Live data from Hacker News

Cybercriminals who breached Nvidia issue one of the most unusual demands ever

arstechnica.com

671–680 of 693 posts

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#671
post #405

Earlier quoted context omitted.

Ads at least require an audience. Crypto mining abuse requires just the ability to execute anything. That’s why ads are like acne for the Internet, but crypto is a cancer.

I'd argue it's the opposite. Crypto is fairly easy to avoid as an individual - the only thing I can think of that crypto has "contaminated" is GPU prices. Otherwise, don't get involved and just watch and laugh at the dumpster fire from a safe distance. You don't have to get involved in crypto to participate in society. Advertising on the other hand is very hard to avoid, and even blocking the ads themselves doesn't i…

Many free CI services have stopped being a thing because people exploited the free compute for crypto mining. That’s directly impacted a lot of developers at least.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#672
post #588

Earlier quoted context omitted.

Ads no longer work online, period. The ad industry is just 10 years behind acknowledging it. Most of what people pay for is just paying for the organic traffic you'd normally get with no ads so they don't give it to someone else. It's more of a protection racket than it is a source of genuine new customers.

I have rather different experience. Most people either don't care or don't know how to. Unless you're tech savvy you're watching ads. And if you're on mobile you're watching them anyway in many cases.

People ignore ads either way these days, I mean

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#673

Earlier quoted context omitted.

So you think nVidia will want to see the release of all of its chip schematics? That's an interesting position, but I fail to see how that would be a good idea for them. Perhaps if they are hoping the hackers will be apprehended before Friday.

They won't want to, but I suspect they would prefer it to the actions demanded by the ransom. Nobody legitimate can do anything with the released information if the hackers leak it. It's a huge patent red flag. They could with the drivers open sourced.

If you're in certain countries you can't do anything with the leaked information officially. But you can still look at it and learn from it without telling anyone. As long as you conceal the trail, which shouldn't be that hard, you're good to use it.

On top of that, there's the issue of potentially violating patents the other poster raised.

I'd say those are pretty good arguments for nVidia to try to prevent this scenario.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#674

Earlier quoted context omitted.

So you think nVidia will want to see the release of all of its chip schematics? That's an interesting position, but I fail to see how that would be a good idea for them. Perhaps if they are hoping the hackers will be apprehended before Friday.

What's to stop the group from releasing them anyway? What happens to the files on the hacker's drive - surely the hackers won't delete the files? That would give up the leverage they have. If the files are out there, they could even be leaked by accident (hacker loses laptop, drama in hacker group causes member to rebel, rival group hacks this group, etc) Risk-wise, I think nVidia has no choice here. They should assu…

There is no guarantee that the complete archive won't at some point be released, that is true, but there is a sizeable, reasonable chance. The alternative is that they are definitely released.

Given this, what is the game theoretical reason for nVidia not to even try preventing the release of the complete archive? I think there is none: they should release the drivers as open source and try to contain the damage.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#675

Earlier quoted context omitted.

So you think nVidia will want to see the release of all of its chip schematics? That's an interesting position, but I fail to see how that would be a good idea for them. Perhaps if they are hoping the hackers will be apprehended before Friday.

It's a standard rock vs hard place situation. But 1) why should nVidia trust the attackers? nVdia might give in, and the files might still be leaked. The attackers should be able to guarantee they won't release the files AND nobody steals the files from them. Hard sell for the attackers, especially with a kid profile . 2) These files are legally toxic. You can't look at them and then publicly act on their content. So…

> 1) why should nVidia trust the attackers? nVdia might give in, and the files might still be leaked.

They might, but they will surely be released if they choose to ignore the attackers. Given the choices between a bad outcome happening potentially and surely, which one would you choose?

> 3)It is well possible the leak is not as damaging as it looks. People in the industry swap jobs all the time, and take knowledge with them. People accidentally do small leaks all the time, being sloppy with data entrusted to them. It seems reasonable for other big organizations to already have some level of knowledge of the content.

I still fail to see the logic. Assuming the attackers are honest, the choice is between: a) drivers public b) everything (which includes drivers) public

Option a) garners significant sympathy. What is the incentive to choose b)?

> They also open themselves up to future ransomers ('Danegeld').

This is the only argument that makes a bit of sense to me.

> especially combined with a 'we'll very publicly sue the attackers in the ground, as an example for all wannabes' response.

That can only happen if they are caught.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#676
post #669
post #668

Earlier quoted context omitted.

You’re talking about the EULA, not the copyright license. The EULA can certainly claim you’re not allowed to do that, but it’s also unenforceable in most places so who cares?

I'm talking about neither the EULA nor the copyright license, but about copyright law, which doesn't allow modifications by default. Only a EULA or other license can then allow modifications. OTOH, even the GPL is pretty much unenforceable these days, unless you are well funded enough to afford time consuming legal cases.

https://en.m.wikipedia.org/wiki/Lewis_Galoob_Toys,_Inc._v._N...>

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#677
post #661

Earlier quoted context omitted.

A more interesting example would be From software issuing a “moonlight sword” nft (maybe for an achievement like 100% elden ring) and various indie devs creating souls-like games choosing to honor it within their game.

I would like to be polite to you here, but it's going to be hard, because this take is wrong at every single level, and it feels like you haven't tried any sort of critical thinking whatsoever: 1) NFTs are the most expensive, least efficient way to implement the least interesting part of this technology. Even if you accept the dubious premise that they do even that job well. 2) You have explicitly described a system…

Also one final point, if 10 mutually independent devs share an NFT blockchain so the moonlight sword can be transferred between games... what stops me from minting my own moonlight sword? Or super moonlight sword? Or unauthorized micky mouse hats?

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#678

Earlier quoted context omitted.

Allowing/supporting crypto mining is short-term thinking. It's a bunch of wealthy people burning absurd amounts of fossil fuels solely for the purpose of making themselves wealthier. There is no benefit to society from allowing this.

They’re not merely making themselves wealthier - they’re providing a service. How is this different from an airline or any other user of fossil fuel?

> they’re providing a service

Doubling the price of GPUs is a pretty bad service.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#679

Earlier quoted context omitted.

The only good panels now are also "smart" tvs with something like a roku or samsung spyware built in in an unavoidable way. You can't simply change inputs to avoid it because the whole OS you're changing inputs within is the smart TV's OS.

looks like there might be an emerging market for 60-inch computer monitors

You can absolutely find these, usually offered as commercial products, e.g. for menus, or billboards in airports, etc.

Buddy of mine used to work in a kabab shop before finishing his IT degree and helped out there off and on. He ordered an installed some 48" monitors (simple HD TVs) and then ordered a few for himself. I think they could 2 inputs max, but that's fine for most purposes.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#680

Earlier quoted context omitted.

I do care when this use case is harmful. We shouldn't need to limit hardware for specific usages, but we already see that people won't stop themselves from wasting energy and accelerating world climate if this gives you more wealth and power. I'd also be up for limiting all military weapons from being so destructive across the globe for example. It's mind blowing how we managed to create so many harmful tools in such…

Likening Crypto Mining to military weapons is ridiculous. Not to mention you as those taking your position on crypto often to have painfully failed Chesterton's Fence.

There's no likening, it was just one more example in the bag of hardware used for harmful activities, which is a very big scope.

I'd love to learn that I'm wrong on the crypto one, give how well widespread is, but I haven't seen any fully convincing argument.

Post reply on HN