German police name alleged leaders of GandCrab and REvil ransomware groups
131–140 of 175 posts
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#132Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#133Earlier quoted context omitted.
It also has something to do with the so called "Hackerparagraph" [1] under which whitehat hacking is basically impossible in Germany. Even writing a program that could potentially be used for hacking is a crime. If you followed the law word for word the authors of e.g. curl could be charged under this law. 1: https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hen... [de]
It'll nevee cease to amaze me how some countries find such creative ways to stifle innovation while they look to be caring about safety or what not.
I'm not sure white-hat hacking is broadly compatible with German culture. Keep in mind that going bankrupt in Germany permanently closes off lots of avenues, from future lending to whether you can be in senior management at a public company.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#134Earlier quoted context omitted.
I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.
It also has something to do with the so called "Hackerparagraph" [1] under which whitehat hacking is basically impossible in Germany. Even writing a program that could potentially be used for hacking is a crime. If you followed the law word for word the authors of e.g. curl could be charged under this law. 1: https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hen... [de]
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#135These groups typically exploit unpatched vulnerabilities and exposed credentials. Most companies don't discover they're vulnerable until after a breach. Regular security audits are the only real defense.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#136Some of the comments here (and lately on HN in general) are very concerning to me. Are we really going to pretend that people accused of real crimes shouldn’t be arrested, charged and, if found guilty, have an appropriate sentence? It doesn’t take many more than 2 brain cells rubbing together to see that that won’t end well. Whataboutism, political differences, and even real injustices in my opinion do not make this…
It probably depends on what people think about the laws that define what a "real crime" is. E.g. in germany it was a real crime to grow some weed. Now it's legal, but even before a lot of reasonable people didn't want someone go to jail over weed.
If growing weed is illegal in Germany, and someone unknown grew a lot of weed in Germany, they end up being sought, and (eventually) their name and other details could end up in a police warrant.
The comparison is moot though since growing weed in Germany requires physical presence in Germany. The alleged cybercrimes could've originated from anywhere in the world due to the nature of the internet.
It just isn't doxing unless you don't see legal merit in the German police and German authorities. Which is obviously rhetoric the Russians want others to follow.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#137So apparently some CCC-connected hackers already unmasked one of them years ago (as reported in the update, which could have also just linked to the talk here: https://media.ccc.de/v/37c3-12134-hirne_hacken_hackback_edit... ) Makes you wonder if the investigators discovered this independently, or decided to maybe ask the hackers already involved in defending against them for help...
I'm not deep into the topic, but AFAIK there generally isn't a warm connection between the CCC and the BND in Germany (in the recent years mostly due to the BNDs involvement ins spying on German citizens, but I think there is also deeper history there). If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.
nor should there be.
Similar to how us American hackers have a huge dislike and distrust of the FBI.
Your own law enforcement agency will lie to you, manipulate you, raid you, extort you, and imprison you over bullshit.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#138Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#139Feels odd for an infosec blog to use 'doxxing' this way. Doxxing is generally considered to be unethical exposure of personal information. Identifying a criminal is ethical.
Is it ethical to dox a pregnant woman seeking an abortion in a southern US state?
Is it ethical to dox a gay human rights defender in Russia?
Is it ethical to dox a woman seeking an education in Afghanistan?
Not all criminals have done something wrong.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#140Earlier quoted context omitted.
It'll nevee cease to amaze me how some countries find such creative ways to stifle innovation while they look to be caring about safety or what not.
> some countries find such creative ways to stifle innovation while they look to be caring about safety or what not I'm not sure white-hat hacking is broadly compatible with German culture. Keep in mind that going bankrupt in Germany permanently closes off lots of avenues, from future lending to whether you can be in senior management at a public company.