Live data from Hacker News

North Korean hackers stole a record $1.7B of crypto last year

economist.com

71–80 of 203 posts

Re: North Korean hackers stole a record $1.7B of crypto last year

#71

Earlier quoted context omitted.

Privacy absolutists are free to deal in cash. Whatever amounts they send and receive, criminals and dictators do orders of magnitude more and people suffer as a result. If it wasn't so sad it would be funny that the countries with highest levels of freedom and least corruption tend to be the ones with most vocal privacy absolutists...

>the countries with highest levels of freedom and least corruption tend to be the ones with most vocal privacy absolutists... Correlation or causation?

Only irony. No one is taking cash away from those guys.

Re: North Korean hackers stole a record $1.7B of crypto last year

#72

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Can you provide a legitimate use case for mixers? (I'm not trolling, I'm genuinely curious)

The Bitcoin Lightning Network uses indirection for privacy and liquidity in a way that could be described as mixing. https://en.wikipedia.org/wiki/Lightning_Network

Re: North Korean hackers stole a record $1.7B of crypto last year

#73

As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are: 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. 2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule account…

> 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. I'm just a 'regular security guy' but in that link you posted they detail that after the initial phishing compromise "The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access t…

The companies getting hacked are not the web3 ones like Ethereum or Terra. They are normally inside jobs with the founders stealing from the "decentralised" network they secretly control. It's the exchanges that are run like traditional business without the magic blockchain power.

Re: North Korean hackers stole a record $1.7B of crypto last year

#74

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

I agree in principal, however if the vast majority of a given service's users are using it for criminal activity then maybe there's room for some added scrutiny.

Ok, so all you have to do is prove that the vast majority of a given service's users are using it for criminal activity, right?

Re: North Korean hackers stole a record $1.7B of crypto last year

#75
post #51

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

If 99% of BTC mixers' volume is helping laundering international drug trade money, arms or human trafficking, it's not exactly hard to demonize mixing itself. I have no data to base this on, but I assume that privacy absolutists are a tiny, tiny drop in the pool of blood and crime.

do you feel the same way about Tor?

If 99% of Tor's volume is helping laundering international drug trade money, distributing CSAM, etc, should it be demonized as well?

Re: North Korean hackers stole a record $1.7B of crypto last year

#77
post #65

Earlier quoted context omitted.

Can you provide a legitimate use case for mixers? (I'm not trolling, I'm genuinely curious)

Scenario one. Individual (while working in a startup) is receiving some tokens as a compensation. Time passes. Their remuneration being on-chain and visible is a problem when negotiating salary in the next job. Scenario two. I want to have on-chain identity (e.g. exo762.eth domain name). To register it I need to have some ETH (gas, registration fee). If I sent this ETH directly from my "money" account, I will forever…

How are these scenarios "use cases" for a mixer and not critical flaws in the underlying system?

We're in a thread about a rogue state using the tech to steal money to fund their operations (Chemical attacks in airports, nuclear warheads, intercontinental ballistic missiles, etc.) How many nuclear detonations would you consider acceptable in exchange for the cryptobros to have their toys?

Re: North Korean hackers stole a record $1.7B of crypto last year

#78
post #49

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Can I use an RPG-7 to kill animals like bears that threaten my life on my property? Yes. It’s definitely usable for non nefarious activities. Should I be demonized for having one in my house? Probably

And when it's less obvious? Should I be demonized for using TOR? Monero? Signal? GPG?

Re: North Korean hackers stole a record $1.7B of crypto last year

#79

As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are: 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. 2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule account…

> 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. I'm just a 'regular security guy' but in that link you posted they detail that after the initial phishing compromise "The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access t…

The problem was ultimately in the bridge’s design and implementation. Even though it was sold as a decentralized system it was a multisig with very few signatories. A properly designed decentralized bridge would require the compromise of many validators, each with a different infrastructure setup. This is why you never hear about Ethereum itself getting hacked.

Instead, the Axie bridge was a multisig, and as of that wasn’t bad enough, most of the signatories were controlled by the same organization on the same infrastructure. Really demonstrated that concerns about decentralization are not just pedantic or academic.

Re: North Korean hackers stole a record $1.7B of crypto last year

#80
post #77
post #65

Earlier quoted context omitted.

Scenario one. Individual (while working in a startup) is receiving some tokens as a compensation. Time passes. Their remuneration being on-chain and visible is a problem when negotiating salary in the next job. Scenario two. I want to have on-chain identity (e.g. exo762.eth domain name). To register it I need to have some ETH (gas, registration fee). If I sent this ETH directly from my "money" account, I will forever…

How are these scenarios "use cases" for a mixer and not critical flaws in the underlying system? We're in a thread about a rogue state using the tech to steal money to fund their operations (Chemical attacks in airports, nuclear warheads, intercontinental ballistic missiles, etc.) How many nuclear detonations would you consider acceptable in exchange for the cryptobros to have their toys?

You’d rather they sell meth? They’re gonna find the money one way or another.
Post reply on HN