Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

571–580 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#571

Earlier quoted context omitted.

As far as I'm concerned, ransomware attacks essentially fall into the same classification as highwaymen, bandits, and pirates. We tend to take those pretty seriously. Or at least, we did once they've robbed the wrong people. Sounds like the ransomeware people finally robbed the wrong people.

We have only DarkSide's word for what happened to them. No corroboration. Not saying it's false, but the story doesn't ring true to me. They appear to be sophisticated, yet they made the newbie error of keeping all the funds in a network accessible device, rather than a cold wallet. Really?

One of the things that criminal gangs always need to be aware of is being defrauded by their own collaborators. So they often have to make sub-optimal choices on OpSec because they have to work with hostile actors.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#572
post #557

Earlier quoted context omitted.

> another favourite talking point of the crypto people that it secures your money from government access Credibly threatening repeated 51% attacks against Bitcoin is well within any G7 member’s budget.

Actually this ignores the fact that bitcoin uses ASICs now, and every ASIC built for bitcoin hashing is probably already hashing. Semiconductor production can't be scaled up instantly, so 51% attacks require seizure of assets. Even if the USA purchased every single CPU, GPU, FPGA, and ASIC made in the next month, it's unlikely they will have more than 10% of the network or so. To seize the majority of the hashpower,…

I mean it doesn’t require ASICS, it’s just inefficient not to, right? Shouldn’t it be theoretically possible to mount a 51% attack with conventional CPUs (or GPUs), just a lot more of them? I have no idea what kind of computing resources various major states have, but I wouldn’t completely write off the possibility that they have enough CPUs to throw at the problem.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#573
post #509

Earlier quoted context omitted.

I hope they will be hit with massive fines. That sort of reasoning should be absolutely unacceptable... Billing system going down should not take down critical infra...

> should be absolutely unacceptable... Billing system going down should not take down critical infra It’s a privately financed, constructed and operated pipeline. I don’t see why they should be obligated to operate without getting paid.

When you become critical national infrastructure, the calculus changes. For any company in that position, their NUMBER ONE priority is to keep operating and providing their deemed essential service.

Colonial obviously have done well in certain ways: their business side and operational side are decoupled. Business side got hit with a major IT problem - and the damage was contained. Pipelines kept working as intended. That's good operational planning, and they deserve credit for it. They were perfectly capable of, quite literally, keeping the lights on for 100M people.

> It’s a privately financed, constructed and operated pipeline. I don’t see why they should be obligated to operate without getting paid.

Because they are critical infrastructure. Colonial are entitled to their profits as long as they keep their side of the bargain: supply oil and fuel for those 100M people who critically depend on them.

This is where role of a regulation comes in. Make it the critical supplier's responsibility to ensure that they supply. If they lose their billing capability, that's their problem. Not their customers'.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#574
post #572
post #557

Earlier quoted context omitted.

Actually this ignores the fact that bitcoin uses ASICs now, and every ASIC built for bitcoin hashing is probably already hashing. Semiconductor production can't be scaled up instantly, so 51% attacks require seizure of assets. Even if the USA purchased every single CPU, GPU, FPGA, and ASIC made in the next month, it's unlikely they will have more than 10% of the network or so. To seize the majority of the hashpower,…

I mean it doesn’t require ASICS, it’s just inefficient not to, right? Shouldn’t it be theoretically possible to mount a 51% attack with conventional CPUs (or GPUs), just a lot more of them? I have no idea what kind of computing resources various major states have, but I wouldn’t completely write off the possibility that they have enough CPUs to throw at the problem.

Bitcoin is currently 170 exahashes per second, or 170 x 10^18.

The latest and greatest Intel i7 can do maybe 30 mh/s.

You would need more than all cpus produced in history. I can believe G7 secretly having a third of total known CPU compute.

I can't believe G7 secretly having multiples of all known CPU compute.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#575

Earlier quoted context omitted.

> It is created by governments and its value is driven by taxation. How does taxation drive value? Which taxation? There are governments that don't charge income taxes, there are governments that don't charge property taxes, there are governments that don't charge sales taxes.

This idea comes from Modern Monetary Theory (MMT). Most mainstream economists do not agree with it. But the MMT claim is that at base, people only need USD because it’s how taxes are denominated. The notion is that without the driving force of compelled taxation, no one would use USD or other sovereign currencies. MMT also claims, through similar logic, that a monetary sovereign can print an extreme amount of currenc…

The words “extreme” and “massive” are subjective. MMT claims that the best way for a monetarily sovereign government to maintain aggregate spending at full employment levels is to hire anyone willing to work but who cannot find work in either the private sector or the permanent government sector.

Also note that the work of legal historians such as Christine Desan who are not affiliated with MMT economists concurs with this analysis.

Also note that most mainstream economists do actually agree with the tenets of MMT when individually stated but base their disagreement on a deliberate misreading/misstatement of MMT which they then proceed to criticise.

That taxation is sufficient to drive demand for a currency is not contentious, that it is necessary is unconfirmed.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#576
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> Statements like this seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. It's just digital Privateering - Francis Drake with a laptop. > If a market correction occurs... The English solved it by expanding their Navy and enlisting those who would otherwise pirate. Seems like as good a solution as any here.

I thought privateers were state sponsored (i thought that was the distinction from piracy?). Which sort of makes the comparison to ransom ware potentially more apt/thought provoking?

In anycase disparity of oppourtunity is what breaks trust and therefor collaboration. The world needs to universally operate in the ballpark of fairness or we are all at risk in the long term. (This comment is also influenced by the under valued tech resources thought).

Edit (sorry some more thought while fixing typos): When the disparity of oppourtunity is at state level there are privateers and wars, when at a personal level there are muggings and burglaries etc.

*this is all probably stupidly obvious.. but as its against uncontrolled capitalism or classist segregation we dont seem to want to say it too much maybe?

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#577

Earlier quoted context omitted.

> It is created by governments and its value is driven by taxation. How does taxation drive value? Which taxation? There are governments that don't charge income taxes, there are governments that don't charge property taxes, there are governments that don't charge sales taxes.

This idea comes from Modern Monetary Theory (MMT). Most mainstream economists do not agree with it. But the MMT claim is that at base, people only need USD because it’s how taxes are denominated. The notion is that without the driving force of compelled taxation, no one would use USD or other sovereign currencies. MMT also claims, through similar logic, that a monetary sovereign can print an extreme amount of currenc…

The idea isn't exclusive to MMT. Critics from across the spectrum recognize that taxation supports the USD. Buttresses such as legal tender laws, the petrodollar system and other barriers serve to support the USD.

Tally sticks are an early example of monetized debt as a taxation medium.

https://en.wikipedia.org/wiki/Tally_stick

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#578

Earlier quoted context omitted.

Opinions are my own. There is something called the "gun test". The crypto on an encrypted hard drive is not more secure than the gold bars in a locked safe. Its security is a function of how the secret holder response to gun-on-their-head events. In this case, since the government is directly involved (and angry), a lot of criminals may pick personal safety over assets. Frankly, I think a large portion of cryptocurre…

This is commonly referred to as Rubber-hose cryptanalysis : In cryptography, rubber-hose cryptanalysis is a euphemism for the extraction of cryptographic secrets (e.g. the password to an encrypted file) from a person by coercion or torture[1]—such as beating that person with a rubber hose, hence the name—in contrast to a mathematical or technical cryptanalytic attack. https://en.wikipedia.org/wiki/Rubber-hose_cryptan…

Julian Assange and a couple of others developed a file stem called Rubberhose to avoid this problem. All of the filesystem structures, data, and free space are indistinguishable from noise without the decryption key. The system always sets up some portion of the filesystem as unusable space that's initialized to noise. This space may contain another Rubberhose instance, which would also have some unusable space in it.

If you're tortured to keep revealing keys to deeper and deeper volumes, eventually you're going to hit a point where there are no more volumes, but you can't prove it.

I think the original threat model was someone willing to torture you, but willing to accept plausible deniability once you'd revealed some moderately sensitive information.

In reality, if someone is willing to torture you a couple volumes deep, there's a good chance they're going to just keep torturing you forever. Rubberhose may still work in this model, since in theory the promise of avoiding torture loses most of its power. The downside is that once you format a partition with Rubberhose, you're resigning yourself to being tortured forever.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#579
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

The fact that their coins were apparently easily stolen also debunks another favourite talking point of the crypto people that it secures your money from government access. Clearly, ways and means have been developed to do just that if necessary.

That's the point that got me thinking about the likelihood of a very different real story that might be going on. What if some individual or subgroup just ran away with the hoard? Some subcontractors/mid-level data henchmen could have tried to press compensation by threatening to release victim keys, and then a combination of disbelief, unwillingness to accept having gotten fooled by a peer and dreams of spy story grandeur conjuring up a fantasy about state involvement that they eventually believe themselves. Or at least like better than the alternative.

I don't consider that the most likely scenario, but something in the willingness to declare defeat got me into "what if" mode.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#580

Earlier quoted context omitted.

> I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security Um. Terrorism is basically never a threat to national security.

Threats to financial centers and satellite offices of major intelligence offices that are part of the US intelligence apparatus such as in 9/11 are definitely threats to national security. Not sure if you were being sarcastic?

That's an outlier as far as terrorism goes. And even 9/11 harmed US power only by causing it to spend trillions in Iraq.
Post reply on HN