perhaps.

Of course you are free to make your own bets.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#318
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

> This is a business that actually provides better support than a regular business.

The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be:

1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.

2. Create enough trust in the company you attacked that they believe you will give the data back once you pay them.

It is crazy that they are psychologically savvy enough to simultaneously attain those directly conflicting goals.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#319
post #255

Earlier quoted context omitted.

If you anger a sufficiently powerful nation-state, you should assume all options are on the table for recovering you, your hard drives, and your keys.

The hiding crypto from government entails im large part avoiding taxes, yet it seems like the government does not do much to recover lost taxes on current schemes such as fiscal paradises and so on. I doubt the governemnt would go as far as locating a harddrive, seizing it just for tax purposes. Something else must raise their flags for them to go that route. Also this route is very hit and miss in my oppinion and on…

"Does not" and "cannot" are two different things.

My read is that tax enforcement failure is intentional, lubricated by political donations and influence, vs incompetence.

See the high-net-worth enforcement group at the IRS that was quickly shut down for murky reasons.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#320

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

No. It just demonstrates that they're incompetent.

This doesn't really improve the optics. If anything it makes it worse: if very technical people who clearly want to escape government oversight can't, what hope would my 60yo "I think Windows and Word are the same thing" father have to use them correctly?

Beyond all the technical discussion about the value of cryptocurrencies I never believed that the idea that everybody would carry their cryptocurrency wallet with them at all time was in any way realistic. People would get their wallet stolen, destroyed or lost all the time, locking them away from their savings. The vast majority of people will prefer having the peace of mind of entrusting their coins to a third party who'd handle the technical details and provide insurance against lost and theft. And just like that we've reinvented banks.

Post reply on HN