Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

341–350 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#341

Earlier quoted context omitted.

Opinions are my own. There is something called the "gun test". The crypto on an encrypted hard drive is not more secure than the gold bars in a locked safe. Its security is a function of how the secret holder response to gun-on-their-head events. In this case, since the government is directly involved (and angry), a lot of criminals may pick personal safety over assets. Frankly, I think a large portion of cryptocurre…

In the bitcoin space it’s colloquially known as the “$5 wrench attack.” All the cryptographic, air gapped security hardware doesn’t matter if someone can beat the keys out of you.

Source: https://xkcd.com/538/

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#342
post #237

Earlier quoted context omitted.

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

The truly cynical take is that they managed to take down Colonial's billing . In response, Colonial shut down the pipeline - because obviously delivering oil without getting paid is out of the question. Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...

The more charitable take on this is that if one system is compromised, there's a high chance others may be, so if you have safety-critical systems and you're not absolutely certain they were properly air-gapped from the compromised system, shutting them down may be the safest course of action.

In truth both factors probably played a role in this case, perhaps also with a hefty dose of "our software literally can't run if billing is down because it was never designed to handle that".

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#344
post #131

Earlier quoted context omitted.

One (of many) ways: Monero -> bitcoin -> localbitcoins with stolen identity. Each localbitcoins account can trade up to $200k a year without any kind of in-person verification. Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.

There is no way to exchange Monero for Bitcoin or vice-versa without the risk of being tracked. LocalBitcoins has been doing KYC/AML since 2018.

Atomic Swaps on Monero will be decentralized, no KYC.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#345

Earlier quoted context omitted.

I could see 10 developers costing that much

$500,000 salary? Let me know where these jobs are because I'd like to submit my resume.

More like a $250,000 salary + benefits. Medical coverage is hideously expensive for example. Plus retirement, dental, insurance, and taxes. Still a cushy salary for a dev, but not completely out of the realm of reason.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#346

Earlier quoted context omitted.

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

> This is a business that actually provides better support than a regular business. The thing I find fascinating from a sociology perspective about ransomware is that they have to. To be a successful ransomware company, you have to simultaneously be: 1. Completely immoral enough to attack companies, hold their data ransom and potentially put them out of business and reveal the private details of thousands of people.…

I don't think these goals are very conflicting. It's not hard to imagine a criminal unwilling to lie and/or break their promise, as a matter of fact it is a common trope in works of fiction (https://tvtropes.org/pmwiki/pmwiki.php/Main/IGaveMyWord).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#347

Earlier quoted context omitted.

I mean, the pipeline in question provides half of the gas to the US East coast. You don’t have to love oil to see that losing 40% of the supply to more than 100m people overnight would be a public safety (what if emergency vehicles can’t buy fuel?) and economic risk. The number of people reliant on this pipeline is several orders of magnitude greater than would be impacted by taking a single hospital offline. You’d n…

Yeah, I understand this and agree with you. Compare one of the biggest oil pipelines in the country with one hospital, of course one will be worse than the other. But if you instead compare 40% of the hospitals going offline VS 40% loosing access to gas, with similar conditions, I think the mortality will be higher by attacking hospitals. I think the government could probably somehow logistically ration oil if shit r…

If 40% of the hospitals shutdown the majority of people would not notice if you somehow kept it out of the news. It would be a disaster for those who need a hospital right then, but the average person doesn't even visit a hospital once a year.

The average person fills their gas tank once a month, so they are much more likely to notice personally.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#348

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

Unless you're located inside of a foreign military installation, there aren't many places to put a hard drive that the government can't get to.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#349
post #262

> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.” I am... flabbergasted. What? Ransomware has always been a brand of e…

I actually laughed out loud reading this, These guys are giving ransomware a bad name, ahahaha, what?!

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#350

Earlier quoted context omitted.

The median lifetime earnings in the US is 1.7 million, and that’s equivalent to... $20 an hour or so. 5 million is “never work again” money for a couple of people who want middle class incomes the rest of their lives... it is not really that much when spread over more than a few people.

Darkside is likely based in Russia, where lifetime median earnings are much lower.

They're also going to lose a big chunk of that to money laundering losses. But since it is in Bitcoin it's probably going to appreciate over time. The problem is that if they fuck it up just once the record will be on the blockchain forever and they'll never be safe.
Post reply on HN