Earlier quoted context omitted.
Opinions are my own. There is something called the "gun test". The crypto on an encrypted hard drive is not more secure than the gold bars in a locked safe. Its security is a function of how the secret holder response to gun-on-their-head events. In this case, since the government is directly involved (and angry), a lot of criminals may pick personal safety over assets. Frankly, I think a large portion of cryptocurre…
While I tend to agree with your argument, there is a difference: crypto is safe if no one knows it exists, or rather no one can link ownership to owner. It's very hard to do this with gold.
DarkSide ransomware gang quits after servers, Bitcoin stash seized
331–340 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#332It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#333Earlier quoted context omitted.
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
I know you're saying this in jest, but that's the calculus. The outcome here shows that executives made the right call. The $5MM fee was easily paid, less than the costs of security, and the insurance company will probably cover it anyway. And the government/people were so outraged that the attackers were met with fucking swift justice. The company will probably get some grants or something to cover the cost of "secu…
Any employee choosing to spend millions to avoid the cost of a heretofore unencountered cyberattack would be making a strategic decision, while probably not being empowered to make decisions at that level. So they do not take action.
Bureaucracies do not take visionary action. They stay the course.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#334> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#335Earlier quoted context omitted.
Now that they've outed themselves as an easy mark, should be simple to hit them again and demand more money. At some point it'll be less expensive to improve their security infrastructure.
Ransoming Colonial basically put Darkside out of business. no one is going to hit them again
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#336Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#337Earlier quoted context omitted.
Thanks for sharing your experience. Not to dig too deep into details, but what would you say your primary motivation was in your 'young and dumb' days? Were you curious about it, was it a statement, was there an allure?
For me it was about making a statement. I had gotten into an argument with a professor on a discussion board. He used derogatory terms to refer to me, which pissed me off. I sent him a virus that was supposed to just damage files and delete some random files. It turns out it propagated onto their main network and crashed the entire universities network. Suddenly, you feel untouchable (even though the virus had gotten…
> the virus had gotten out of control, which I didn't mean it to do
This isn't just a whoops, how do you "accidentally" create a virus that leaves the boundaries of the computer and traverses their network?
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#338Earlier quoted context omitted.
The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.
If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?
If that's not enough and anyone of them is in the USA they do have access
Can your wallet be hard to crack? Yes but either use your zero day to get all data including a Password or book a little bit of supercomputer time for brute forcing.
They might have linguists available to help out with a dictionary attack.
As aluminum foil hat this might have sound in pre Snowden that's how it could have been played out.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#339Some pretty good karma/irony there. They left wallet keys laying around on a server.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#340Earlier quoted context omitted.
> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…
> This is a business that actually provides better support than a regular business. The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be: 1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.…