Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

411–420 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#411

Earlier quoted context omitted.

How does the scam work ? You got me curious...

Ball gets placed under one of three cups. Cups get mixed around and people guess where the ball is for money. The ball isn’t under any of them though. The scammer palmed it.

I guess people let their guards down when the plant in the audience gets it right and win some money, they pay less attention to the scammer's sleight of hand.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#412

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

If you store your coins on a hard drive there's nothing the government can do to get them right? They would need your private key and your hard drive?

> They would need your private key and your hard drive?

Most people serious about cryptocurrencies do not trust computers/harddrives anymore since years. They use "hardware wallets", which are HSMs with a very small attack surface. It's not impossible that hacks happen but there's a gap so wide between "a Windows 10 computer running some Bitcoin software wallet" and "a Ledger Nano S" hardware wallet that it's basically two different worlds.

Think a Yubikey (with a tiny screen) to cryptographically sign your transaction.

$5 wrench attack still works but compromising your private key(s) by "logging every OS keystroke in the name of telemetry" or "using one of the tens JavaScript 0-day from today" doesn't.

The idea behind these cryptocurrencies hardware wallets is that ANY computer you connect them to is compromised (which is precisely why you're using an hardware wallet) and that, yet, that's not a problem.

I have to say: it's not a bad way to think about computer (in)security.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#413
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Treating more and more attacks "as terrorism" has it's limits. The US may have awesome offensive cyber attack abilities but stopping widespread ransom wear requires systematic security, not threatening the bad guys, since there will always be more bad guys.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#414

Earlier quoted context omitted.

Would the same apply for someone who physically took something essential to national security hostage and then demanded money? Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

Terrorism has to have some ideological agenda, which is what makes it dangerous - I doubt you'll see suicide bombers for hire.

Not more than once, anyway.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#415

Earlier quoted context omitted.

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

so which is it then? "BTC is bad cause it can be used by drug dealers to launder money" "BTC is not even secure from government access" Surely someone will point out both can be true but the point is the anti-btc folks seem to be talking out both sides of the mouth

> Surely someone will point out both can be true but the point is the anti-btc folks seem to be talking out both sides of the mouth

The most beautiful being: "The cryptocurrencies scam should all stop but, please, let us collect all the due taxes on the gains you made".

From that standpoint which one is it: are they legal or illegal? Because it's funny that they both want it to be illegal, yet they want people to pay taxes on the gains they made.

Hypocrites.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#416

Earlier quoted context omitted.

On the high seas of the Internet there is a thin line between pirates and state actors. There could even be "privateer" ( https://en.wikipedia.org/wiki/Privateer ) attackers who work for a nation and for profit at the same time. From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the da…

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

With that definition this is explicitly not terrorism, because it was for money not for political or religious reasons?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#417
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

> debunks another favourite talking point of the crypto people that it secures your money from government access

In order to seize someone's cryptocurrency, the government has to literally seize the private keys used to sign transactions. This could be as easy as seizing computers containing the key but it could also be as hard as torturing people until they reveal their seed phrase.

They can't simply order the banks to freeze people's assets. They have to physically go there and try to seize them. This puts a limit on the scope of their operations. It's just like surveillance: encryption makes dragnet espionage harder but it's still perfectly possible for a target to be attacked directly.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#418
post #331

Earlier quoted context omitted.

While I tend to agree with your argument, there is a difference: crypto is safe if no one knows it exists, or rather no one can link ownership to owner. It's very hard to do this with gold.

How is this different than burying gold?

A. You can store redundant copies in various secret locations.

B. To bury gold you must transport the valuable property in meat space to your hiding spot after acquiring it. With cryptocurrency, you hide the secrets before they have value and transfer the funds to them without new data actually traveling to the hiding spot, electronically or physically.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#420
post #411

Earlier quoted context omitted.

Ball gets placed under one of three cups. Cups get mixed around and people guess where the ball is for money. The ball isn’t under any of them though. The scammer palmed it.

I guess people let their guards down when the plant in the audience gets it right and win some money, they pay less attention to the scammer's sleight of hand.

[deleted]
Post reply on HN