Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

381–390 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#381
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

so which is it then?

"BTC is bad cause it can be used by drug dealers to launder money"

"BTC is not even secure from government access"

Surely someone will point out both can be true but the point is the anti-btc folks seem to be talking out both sides of the mouth

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#382

Earlier quoted context omitted.

If I'd just collected enough ransom to retire and never work again, I'd also put out a press release announcing I was out of business and someone seized all my shit and etc.

Darkside was a legit business. They routinely collected ransoms ten or twenty times larger than what they got from Colonial. if they were going to retire, they would have done it a long time ago

I can't find evidence of this "routinely collected ransoms ten or twenty times larger than what they got from Colonial" claim. Colonial is rumored to have paid out ~$4mm. Every source about Darkside seems to cite a "between $200,000 and $2 million for the file decryption key" range. This would put the Colonial ransom far above their typical payout.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#383
post #323

Earlier quoted context omitted.

> What is the externalized cost of this crisis on the entire country? If a business externalizes the cost, does it matter to them? Civil penalties levied by regulators will drive the change that matters.

> If a business externalizes the cost, does it matter to them? I mean, yes? Maybe not before next quarter's revenue statement, but eventually it will have to start to matter? If your dog goes and craps in the yard every day, you eventually have to clean it up or you will get flies in the yard, and if you have to open the door or leave the house at all then sooner or later you will have flies in the house, it matters,…

But if you're a monopoly (a competing pipeline isn't likely to spring into existence any time soon) and the courts aren't inclined to impose particularly harsh penalties, business as usual will remain your optimal moneymaking strategy.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#384

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

There is billions of dollars of value in BTC sitting in wallets as an open bounty for anyone who can hack private keys. So which of the following is most likely: - the government has a tool that can break private key encryption and used it to confiscate a hacker groups funds OR - whoever controls the groups wallet transferred it out and is on the run

OR

Someone got a little sloppy on their payment processing server (also seized) or with maintaining separate wallets and control of that server allowed sending of payments to an account specified by whoever was in control - likely since the server was for paying affiliates.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#385
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

Ripping of the average middle America Jack and Hortense is one thing - start impinging on CNI and your playing big boy and girl games.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#386
post #317

Earlier quoted context omitted.

It’s not 2001 anymore. You can have both secure windows and Linux infrastructure. Telling people to just use Linux as a remedy doesn’t help. If you don’t invest into securing your Windows infra, your Linux infra will be also full of holes.

In 2016, while I was still working at Microsoft, they gave us cloud engineers a separate laptop for accessing customer data (they called them SAWS, for Secure Access Workstation), because they decided that our normal everyday Windows 10 machines with root privileges could not be trusted. This was in 2016, not 2001. I do not think you can have secure Windows infrastructure today. In the future, a few years after it's…

This sounds more like a policy decision. Any serious company is heavily limiting how customer data is accessed. Lots of them have special rooms, with heavy physical security, where you cannot even bring electronic watch, not even talking about your work phone or normal work laptop. And those companies often run on Linux.

Open source doesn’t make stuff magically secure. Remember heartbleed? Or how easy it’s was proven (by sketchy research, sure, but that’s secondary point) to bring malicious code into THE open source project, Linux kernel?

Believing that by simply using open source you have secure infra, and that by using Windows is naive view by people who never seriously worked on security for big companies.

I say all of that as a heavy Linux supporter. Linux is better, yes. But it’s not a magic bullet. I’ve worked in Windows shops that had extremely good security, and Linux shops that could’ve been hacked by someone after one day classes of how to be a hacker.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#387

Earlier quoted context omitted.

There are few jurisdictions where the US Government can't easily get at you, either physically or financially. China, Venezuela, North Korea, Russia the list is super thin and almost exclusively places you either don't want to be or where you better be a protected local (otherwise they'll just hang you out to dry for their own benefit or amusement). Most authorities around the world will want to nail you - and or you…

Don't forget Iran and Vietnam. You don't need to live there for very long. Just for long enough to cash out into fiat, launder the money, etc...

Maybe. This isn't a political target though, this is criminals wanting money. At most the governments gets a bit of tax money: it just isn't worth it even before you consider that the gangs who can pull this off may turn against the governments. Governments may want the types of people on staff who can pull off these attacks, but they are careful on who gets targeted, and money isn't the goal.

Vietnam doesn't like the US for historical reasons, but overall they want to play on the world stage. Also US relations have been thawing over the years. I'm inclined to think they see it as to their advantage to help out.

Similar with China - they want the ability to get at the US, but they are more likely to reserve it for something that matters to them. Money doesn't really matter as much as they get plenty sending the US cheap plastic toys. Though if China declares war next week this could be their first attack (highly unlikely, it is possible though)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#388

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

aes 256 is as strong as the decryption key . even as few as 7 words from a 2000-word dictionary should thwart any attackers. A slow KDF makes it all but impossible.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#389

Earlier quoted context omitted.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

Unless you're located inside of a foreign military installation, there aren't many places to put a hard drive that the government can't get to.

put the contents on the cloud

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#390
post #257
post #183

Earlier quoted context omitted.

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…

Which is also why they need a $15-50 million dollar fine on top this

I'm curious about the potential legal basis for such a fine.
Post reply on HN