Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

351–360 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#351
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

IMO terrorism is a "waffle word" that doesn't really have any meaning anymore. Originally a use of violence and intimidation against civilians in pursuit of political ideology, it's come to mean "people we don't like, who aren't state actors and don't fit conventional organized crime narratives."

I don't think it's necessary to staple the term to the action in order to take it seriously. It should, however, be taken seriously as the national security threat it is. For instance, climate change is a national security issue but oil executives, while distasteful, aren't terrorists.

I agree that many folks in the tech community (and especially here, though I don't know if they're overrepresented here) treat technology as platonic. That's not going to cut it moving forward. Technology that enables bad things in the world should be curtailed even if its "neat."

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#352

Either the founder stole the money himself, or the NSA showed the world just how powerful they are when they flex. If it’s the latter, I’m really impressed by their skills.

The guys developing the ransomware are not necessarily the guys behind this group. Even if the developers were in-house, they may not be managing the money. So hack may be not be as difficult as we might think.

It is kind of ironic actually, the ransomware targeted billing systems of colonial, however they didn't really secure their own money.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#353
post #72

Earlier quoted context omitted.

These groups will often use bitcoin tumblers/mixers to anonymize their btc. This is a solid explanation https://www.deepwebsiteslinks.com/wp-content/uploads/2017/10...

Is there a technical reason that makes use of a tumbler legally safe? My concern would be that putting in a clean bitcoin would result in me getting a fraction of a stolen bitcoin and I would be receiving stolen property. The fact that they are fully traceable means that it would be easy for someone innocent to be caught up in something like that.

That and you don't know if the tumbler you are using is operated by the FBI.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#354

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

HN is full of assholes who practice deprecating others to find their own worth. Set yourself free of their dogma and change the world the way you see it!

Some downvoting can be truly surprising, and one factor may be because HN is much more international, while I think of it as "American". It is Y-Combinator, after all.

Funny fact - one way to get down votes on HN is to say something negative about that shit-tier human Peter Thiel. Apparently becoming rich off of venture capital makes you automatically a good human being.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#355
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

They may have just intended to get money, but they definitely spread terror. I had to have like an hour long phone call with my mother on Monday explaining why she had to go to 4 gas stations before she could get any gas, and that no the pipeline was not going to explode.

From the satire site that shall not be named: "People in the Middle East head to bomb shelters after learning that Americans are experiencing gasoline shortages."

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#357
post #307

Earlier quoted context omitted.

> non-state > economic, not political There’s a well known phenonenom of a certain large nation harbouring cybercrime gangs and keeping them on the government leash. Their economic activity benefits the governments political agenda. Ergo all conditions are true.

There's also a well-known phenomena of large nations harboring multi-national corporations that break the law in other nations they operate in. That doesn't mean that the large, developed nations in question are engaging in organized crime. Taking advantage of regulatory arbitrage does not mean that their government is in collusion with them. If it did, then we could pile a lot of crimes at the feet of Western govern…

There is no sense to your comparison when you’re putting a criminal enterprise (which exists to do harm and harm only) and legitimate business into the same bucket.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#358
post #227

Earlier quoted context omitted.

There is basically a zero percent chance that the US knew where they were physically. The servers that were claimed to be seized were on cloud platforms. And even then, we don't know if this is true or if it's just an exit strategy.

It's easy to say "basically zero chance" when we're armchair quarterbacks and not the ones in the hot seat. I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)

This isn't the first such attack. You can bet the big agencies worldwide have been aware of ransomware and investigating. They have been putting evidence together. It only takes a few of the right mistakes on the part of the criminals for them to be figured out. In the long run the advantage is to the police because they can keep looking.

If you want to be a criminal who gets away with it you really need exactly one big action, and at most a few tiny practice runs before the big one. Choose your target well because once the big one is done you have to be done. (and don't do anything copycat - investigations to get the first guy might find you instead)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#359
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

> This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading up to this. And why would you say this is desirable to the US? Just general "governments take advantage of crises to gain power" reasons?

What? This makes no sense.

The hacker group attacked resources considered "critical infrastructure"; this was closer to an act of war than any other cyber attack has come. The US Cyber Command responded swiftly.

> "governments take advantage of crises to gain power"

Please, elaborate? I fail to see how the US Govt is taking advantage of this crisis for more power.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#360
post #122

Earlier quoted context omitted.

> I do wonder if ransomware is (in a strange way) a(n illegal) free-market response to what is perceived to be an under-valuation of tech skills - aggrieved people who can carry out attacks and gain access to deploy ransomware are likely to be able to earn more through this route, even factoring in their "risk of being caught". Sure. In the same way the mugging people is a response to undervaluing “beating the crap o…

Its been said before: "When the system fails you, you create your own system." Which relates to what you're saying. When clever, intelligent people are ostracized and marginalized, they then use those skills to get illegally what society has prevented them from getting legally. At some point, the idea of getting caught doesn't even register anymore.

Were these people ostracized and marginalized?

If we just paid engineers more would this type of crime disappear?

Or is greed, ego, arrogance also a part of their actions?

Post reply on HN