Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

501–510 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#501
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

> I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security

Um. Terrorism is basically never a threat to national security.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#502

Earlier quoted context omitted.

They don't actually own the oil they're pumping, right? So if their billing was compromised to the point that they don't know what oil needs to be pumped where, they had a legal duty to refrain from pumping it willynilly.

Shouldn’t they have a paper-based/offline downtime procedure for this? (Oh shit, everything just went down, turn on the generator, go plug that printer and laptop in, and print off all the reports of where we were from the offsite/offline/whatever backup). What did they do before computers? Failing to plan is planning to fail and all. I like the idea of monthly planned downtimes where possible so people don’t run aro…

> Shouldn’t they have a paper-based/offline downtime procedure for this?

If they did, I would expect their employees to be out of practice with such methods since they weren't working that way day-to-day. Unless they're running regular "all computers are down"-drills to keep their employees sharp, downtime was probably inevitable.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#503
post #52

Earlier quoted context omitted.

It just takes one agent or informant on the inside to bring the whole house down.

> takes one agent or informant Only if that agent has the master keys. Strong security is about making sure that there is no master key.

I was thinking more about the soft targets and people based parts of the system, but you raise an interesting point. Zero trust systems might be solvable from a tech perspective, but zero trust organizations from a social perspective are a whole lot harder to design and enforce, maybe impossible.

In accounting systems, which are targets of fraud and malfeasance (e.g. Enron), there is a "4 eyes" principle. It takes at least 2 people to change something that impacts the financials. But that can't stop 2 people from colluding.

Back to the topic, if one agent or informant builds trust with one actor in the target group, and they collude or if one slip is made, it could be game over. Once the org is compromised, how do you know who to trust?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#504

Earlier quoted context omitted.

Seriously! It's FIVE MILLION. That's "I don't ever have to work again" money. What is wrong with people! Probably they want Mercedes, and Rolexes, and Mont Blanc pens and all that showy consumer garbage.

The median lifetime earnings in the US is 1.7 million, and that’s equivalent to... $20 an hour or so. 5 million is “never work again” money for a couple of people who want middle class incomes the rest of their lives... it is not really that much when spread over more than a few people.

My friend, you need to [1] travel, and [2] learn a tiny bit about investing.

First, you can live like a fucking KING for $2000/mo in southeast asia and most of central/south america. 24k/yr is 208 years. Bonus! The food is awesome, the people are great, the climate is ... nice most of the year, and the pollution is a little awful in the cities, but damn the beaches are gorgeous, and there are loads of them.

Second, ETF index funds for DJIA/NASDAQ/SP500, easily clear 5-7% per 5/yrs in BAD times; bluechip/bellweather stocks & municipal funds pay dividends that would easily clear that after taxes. Investing like a grown adult versus /r/stonks are two completely different things. I recommend you hire a CFPA (or RIA) for at least a few years as soon as you can afford it, bonus if you can do it in your 20's, it will at least set you on the right track.

Of course, once you get old and medical conditions bankrupt you that's a problem. But then you swan dive off of Machu Picchu and go out in style!!

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#505
post #259

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

Honestly I’d say any highly asymmetric violent or offensive action would lend many folks to trot out the T word.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#506
post #227

Earlier quoted context omitted.

There is basically a zero percent chance that the US knew where they were physically. The servers that were claimed to be seized were on cloud platforms. And even then, we don't know if this is true or if it's just an exit strategy.

It's easy to say "basically zero chance" when we're armchair quarterbacks and not the ones in the hot seat. I'm inclined to agree that our cyber-security apparatus is not up to the task, but it's also true that nobody has perfect OpSec, (and I'd guess there are few out there have deeper pockets to track down and make sure the perpetrators regret this, than the combination of US government + oil companies.)

There have been hundreds of ransomware attacks. How many of them were arrested? Many of them caused more damage than this one.

The US government has a long reach, but even they cannot do anything to you if you are in Russia, for example.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#507

Earlier quoted context omitted.

Just like how robbing a bank may cause terror to the people in the bank or the neighborhood but it was done for profit not politics.

Wealth is the primary means of expanding ones political influence. It’s a primitive tool like a talking stick to coerce all the other monkeys to do shit for you. Trying to gain money is absolutely political

I think you just defined yelling at someone over money to be terrorism.

You can make a reasonable argument that "nothing is apolitical" but but that's not the definition of political being used when people say what terrorism is.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#508

Earlier quoted context omitted.

Don't forget Iran and Vietnam. You don't need to live there for very long. Just for long enough to cash out into fiat, launder the money, etc...

Maybe. This isn't a political target though, this is criminals wanting money. At most the governments gets a bit of tax money: it just isn't worth it even before you consider that the gangs who can pull this off may turn against the governments. Governments may want the types of people on staff who can pull off these attacks, but they are careful on who gets targeted, and money isn't the goal. Vietnam doesn't like th…

Governments are faillible. Corruption and organized crime exists.

Vietnam has a complicated relationship with the US. Don't trust western media too much on it, there is quite a bit of propaganda and extrapolation from conflict with China that doesn't carry over. Relations with the US appear to thaw but this is mainly limited to trade. Strategically Vietnam is solidly allied with Russia and otherwise independent. There is no scenario in which Vietnam extradites to America or allows American intelligence to operate on their soil.

The same is with China. There is zero political cost, they will simply ignore the hackers until they leave the country. US intelligence is quite weak in terms of real assets in China, so uncertainty would be very high.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#509
post #288
post #237

Earlier quoted context omitted.

The truly cynical take is that they managed to take down Colonial's billing . In response, Colonial shut down the pipeline - because obviously delivering oil without getting paid is out of the question. Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...

The Colonial Pipeline Is Finally Back Online and Pumping Gas https://www.thedrive.com/news/40583/the-colonial-pipeline-is... > New details from within Colonial Pipeline have come to light surrounding the decision to shut off supply. Those briefed on the matter have suggested that fuel flows were shut down due to the company's billing system being compromised. Company officials were reportedly concerned that they woul…

I hope they will be hit with massive fines. That sort of reasoning should be absolutely unacceptable... Billing system going down should not take down critical infra...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#510

Earlier quoted context omitted.

Looking only at the parts quoted in krebs’s post, it doesn’t really stick out to me as either American or British English. They use double quotation marks, for example - American - but leave the trailing comma outside, which is British. Other than that, there are no giveaway spellings or idioms. It could just as easily be someone whose exposure to English is dominated by technical documentation, which tends to use mo…

You have a good point about the comma. I am not sure what the use of the word "funds" tells me. I think in the US, only the highly-educated or those in the financial industry would use that term instead of "money" (bitcoin?). It very well could be much more common in other parts of the, umm, anglosphere.

I think anyone who’s worked in any kind of corporate environment would distinguish “funds” from “money” when writing formally, but maybe that’s just me.

I grew up in the US but lived most of my adult life abroad, and the only thing I can tell you for sure is that you should never stereotype anyone based on the way they use their second or third language.

Post reply on HN