Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

391–400 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#391
post #359

Earlier quoted context omitted.

> This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading up to this. And why would you say this is desirable to the US? Just general "governments take advantage of crises to gain power" reasons?

What? This makes no sense. The hacker group attacked resources considered "critical infrastructure"; this was closer to an act of war than any other cyber attack has come. The US Cyber Command responded swiftly. > "governments take advantage of crises to gain power" Please, elaborate? I fail to see how the US Govt is taking advantage of this crisis for more power.

Without breaking down my reasoning (which was pretty half-baked and underthought)--I was just trying to understand the OP's point.

OP used all kinds of language we associate with governments doing sketchy stuff: "what could be sold as reasonable doubt to shut down the pipeline"; "created the impetus" ("impetus" is often used to claim the real motivations were something else); "political cover"; etc.

I just didn't know how else to interpret all the cloak-and-dagger language about the US's behavior. Personally, it seems to me like our response was pretty reasonable. I think the "government takes advantage of crises" line of argument only goes so far, and at its extreme leads to dumb stuff like 9/11 truthers.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#392

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

IMO terrorism is a "waffle word" that doesn't really have any meaning anymore. Originally a use of violence and intimidation against civilians in pursuit of political ideology, it's come to mean "people we don't like, who aren't state actors and don't fit conventional organized crime narratives." I don't think it's necessary to staple the term to the action in order to take it seriously. It should, however, be taken…

Original its terror for terrors' sake to disrupt society not for individual aims is my understanding.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#393
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

> I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security.

Well... yes? That isn't a sense of the word "terrorism".

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#394

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

They did get some free help from the US amplifying all of this and the media essentially tying DarkSide to the pipeline shutdown (even though they likely only set out for the business side). Maybe now utilities going to the US for a similar reason will be in everyone's DR/IR plan (even if Colonial didn't reach out to the US admin).

Expecting the company to continue operating after freezing data on the "business side" seems strange to me.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#395

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

As someone else said, you do not store coins anywhere, they are derived from the public ledger (block chain).

What you store is your private key.

Your private key was generated together with your public key, and your public key is, well, public.

So the question is, can someone re-generate your private key?

In theory, yes, it is possible. In practice, it takes a very very long time.

But sometimes flaws are found in the generation process, like a weak pseudo-random number generated used, which significantly reduces the solution space, and then it becomes feasible.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#396

Earlier quoted context omitted.

Opinions are my own. There is something called the "gun test". The crypto on an encrypted hard drive is not more secure than the gold bars in a locked safe. Its security is a function of how the secret holder response to gun-on-their-head events. In this case, since the government is directly involved (and angry), a lot of criminals may pick personal safety over assets. Frankly, I think a large portion of cryptocurre…

In the bitcoin space it’s colloquially known as the “$5 wrench attack.” All the cryptographic, air gapped security hardware doesn’t matter if someone can beat the keys out of you.

Also perhaps a fair reason for some part of taxation. Owning millions in .*coin, and the ability to freely wander around in a first world country while not getting hit with a wrench has a whole lot of value.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#397
post #349
post #262

> “There’s too much publicity,” the XSS administrator explained. “Ransomware has gathered a critical mass of nonsense, bullshit, hype, and fuss around it. The word ‘ransomware’ has been put on a par with a number of unpleasant phenomena, such as geopolitical tensions, extortion, and government-backed hacks. This word has become dangerous and toxic.” I am... flabbergasted. What? Ransomware has always been a brand of e…

I actually laughed out loud reading this, These guys are giving ransomware a bad name , ahahaha, what?!

I read it as more of a “they’ve ruined it for the rest of us” whinge.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#398
post #86

Earlier quoted context omitted.

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I think you're right - as I said on a sibling comment, if beans are all you count, and bean-counters rule the roost, you can write this off as a one-off, and point out you had 30 years without a ransomware, and therefore we don't need to do anything...

That's surely how it would be represented in order to retroactively justify negligence.

But a more precise calculus would take into account that (1) the proliferation in ransomware is recent and explosive, and (2) getting hit by one ransomware group doesn't mean a second group won't strike soon. (Although I'm guessing the second wouldn't be allowed to use the same ransomware-as-a-service platform, as that would harm the platform's reputation.)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#399

Earlier quoted context omitted.

Now that they've outed themselves as an easy mark, should be simple to hit them again and demand more money. At some point it'll be less expensive to improve their security infrastructure.

Ransoming Colonial basically put Darkside out of business. no one is going to hit them again

Their stuff may have been seized, but their business model has not to my knowledge been invalidated. Ransomware is not a capital-intensive business. A new generation of ransomware groups will quickly spring up to replace DarkSide.
Post reply on HN