Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

151–160 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#152
post #143

Earlier quoted context omitted.

Banning... how?

The entire thing relies on several things: nearly always-on connectivity, ability to convert to USD, crummy UX, and legit cover. A ban would do serious harm to 2, 3 and 4. If no one could pay legitimately and it would become (ever more) difficult to launder, the ransomware demands would die. The first (connectivity) could be impacted as well. What would happen when traffic shaping makes sync take longer and when ever…

I think the person you're responding to is how you would go about banning it in the first place, not necessarily why you would ban it.

Re: US travel firm $4.5M ransom negotiation open chat

#153
post #60

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

The responses suggesting backsups are ignoring the exfiltration part. The ransomware groups have updated their strategy to encrypt and carry away data that they would leak if not paid. Protecting against that is much harder. Compartmentalization and data minimization might help.

"Data is a toxic asset." If it would hurt the business when leaked, then its value has to justify the risk of keeping it around.

Re: US travel firm $4.5M ransom negotiation open chat

#154
post #135

Earlier quoted context omitted.

Not sure how you arrived at a negative value. Or are you suggesting there is no positive use-case that could offset it?

I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.

I'm not convinced that it is negative. After every high profile hack or breach, we complain about how organizations regularly get away with poor security practices with mere slaps on the wrist (in terms of legal penalties they end up having to pay).

Perhaps these ransomware attacks are the market's way of making things... more fair.

Re: US travel firm $4.5M ransom negotiation open chat

#155

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Can you really not follow the trail from the mixers?

CipherTrace says they lost the trail on the twitter hackers when they threw the btc they scammed into mixers.

On the other hand, the Feds arrested a kid in Florida, so my question is... how did they find him?

Re: US travel firm $4.5M ransom negotiation open chat

#156

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

Re: US travel firm $4.5M ransom negotiation open chat

#157

Earlier quoted context omitted.

An interesting technical and financial challenge is how they intend to launder and tumble the Bitcoin and eventually turn it into fiat currency. The open nature of the block chain means that third parties can and will track all transactions related to the wallet(s) that received the 4.5m.

I guess figure out the average amount tumbled typically (maybe half a bitcoin - 4kish), divide that by total amount (4.5m), something like 1100 tumbles/mixes? Then spend 1100 days mixing the total sum to keep things as banal as possible (3 years). Possibly randomize the amount tumbled per transaction up to $1000 dollars. The 4.5m would have to be mixed immediately so the original wallet can no longer be an event sour…

The smarter move if this was 1 person who intends to use the 4+m to live off, and not buy a Lamborghini or some stupid shit, would be to extend the timeline much further past 1100 days. The smaller the individual amounts the better. If they are long term bullish on the prospects of bitcoin retaining its value or increasing, launder just enough to pay themselves a nice monthly 'salary' for living expenses, under 200k a year, and take a lot of time to consider what to do with the rest.

And dividing it up between as many possible independently run tumblers/mixers.

I'm sure some additional smurfing techniques could come into play for additional obfuscation.

Re: US travel firm $4.5M ransom negotiation open chat

#158

I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...

Kinda funny to see 1BTC sent to check it worked before they sent the rest. Cant undo it like a wire transfer...

But why 1 BTC? That's worth more than 10k. Surely they could have sent a fraction? Or maybe they didn't know bitcoins can be split?

Re: US travel firm $4.5M ransom negotiation open chat

#159

Earlier quoted context omitted.

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose? This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.

Authorities might already know mixers service providers and a subpoena will give them all info they need. Not sure tho, I haven't used bitcoin but there always be weak link somewhere

Re: US travel firm $4.5M ransom negotiation open chat

#160

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

Isn't this confusing the fact that in general any mean of transaction, can be used negatively? The nature of which depends of the nature of the currency. But that's not an argument to say bitcoin and crypto are bad as opposed to for example the dollar. Rather this only shows that criminals are much faster at understanding crypto's advantages and adopting it. The "good" use cases will follow when adoption increases and a proper legal framework is implemented.
Post reply on HN