Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

191–200 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#192
post #87

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

The folks like this should actually do a startup. Hardening security is often just keeping up with and following checklists, installing proper monitoring, backup and audit software however for large majority of company it is impossible to hire competitive security specialists. These guys can scale up by hiring 100s of employees who they train on different aspects and contract with small firms like these at annual sub…

They are likely based in a country not regarded to be a technology leader. Say you were the CTO of a firm looking to improve security, would you engage a Nigerian cybersec consultant? Almost certainly not, you would look in your home country, or the US/Europe.

If they were to start a consultancy, even if they are as skilled as anyone else, they’d have an uphill battle from the get go; and have to either stick to their home market, or heavily discount their services. Either way making less than from their ransomware.

Re: US travel firm $4.5M ransom negotiation open chat

#193

Earlier quoted context omitted.

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

I think one of the ideas of mixers is to achieve such a large volume of transactions that dedicating man-hours and personnel resources to tracking down every transaction path becomes cost prohibitive on the part of a law enforcement organization.

The idea is that you can't track any of the transaction paths. There's nothing tying a specific input transaction to a specific output transaction, and great pains are taken to ensure there cannot be any publicly available link.

Re: US travel firm $4.5M ransom negotiation open chat

#194
post #135

Earlier quoted context omitted.

Not sure how you arrived at a negative value. Or are you suggesting there is no positive use-case that could offset it?

I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.

Although I refuted some of your arguments above (https://news.ycombinator.com/item?id=24033759), I agree that cryptocurrency has fairly limited utility, especially given the costs.

The biggest issue I have with cryptocurrency is that it’s an utter waste of resources. It incentivizes the consumption of electricity (and talent) purely to print money, rather than to produce value. Yes, currencies provide some value to society, but we already have more sustainable options.

I see the appeal if you hate taxes and regulations or live under a particularly oppressive regime. However, given that it relies, to some extent, on public infrastructure like internet and electricity that governments can outright shut off if they so desire, there are better options. Raw materials and bartering work pretty well. Just don’t invest in tulips.

Re: US travel firm $4.5M ransom negotiation open chat

#195
post #176
post #164

Earlier quoted context omitted.

>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance

is there a market for ransomware insurance?

If there were, the prices to unlock would skyrocket.... Unlike most kinds of insurance, the cost here is not a set thing.... It's arbitrary.

Re: US travel firm $4.5M ransom negotiation open chat

#196
post #176
post #164

Earlier quoted context omitted.

>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance

is there a market for ransomware insurance?

There's generic cyber attack insurance so yes.

Re: US travel firm $4.5M ransom negotiation open chat

#197

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Can you really not follow the trail from the mixers?

The mixers keep a ledger outside the blockchain, so no—and a well written one wouldn't store any logs. You could possibly know that someone used a mixer but you wouldn't be able to track from the blockchain where the money came from. It could've come from 1000s of other transactions all with different amounts—none that would trace back to the source funds wallet.

Re: US travel firm $4.5M ransom negotiation open chat

#198
post #58

Earlier quoted context omitted.

Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.

If you were a corporate executive would you risk hard prison time just to save your employer from taking a loss? The whole point of imposing draconian penalties is to make such attacks unprofitable. If the attackers know they won't be able to extract any money from victims then they'll move on to some other scheme.

Banks deal with cartels and other bad guys, they make lot of money and pay a small fine when they get caught. Why do you think paying ransoms would be different?

Re: US travel firm $4.5M ransom negotiation open chat

#199
post #176
post #164

Earlier quoted context omitted.

>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance

is there a market for ransomware insurance?

couldn't you just store your data in append-only fashion?

Re: US travel firm $4.5M ransom negotiation open chat

#200
post #120

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…

> Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current implementations.

Ehhhh, I think the overall impact of Bitcoin is negative, but the "democratizing large-scale crime" argument is a pretty poor argument for why that is. First, Bitcoin isn't "democratizing" anything good or bad--people need to stop using this word with regard to Bitcoin. But assuming you mean something along the lines of "enabling", or "empowering", I'm not sure that the shift in computer hacking crime which is caused by Bitcoin is actually negative.

Prior to Bitcoin, the people who paid for poor security were consumers whose data, money, and time were stolen. In theory if an entity exposes your data, you can sue them, but in reality, data breaches are common and when entities actually get sued, they rarely pay out significantly. I've followed the Equifax case every step of the way for years and still haven't received a dime, and I doubt many people would follow through all the hoops they've put in place--I'm mostly doing it out of curiosity at this point.

That still happens, but more and more, ransomware's biggest targets are large entities which should have secured their services better. Not only does ransomware punish the entities who should have prioritized security, not the consumers, it also makes it public knowledge whose security is lax.

Now there are a lot of complexities here. In theory, ransomeware hackers could also sell the data--but as far as I know that doesn't happen much, probably because they rely on the "honest crook" effect to ever get paid. And sometimes ransomware is employed against individuals.

And to be clear, I'm not endorsing ransomeware attacks. I'm just saying this looks like harm reduction to me: if a big business is going to not prioritize security and get hacked, then I'd rather they pay a ransom than have user's private data sold on the darkweb. In a more just system, that's just the fines they'd be paying anyway.

Post reply on HN