Earlier quoted context omitted.
> n a difficult to trace manner is a new thing I still don’t understand - how is Bitcoin difficult to trace when there is a global immutable public record of all transactions?
https://en.wikipedia.org/wiki/Cryptocurrency_tumbler
US travel firm $4.5M ransom negotiation open chat
171–180 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#172Re: US travel firm $4.5M ransom negotiation open chat
#173Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…
Why not ban the encryption while we’re at it?
Instead of bashing it, how about we come up with solutions to the problems?
Re: US travel firm $4.5M ransom negotiation open chat
#174Earlier quoted context omitted.
Can you really not follow the trail from the mixers?
CipherTrace says they lost the trail on the twitter hackers when they threw the btc they scammed into mixers. On the other hand, the Feds arrested a kid in Florida, so my question is... how did they find him?
Re: US travel firm $4.5M ransom negotiation open chat
#175Earlier quoted context omitted.
> let any company that doesn't have the budget to have a proper cybersecurity team just die? Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations…
> the simplest of backup solutions would have prevented this. Incorrect. The black hats almost always encrypt backups, too. You could say "what about offline, glacial backups?" But then you're no longer talking about "the simplest of backup solutions"
Re: US travel firm $4.5M ransom negotiation open chat
#176Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…
>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance
Re: US travel firm $4.5M ransom negotiation open chat
#177What's amazing to me is that even though it stings, you get better "customer" service from these criminals than from e.g. Google.
Re: US travel firm $4.5M ransom negotiation open chat
#178Earlier quoted context omitted.
Banning... how?
The entire thing relies on several things: nearly always-on connectivity, ability to convert to USD, crummy UX, and legit cover. A ban would do serious harm to 2, 3 and 4. If no one could pay legitimately and it would become (ever more) difficult to launder, the ransomware demands would die. The first (connectivity) could be impacted as well. What would happen when traffic shaping makes sync take longer and when ever…
1. Bitcoin transactions don’t require access to the internet at the time the transaction takes place. There have been solutions for performing offline transactions, though none have really taken off. Nevertheless, it’s not hard to do, though it’s riskier for the recipient than an online transaction. I won’t go into the technical details, but it’s nothing fancy. The idea is that you can place money in any number of accounts ahead of time, then simply pay people by handing them the keys to those accounts. There’s little overhead for creating new accounts; often merchants will use a fresh account for every transaction. Of course, the recipient has to be able to trust that they’re actually receiving keys to an account with the right amount of currency, which is a harder problem to solve.
2. This isn’t necessary. Bitcoin was popular in certain criminal communities long before there was any easy way to convert between Bitcoin and fiat. Cashing out dirty Bitcoin to USD remains risky.
3. The UX is already terrible. The UX that criminals experience isn’t the same UX that investors experience. They can’t use services like Coinbase to cash out.
4. Prior to Bitcoin going mainstream, the cover was that you could exchange your Bitcoin for various illegal products and services. (Want to buy a stolen car?) When there’s a whole underground economy whose participants are thoroughly convinced they are outside the reach of the law, any currency will work, as long as there’s a consensus within that community.
Banning cryptocurrency would have some interesting effects, but it would be nearly impossible to enforce, and it wouldn’t have the impact you’re seeking.
Re: US travel firm $4.5M ransom negotiation open chat
#179Earlier quoted context omitted.
>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…
Banning... how?
Re: US travel firm $4.5M ransom negotiation open chat
#180Earlier quoted context omitted.
I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.
I'm not convinced that it is negative. After every high profile hack or breach, we complain about how organizations regularly get away with poor security practices with mere slaps on the wrist (in terms of legal penalties they end up having to pay). Perhaps these ransomware attacks are the market's way of making things... more fair.
Security improvements seem to be driven more by regulation (GDPR), competition (when did ElasticSearch release TLS support for free? Not after the Nth open ES cluster - only after Amazon competed with them), and large costs (switching to Linux servers because they're cheaper. Though there are concerns about current security practices there too...).