Earlier quoted context omitted.
500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose? This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.
Authorities might already know mixers service providers and a subpoena will give them all info they need. Not sure tho, I haven't used bitcoin but there always be weak link somewhere
US travel firm $4.5M ransom negotiation open chat
181–190 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#182Re: US travel firm $4.5M ransom negotiation open chat
#183Earlier quoted context omitted.
In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.
What's the difference? Cut deeply enough - take out entire companies - and people lose their jobs. People can't eat. People lose their health insurance that allows them to afford their life-saving medication. At some point, it's not just "big corporations"; it's the people that work for them, too.
Only in one country on the planet.
Re: US travel firm $4.5M ransom negotiation open chat
#184Earlier quoted context omitted.
In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.
Ok, and now a hospital with critical medical information gets hit by the ransom. What then?
But really, I expect such a law would provide for exceptions, with a maximum payout capability. And for such a law to come after an offsite airgap backup requirement for such entities.
But really, the answer is that the equivalent physical criminal action: walking into a hospital and absconding with all of their medical records, would result in criminal action against the thief. Their actions may be akin to manslaughter if deaths result.
[1]: https://www.ucsf.edu/news/2020/06/417911/update-it-security-...
Re: US travel firm $4.5M ransom negotiation open chat
#185Earlier quoted context omitted.
https://en.wikipedia.org/wiki/Cryptocurrency_tumbler
Isn't 'tumbling' literally a money laundering operation?
It's just a ledger kept outside so there is no link between the money going in and the money coming out.
Re: US travel firm $4.5M ransom negotiation open chat
#186Earlier quoted context omitted.
To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…
> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. That argument could be used to justify any theft or even kidnapping. I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives. There are real harms to ra…
What should the govt so when govt agencies get hacked?
Re: US travel firm $4.5M ransom negotiation open chat
#187This is a very recent event (ransom was only paid on 07/28). They're not out of the woods yet. Whats the bet they get crypto locked again next week?
From what I read, the hackers always keep their words. Otherwise nobody will pay them next time.
Re: US travel firm $4.5M ransom negotiation open chat
#188Another windows local admin/group/domain thing. When are IT departments going to take it off their networks? Why have LANs at all, for most back office work? Immutable, versioned files in managed cloud storage eliminates the locker threat (not the disclosure one though).
When work for a big IT team at a company that's already invested a fortune in on-prem storage and your job depends on pre-cloud procedures, you keep your mouth closed and do what's asked of you. After all, if the company gets hacked, it's usually just the CISO that gets fired. Not you. You made a very good point about Windows GPOs. The delivery mechanism for them vs. how macOS does it shows how dated of a paradigm th…
Scenario 2: Sell solid security and backup principles to management, fighting annoying budget and corporate culture battles along the way. Company does not get attacked. Nobody notices.
Scenario 3: Quietly set up an immutable backup service with hourly backups for your enterprise without anyone really noticing. Company gets attacked. "Actually, we do have backups. We can just reformat all those Windows machines." Hero!
Re: US travel firm $4.5M ransom negotiation open chat
#189Earlier quoted context omitted.
1) You need to be able to tie a BTC address to a human 2) Mixers
Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?
Re: US travel firm $4.5M ransom negotiation open chat
#190So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.
Buy insurance and pray. There is not a single readily available enterprise solution that would even dare to put that in writing, let alone deliver. If there is one that does dare, ask to test their claim by having the deal conditional on them putting out an open $4.5M bug bounty and nobody collecting on it (you should also be the one to determine if they have to pay). Every company will either back out or get collected on, no question. This is a good test because if it costs more than $4.5M to do such an attack, then it would be unprofitable to collect on the bug bounty. It is also unlikely to give a false positive (their system is good when it is not) since $4.5M is more than than almost every other bug bounty and it is totally above board, so you will get the best of the best trying to break into the system.